Bangladesh evidence checks · payment safety · complaint routes
CASINO CHECK BDIndependent public-safety evidence desk
Bangladesh · English editionReviewed: 28 August 2026
Nagad · payment guide

How to Spot Fake Nagad Support and Phishing Links

Why fake Nagad support needs careful checking

A BGD e-GOV CIRT advisory published on 17 May 2026 describes an AsyncRAT campaign using fraudulent gambling infrastructure and localised bKash, Nagad and Rocket payment lures. The finding concerns the described malicious infrastructure; it does not mean that Nagad, bKash, Rocket or every casino-related transfer is fraudulent.

If you have not yet opened a suspicious link, do not enter an OTP, PIN, password or card detail. Do not install an app or remote-access tool at the request of an unverified support contact.

Separate the official Nagad identity

The official Nagad website captured on 28 August 2026 presents Nagad services, account opening, help and the Nagad app. The official site is nagad.com.bd, but reaching that domain alone does not identify or approve a casino recipient and does not determine a refund or complaint outcome. Use the official site as a provider-identity reference, not as proof that a separate payment request is authorised.

Check the complete domain and URL rather than relying on a logo, colour scheme, search-result title or a familiar-looking support name. A cloned Nagad page may copy visible design elements while using a different domain. Treat shortened, redirected or misspelled links as unverified until their destination is understood.

For general provider information, use the Nagad payment hub. For broader payment-risk guidance, see payment risks.

Read the URL before interacting

A suspicious URL can preserve useful evidence even when the page disappears. Record the full address as displayed, including the protocol, domain, path, query string and fragment. Note the time shown on your device and where the link arrived, such as an SMS, social message, advertisement or chat.

Do not revisit a dangerous link merely to capture it. If a message contains a redirect, preserve the original message and the visible URL. A screenshot can help show what was displayed, but it should supplement—not replace—the text record. Do not edit the original evidence.

Item to retainWhat it can establishSafe handling
Full URLThe exact domain, path, parameters and fragment presentedCopy it without opening the link again
Original messageSender label, wording, timestamp and delivery channelPreserve the message and export it if available
Domain and IP, if knownTechnical identifiers relevant to incident reportingRecord the value supplied by a trusted device or existing log
Page or app behaviourCredential prompts, download requests or redirectsDescribe what occurred; do not retry the action
Transaction referenceA payment event that may be checked separatelyKeep the original receipt and do not publish OTP or PIN data

Recognise credential and malware indicators

Fake Nagad support often tries to create urgency. Warning signs include a request for an OTP or PIN, a demand to “verify” an account through an unfamiliar page, instructions to share screen access, or pressure to install an APK, browser extension or remote-control application. A request to send a fee before a supposed recovery is also unverified; no recovery outcome should be assumed.

A gambling-themed link deserves additional caution when it combines a payment lure with an executable download, an unsolicited support chat or a demand for credentials. The CIRT advisory dated 17 May 2026 specifically describes an AsyncRAT campaign using fraudulent gambling infrastructure and localised bKash, Nagad and Rocket payment lures. That dated record supports documenting the indicators; it does not identify every gambling-themed link as the same campaign.

If credentials may have been exposed, stop interacting with the sender and use a trusted route to review account security. Do not place OTPs, PINs, passwords, national identification details or recovery codes in a public report.

Decide what the evidence actually shows

Evidence should describe an event, not add a conclusion that the records cannot support. Keep a provider identity claim separate from a recipient claim, a transaction claim and a complaint claim.

Recorded itemReasonable descriptionDescription not supported by the item alone
nagad.com.bd displayed in a browserThe official Nagad domain was displayed at that timeThe separate recipient or payment request was approved
A Nagad transaction receiptA transaction record exists with the shown detailsThe recipient owns a particular business or casino
A message using Nagad brandingThe sender used Nagad-related branding or wordingThe sender is Nagad support
A suspicious domain and download promptThe link presented a possible phishing or malware indicatorThe operator is legally responsible or the transfer is fraudulent
A CIRT submissionAn incident was reported through the stated formCIRT has decided the dispute or will recover funds

Keep the casino claim separate as well. A message may claim to represent a gambling service, but that claim is not proof of licensing, ownership, legality, balance, withdrawal entitlement or responsibility for a payment. Avoid naming or contacting an alleged operator through the suspicious link.

Preserve transaction and device evidence

Save the original Nagad receipt, transaction ID, amount, date and time exactly as displayed, while redacting secrets from copies. Do not alter a screenshot to add context. Keep a private chronology: when the message arrived, when the URL was opened, what the page requested, whether any credential was entered, whether an app was installed, and what payment activity followed.

