Why fake Nagad support needs careful checking
A BGD e-GOV CIRT advisory published on 17 May 2026 describes an AsyncRAT campaign using fraudulent gambling infrastructure and localised bKash, Nagad and Rocket payment lures. The finding concerns the described malicious infrastructure; it does not mean that Nagad, bKash, Rocket or every casino-related transfer is fraudulent.
If you have not yet opened a suspicious link, do not enter an OTP, PIN, password or card detail. Do not install an app or remote-access tool at the request of an unverified support contact.
Separate the official Nagad identity
The official Nagad website captured on 28 August 2026 presents Nagad services, account opening, help and the Nagad app. The official site is nagad.com.bd, but reaching that domain alone does not identify or approve a casino recipient and does not determine a refund or complaint outcome. Use the official site as a provider-identity reference, not as proof that a separate payment request is authorised.
Check the complete domain and URL rather than relying on a logo, colour scheme, search-result title or a familiar-looking support name. A cloned Nagad page may copy visible design elements while using a different domain. Treat shortened, redirected or misspelled links as unverified until their destination is understood.
For general provider information, use the Nagad payment hub. For broader payment-risk guidance, see payment risks.
Read the URL before interacting
A suspicious URL can preserve useful evidence even when the page disappears. Record the full address as displayed, including the protocol, domain, path, query string and fragment. Note the time shown on your device and where the link arrived, such as an SMS, social message, advertisement or chat.
Do not revisit a dangerous link merely to capture it. If a message contains a redirect, preserve the original message and the visible URL. A screenshot can help show what was displayed, but it should supplement—not replace—the text record. Do not edit the original evidence.
| Item to retain | What it can establish | Safe handling |
|---|---|---|
| Full URL | The exact domain, path, parameters and fragment presented | Copy it without opening the link again |
| Original message | Sender label, wording, timestamp and delivery channel | Preserve the message and export it if available |
| Domain and IP, if known | Technical identifiers relevant to incident reporting | Record the value supplied by a trusted device or existing log |
| Page or app behaviour | Credential prompts, download requests or redirects | Describe what occurred; do not retry the action |
| Transaction reference | A payment event that may be checked separately | Keep the original receipt and do not publish OTP or PIN data |
Recognise credential and malware indicators
Fake Nagad support often tries to create urgency. Warning signs include a request for an OTP or PIN, a demand to “verify” an account through an unfamiliar page, instructions to share screen access, or pressure to install an APK, browser extension or remote-control application. A request to send a fee before a supposed recovery is also unverified; no recovery outcome should be assumed.
A gambling-themed link deserves additional caution when it combines a payment lure with an executable download, an unsolicited support chat or a demand for credentials. The CIRT advisory dated 17 May 2026 specifically describes an AsyncRAT campaign using fraudulent gambling infrastructure and localised bKash, Nagad and Rocket payment lures. That dated record supports documenting the indicators; it does not identify every gambling-themed link as the same campaign.
If credentials may have been exposed, stop interacting with the sender and use a trusted route to review account security. Do not place OTPs, PINs, passwords, national identification details or recovery codes in a public report.
Decide what the evidence actually shows
Evidence should describe an event, not add a conclusion that the records cannot support. Keep a provider identity claim separate from a recipient claim, a transaction claim and a complaint claim.
| Recorded item | Reasonable description | Description not supported by the item alone |
|---|---|---|
| nagad.com.bd displayed in a browser | The official Nagad domain was displayed at that time | The separate recipient or payment request was approved |
| A Nagad transaction receipt | A transaction record exists with the shown details | The recipient owns a particular business or casino |
| A message using Nagad branding | The sender used Nagad-related branding or wording | The sender is Nagad support |
| A suspicious domain and download prompt | The link presented a possible phishing or malware indicator | The operator is legally responsible or the transfer is fraudulent |
| A CIRT submission | An incident was reported through the stated form | CIRT has decided the dispute or will recover funds |
Keep the casino claim separate as well. A message may claim to represent a gambling service, but that claim is not proof of licensing, ownership, legality, balance, withdrawal entitlement or responsibility for a payment. Avoid naming or contacting an alleged operator through the suspicious link.
Preserve transaction and device evidence
Save the original Nagad receipt, transaction ID, amount, date and time exactly as displayed, while redacting secrets from copies. Do not alter a screenshot to add context. Keep a private chronology: when the message arrived, when the URL was opened, what the page requested, whether any credential was entered, whether an app was installed, and what payment activity followed.
