Protecting Against Unauthorized Login

security unauthorized login phishing
Who this article is for
For all users, and especially for anyone with a role that handles important information, such as a store, business account, or developer.

Four things you must do

  1. A strong, unique password (14+ characters, above the requirements, not reused on other services)
  2. Enable MFA (TOTP or passkey recommended)
  3. Check your login history regularly (about once a month is a good target)
  4. Never click links in suspicious emails

How to spot phishing scams

Suspicious sign Explanation
Sender differs from the official oneThe official sender is noreply@receiptroller.com. e.g. ...@receipt-roller.co is not legitimate
The URL is a fake siteThe official domain is receiptroller.io. Be wary of .com or look-alike domains
Creates a sense of urgencyThings like "verify now or your account will be suspended"
Unnatural wordingText that reads like a machine translation
Asks you to enter your passwordReceiptRoller never sends an email asking you to "enter your password"

Care on shared PCs and public Wi-Fi

  • Leave "Keep me signed in" unchecked
  • Clear the browser cache and cookies when you're done
  • Always log out before leaving your seat
  • Use a VPN on public Wi-Fi

The risk of reusing passwords

Password stuffing attacks that use lists of passwords leaked from other services are on the rise. Always use a different password from any service other than ReceiptRoller.

If you notice an unauthorized login

  1. Change your password immediately
  2. "End all sessions"
  3. Enable MFA (right away, if it isn't set up)
  4. Note the IP and date/time of the suspicious access and report it to support
  5. Share "possible unauthorized access" with members of the stores and business accounts you're linked to
  6. If there's financial damage (fraudulent payments or plan changes), request that transactions be halted

Related guides

Published: 2026-04-27 Updated: 2026-07-05