CrownPlay Evidence

Independent Australian consumer reference

CrownPlay app, sideloading, and device safety

Avoid unknown installation packages, inspect permissions and signatures, and respond quickly if an untrusted app reached your device.

Evidence status: primary records checked 18 July 2026; unresolved claims are identified.

Dated primary evidence

: ACMA's NovaForge formal warning (PDF) says NovaForge Ltd provided the CrownPlay service through crownplay2418.com and crownplay6.com. ACMA found contraventions of subsections 15(2A) and 15AA(3) of the Interactive Gambling Act 2001 involving prohibited and unlicensed regulated interactive gambling services supplied to customers physically present in Australia.

: ACMA's enforcement report records CrownPlay and related domain disruption activity. The current investigations register lists CrownPlay among prohibited services. ACMA also explains the rules for affiliate services; the Interactive Gambling Act 2001 is the legislation source.

: CrownPlay is not licensed to provide online casino services in Australia. We could not verify the current operator as of 18 July 2026. We could not verify a current foreign licence as of 18 July 2026. These limits do not establish who controls every similarly named domain.

Practical procedure

Do not install a CrownPlay package supplied as a direct APK, configuration profile, desktop executable or other sideloaded file merely because a page says an official store is unavailable. Preserve the download page, message, filename, cryptographic hash if your security tool can obtain it safely, publisher name and requested permissions. An app name and icon are not publisher verification. In an official store, inspect the actual developer identity, history, privacy information and permissions, while recognising that store presence is not a guarantee. Accessibility service, device administrator, screen capture, notification access, SMS, contacts, microphone, camera and installation privileges deserve particular scrutiny because they can expose codes, messages or control. If installed, stop entering credentials, disconnect the device if suspicious activity continues and use built-in security tools to remove elevated access before uninstalling. If removal is resisted or the device remains abnormal, seek qualified device support and consider a platform-supported reset after preserving necessary evidence. Change important passwords from a different trusted device, beginning with email, and review financial sessions. Do not pay a stranger for remote cleanup or grant remote access. A clean-looking uninstall does not prove that credentials or copied data were never exposed, so monitor accounts and document subsequent events.

Avoid sideloaded packages

Do not install an APK, configuration profile, executable, browser extension, or mobile package delivered through a direct download, chat, QR code, or attachment. A claim that an official store is unavailable does not verify the file or justify bypassing platform review, signing, update, and removal controls. Do not enable installation from unknown sources just to inspect the package, and do not weaken antivirus or browser warnings at the sender's request. Preserve the download page and filename without running the file. If a platform offers an official store, search from within the store rather than following the supplied button, but remember that store presence alone is not a guarantee. A copied icon and familiar app name can be attached to unrelated software. If no accountable publisher and distribution record can be matched, leave the app claim unresolved. Browser access does not make an unverified service safe either, but it avoids granting a questionable package lasting device permissions merely to test a marketing assertion.

Verify the actual publisher

Read the developer or publisher identity shown by the operating system or store, not only the app title. Compare the legal name, developer website, privacy notice, support domain, release history, and signing information where the platform exposes it. The support hostname should be checked character by character, and the privacy notice should identify the same entity rather than redirecting to an unrelated brand page. Similar names, high ratings, screenshots, download counts, and a polished logo do not prove control by a claimed operator. On desktop systems, inspect the verified signer through built-in file properties without executing the installer. A missing signature is a warning, while a valid signature identifies a signer but does not prove that the app is appropriate or authorised for Australian users. Record the exact listing address, version, publisher, and observation date. If the claimed publisher cannot be connected through accountable records, do not fill the gap by inference and do not install the package to discover more.

Review high-risk permissions

Compare every requested permission with the limited task the app claims to perform. Accessibility service access can read screen content and operate controls. Device administrator or management privileges can obstruct removal or enforce settings. Notification and SMS access can expose authentication codes. Screen capture, contacts, microphone, camera, location, clipboard, and broad file access can reveal unrelated personal information. Permission to install other packages creates an additional delivery path. Do not approve a request simply because the app says it is needed for verification, updates, security, or withdrawals. Deny optional access and stop installation when a high-risk permission lacks a clear, accountable purpose. On an already installed app, record the permissions currently granted and any recent changes before removal. Platform permission screens show capability, not proof that data was actually taken, so describe exposure as possible unless logs establish more. Least privilege is the practical rule: an unverified gambling-related package should receive no device control at all.

Respond to accessibility abuse

If a suspect app has accessibility access, stop entering passwords, codes, card details, or identity information on that device. Disconnect networking when suspicious actions continue, but preserve basic notes about what appeared and when. Open the operating system's accessibility settings directly, identify enabled services, and disable the questioned service before attempting ordinary removal. Also review notification access, display-over-other-apps permission, screen capture, input methods, and installed certificates or profiles because these can support credential observation or deceptive overlays. Do not follow cleanup instructions displayed by the suspect app, and do not grant remote access to a stranger who offers help. Accessibility capability means secrets displayed or typed while it was active may have been visible; it does not prove exactly what was collected. From a different trusted device, secure important accounts and revoke sessions. If the service switches itself back on, settings are blocked, or the device behaves unpredictably, stop experimenting and seek qualified platform support using a separately verified channel.