If a device downloaded a file or remote-access tool, disconnect it from sensitive activity and avoid logging into financial services from that device until it has been checked through an appropriate trusted process. Do not delete logs or the original message before preserving copies. Use transaction evidence guidance and receipt privacy guidance for records that need to be shared.
A transaction ID can show that a payment record exists; it does not by itself show why the payment was made, who controlled the recipient account or whether a refund is due. The provider’s process and any separate complaint or law-enforcement remit must remain distinct.
When the CIRT form is relevant
The BGD e-GOV CIRT incident form captured on 28 August 2026 asks for the affected domain and IP, logs or evidence, incident details, attack vector, impact and steps already taken. The form is relevant when the report concerns a suspected cyber incident such as a phishing page, malicious download or credential-harvesting infrastructure. Read the CIRT incident-report route before submitting and prepare the technical details without exposing secrets.
Submitting that form is not a police complaint, a casino adjudication or a recovery guarantee. It does not by itself establish who owns a recipient, whether a payment can be reversed, or whether a gambling-related claim is valid. Use a separate complaint route when the issue requires a different authority or process. Keep the submission confirmation and the evidence package together.
What to do after a suspected exposure
First, stop replying to the suspicious contact and do not send further money or credentials. Second, preserve the URL, messages, receipts and chronology. Third, use a trusted provider route rather than a link supplied by the sender. Fourth, record which information may have been exposed and which device was used. Fifth, choose the reporting route that matches the issue: technical incident reporting, provider support, or another competent complaint channel.
| Situation | Immediate record | Appropriate next step | Boundary |
|---|---|---|---|
| Fake support message, no click | Sender, message, visible URL | Preserve and avoid engagement | No incident outcome is established |
| Cloned page opened, no credentials entered | URL, screenshots, prompts, time | Preserve safely and report the technical indicator | A page appearance does not prove ownership |
| OTP, PIN or password entered | Time, service, device and affected account | Use a trusted account-security route immediately | Do not disclose the secret in evidence |
| Download or remote-access request | File name, URL, device behaviour and time | Stop using the affected device for sensitive activity and seek trusted technical help | Do not retry the download |
| Payment completed | Receipt, transaction ID, recipient details and chronology | Use the relevant provider and complaint channels | A receipt does not prove refund entitlement |
| Technical incident requiring escalation | Domain, IP if available, logs, impact and steps taken | Consider the CIRT incident form | Submission is not adjudication or guaranteed recovery |
For recipient checks, use Nagad recipient and merchant checks. For a possible wrong recipient, see wrong-recipient guidance. Corrections to factual records can be sent through privacy corrections.
Questions people ask
How can I identify fake Nagad support?
Treat unsolicited contact, requests for OTP or PIN, unfamiliar URLs, urgent payment demands, screen-sharing requests and app-download instructions as warning signs. Verify provider identity through the official Nagad domain and do not use contact details supplied only by the suspicious sender. Preserve the message and URL without replying.
How do I distinguish the official site from a cloned page?
Check the complete domain, protocol, path and redirects. The official Nagad website captured on 28 August 2026 is nagad.com.bd and presents Nagad services, account opening, help and the Nagad app. A familiar logo or copied layout is not enough, and the official site does not approve a separate casino recipient or determine a refund.
Which parts of the URL should I retain?
Retain the complete URL, including protocol, domain, path, query string and fragment. Also preserve the original message, sender label, delivery channel and time. Do not reopen a suspicious link solely to capture it, and do not publish passwords, OTPs, PINs or recovery codes.
When is the CIRT form relevant?
It is relevant to a suspected cyber incident involving indicators such as a phishing page, malicious download or credential-harvesting infrastructure. The form captured on 28 August 2026 asks for the affected domain and IP, logs or evidence, incident details, attack vector, impact and steps already taken. It is not a police complaint, casino adjudication or recovery guarantee.
Does a Nagad transaction prove that a recipient is a casino or merchant?
No. A transaction receipt records the details shown for a payment event. It does not by itself prove recipient ownership, a casino relationship, licensing, legality, refund entitlement or wrongdoing. Keep the transaction evidence separate from any claim made by a message or alleged service.
What should I do if I entered an OTP or PIN?
Stop using the suspicious page and stop communicating with the sender. Do not share the exposed secret in a report. From a trusted route, review account security and contact the relevant provider process. Preserve the URL, message, device timeline and transaction evidence without assuming that recovery or a refund will follow.
Reviewed by Casino Check BD Editorial Verification Desk; author: Casino Check BD Evidence Desk; review date: 28 August 2026. Factual corrections can be submitted through privacy corrections.