If a device downloaded a file or remote-access tool, disconnect it from sensitive activity and avoid logging into financial services from that device until it has been checked through an appropriate trusted process. Do not delete logs or the original message before preserving copies. Use transaction evidence guidance and receipt privacy guidance for records that need to be shared.

A transaction ID can show that a payment record exists; it does not by itself show why the payment was made, who controlled the recipient account or whether a refund is due. The provider’s process and any separate complaint or law-enforcement remit must remain distinct.

When the CIRT form is relevant

The BGD e-GOV CIRT incident form captured on 28 August 2026 asks for the affected domain and IP, logs or evidence, incident details, attack vector, impact and steps already taken. The form is relevant when the report concerns a suspected cyber incident such as a phishing page, malicious download or credential-harvesting infrastructure. Read the CIRT incident-report route before submitting and prepare the technical details without exposing secrets.

Submitting that form is not a police complaint, a casino adjudication or a recovery guarantee. It does not by itself establish who owns a recipient, whether a payment can be reversed, or whether a gambling-related claim is valid. Use a separate complaint route when the issue requires a different authority or process. Keep the submission confirmation and the evidence package together.

What to do after a suspected exposure

First, stop replying to the suspicious contact and do not send further money or credentials. Second, preserve the URL, messages, receipts and chronology. Third, use a trusted provider route rather than a link supplied by the sender. Fourth, record which information may have been exposed and which device was used. Fifth, choose the reporting route that matches the issue: technical incident reporting, provider support, or another competent complaint channel.

SituationImmediate recordAppropriate next stepBoundary
Fake support message, no clickSender, message, visible URLPreserve and avoid engagementNo incident outcome is established
Cloned page opened, no credentials enteredURL, screenshots, prompts, timePreserve safely and report the technical indicatorA page appearance does not prove ownership
OTP, PIN or password enteredTime, service, device and affected accountUse a trusted account-security route immediatelyDo not disclose the secret in evidence
Download or remote-access requestFile name, URL, device behaviour and timeStop using the affected device for sensitive activity and seek trusted technical helpDo not retry the download
Payment completedReceipt, transaction ID, recipient details and chronologyUse the relevant provider and complaint channelsA receipt does not prove refund entitlement
Technical incident requiring escalationDomain, IP if available, logs, impact and steps takenConsider the CIRT incident formSubmission is not adjudication or guaranteed recovery

For recipient checks, use Nagad recipient and merchant checks. For a possible wrong recipient, see wrong-recipient guidance. Corrections to factual records can be sent through privacy corrections.

Questions people ask

How can I identify fake Nagad support?

Treat unsolicited contact, requests for OTP or PIN, unfamiliar URLs, urgent payment demands, screen-sharing requests and app-download instructions as warning signs. Verify provider identity through the official Nagad domain and do not use contact details supplied only by the suspicious sender. Preserve the message and URL without replying.

How do I distinguish the official site from a cloned page?

Check the complete domain, protocol, path and redirects. The official Nagad website captured on 28 August 2026 is nagad.com.bd and presents Nagad services, account opening, help and the Nagad app. A familiar logo or copied layout is not enough, and the official site does not approve a separate casino recipient or determine a refund.

Which parts of the URL should I retain?

Retain the complete URL, including protocol, domain, path, query string and fragment. Also preserve the original message, sender label, delivery channel and time. Do not reopen a suspicious link solely to capture it, and do not publish passwords, OTPs, PINs or recovery codes.

When is the CIRT form relevant?

It is relevant to a suspected cyber incident involving indicators such as a phishing page, malicious download or credential-harvesting infrastructure. The form captured on 28 August 2026 asks for the affected domain and IP, logs or evidence, incident details, attack vector, impact and steps already taken. It is not a police complaint, casino adjudication or recovery guarantee.

Does a Nagad transaction prove that a recipient is a casino or merchant?

No. A transaction receipt records the details shown for a payment event. It does not by itself prove recipient ownership, a casino relationship, licensing, legality, refund entitlement or wrongdoing. Keep the transaction evidence separate from any claim made by a message or alleged service.

What should I do if I entered an OTP or PIN?

Stop using the suspicious page and stop communicating with the sender. Do not share the exposed secret in a report. From a trusted route, review account security and contact the relevant provider process. Preserve the URL, message, device timeline and transaction evidence without assuming that recovery or a refund will follow.

Reviewed by Casino Check BD Editorial Verification Desk; author: Casino Check BD Evidence Desk; review date: 28 August 2026. Factual corrections can be submitted through privacy corrections.