Remove administrator access safely

An app with device administrator, device-management, or configuration-profile control may prevent uninstall or change security settings. Use the operating system's own security menus to identify the administrator or management entry and record its displayed name before revoking it. Remove suspicious profiles, certificates, virtual private network configurations, and unknown package-install privileges only through documented platform controls. Then uninstall the app and run the platform's built-in security scan and update process. Do not repeatedly force removal with unverified cleaner tools, because another package can add risk and destroy useful evidence. On an employer-managed device, contact the authorised administrator before changing management settings. If elevated access cannot be revoked, the app returns, or abnormal behaviour persists, obtain qualified device support. A platform-supported factory reset may eventually be appropriate after essential evidence and clean backups are considered, but a reset should follow official guidance. Removal restores control; it cannot prove that earlier credentials or personal data remained private.

Change credentials from a clean device

Use another device that was not exposed to the package to secure accounts. Begin with the email account because it controls many resets, then address the password manager, financial accounts, mobile service, social accounts, and any credential entered while the suspect permissions were active. Create unique passwords, revoke unfamiliar sessions and connected applications, inspect recovery methods, and enable phishing-resistant multi-factor authentication where available. Do not approve prompts that arrive unexpectedly, and replace recovery codes if they were stored or displayed on the affected device. Contact financial institutions through their own application, a card, or an existing statement if payment information may have been observed. Keep a dated checklist of accounts and sessions changed, but never record new passwords in the incident log. Changing credentials on the suspect device can expose the replacements and defeat containment. After the important accounts are secured elsewhere, update and assess the original device before using it again for sensitive activity.

Preserve package evidence

Before deleting what can safely be retained, record the source message, complete download hostname, listing page, filename, displayed publisher, version, installation time, and permissions requested or granted. Capture the operating system's app-information and security screens. If a reputable security tool already reports a package identifier, signer, or cryptographic hash, preserve that result, but do not run unknown utilities or execute the package merely to calculate more evidence. Note observed behaviour such as overlays, unexpected prompts, battery use, new administrators, or network warnings with exact times. Keep original screenshots and files isolated, and use redacted copies when reporting so account names, notifications, and identity details are not unnecessarily exposed. Do not email a live package to other people or upload it to an unknown analysis site. Evidence should distinguish claims made by the download page, properties reported by the platform, and behaviour you directly observed. That separation helps support staff assess the incident without asserting malware capabilities that have not been technically established.

Monitor financial and identity exposure

Uninstalling an app stops that installed copy from running, but it cannot retract passwords, messages, documents, contacts, or payment details that may already have left the device. Review email and financial session histories, new payees, card entries, password-reset notices, telephone-service changes, and identity-account alerts. Record pending, completed, reversed, and refunded transactions separately and contact the financial institution through an independent channel when activity is unfamiliar or credentials may be exposed. If identity documents were displayed or uploaded, list the visible fields and seek guidance from the issuing authority or a recognised identity-protection service. Continue watching for fake cleanup or recovery agents who cite details from the incident and request a fee, cryptocurrency, authentication code, or remote access. Preserve each later event as a new dated item rather than treating it as proof of the app's cause. Monitoring should be proportionate to the actual permissions and information exposed, while unexplained device behaviour after removal belongs with qualified platform support.

Suspect app containment plan
StageActionRecord
Before installationDecline sideloading and verify publisher independentlySource page, filename and claimed developer
After installationDisable elevated access and remove with platform toolsPermissions, install time and device behaviour
After removalSecure accounts from a clean device and monitorSessions, password changes and financial events

Frequently asked questions

Should I sideload a CrownPlay app?

No. Do not install an unknown package outside an official distribution channel to resolve an unverified operator claim.

Does an app icon prove who published it?

No. Check the developer identity and accountable store or platform records.

Which permissions deserve extra caution?

Accessibility, device administrator, screen capture, notification, SMS, contacts, microphone, camera and package-installation access.

What should I do after enabling suspicious accessibility access?

Stop entering information, disable that access through system settings and treat credentials used on the device as potentially exposed.

Why remove device-administrator access first?

Administrator privileges can prevent uninstall or allow stronger control, so they must be revoked through the platform's security settings.

Where should I change passwords?

Use a different trusted device, secure email first, revoke unfamiliar sessions and then replace reused passwords.

What app evidence should I preserve?

Keep the source, filename, publisher name, requested permissions, install time and any safe security-tool report.

Does uninstalling end every risk?

No. It removes the package but cannot retract credentials, messages or personal data already observed or transmitted.