Home internet providers hold valuable data: names, addresses, phone numbers, and often payment methods. No wonder their name is often borrowed by scammers. The patterns repeat, so they are easy to spot once you know the signs.

The most common patterns

  • A free speed upgrade. The caller announces a "speed upgrade programme" and asks for the code that just arrived on your phone to "activate" it. That code is actually an OTP to log in to your account.
  • A disconnection threat. A message says your bill is overdue and service will be cut today unless you pay into a personal account or through a particular link.
  • Links or APK files. A WhatsApp message carries a "bill" or a "fault checking app" ending in .apk. Installing it can give the attacker access to the SMS and notifications on your phone.
  • A technician turning up unscheduled. The visitor claims to need to "replace the modem" or "check the network", then asks for a cash fee or wants to take equipment away.

What sets them apart from real staff

  • Official staff never ask for OTP codes, PINs, or account passwords.
  • Official payments are not made to accounts in a private person's name.
  • Technician visits usually follow a fault report or an installation schedule recorded in the provider's app.
  • Official apps are installed from the Play Store or App Store, not from files sent over chat.
  • Time pressure, "today", "cut off in five minutes", is a warning sign, not a procedure.

How to verify

The simplest rule: end the conversation, then call back through official channels. Find the customer service number on the provider's website or app, never the number the caller gives you.

For a visitor at the door, ask for their name and visit ticket number, then check it with customer service before letting them in. A genuine technician will understand the check.

If a technician really does need router access, stay with them and change the admin password afterwards. Why the admin password matters is covered in the guide to provider default router admin accounts.

If it's already happened

  1. Contact official customer service and ask for the account to be secured.
  2. Change the provider account password, the linked email, and the Wi-Fi password.
  3. If you installed an APK, disconnect the phone from the internet, remove the app, and call your bank if banking apps are on that phone.
  4. Keep the chat evidence and the scammer's number for a report.

Further steps for a router the attacker may have changed are in the guide to what to do after Wi-Fi is hacked.

Scams in an internet provider's name almost always ask for one of three things: an OTP code, payment to a personal account, or installing an app from chat. Refuse all three, end the conversation, and verify through an official number you look up yourself.

Frequently asked questions

Can an internet provider employee ask for my OTP code?

No. OTP codes are for the account owner only. Anyone who asks for one, including someone claiming to be official staff, should be treated as a scammer.

How can I be sure a technician at my door is genuine?

Contact official customer service through the number on the provider's website or app, not a number given by the visitor, and ask whether a visit is scheduled and who the technician is.

What should I do if I already gave away the OTP code?

Contact official customer service right away to secure the account, change the account and Wi-Fi passwords, and check for unfamiliar transactions or plan changes. If a bank account is involved, call the bank immediately.