📱 Over the past three weeks, EnterpriseAM spoke to multiple people who had been exposed to a phone scam. Three of them actually lost money to the same script. Each was contacted by someone posing as an Instapay customer service representative, told their account data needed urgent updating, and walked through a sequence of “transfers” framed as a routine verification step. Two were scammed out of EGP 80k each; a third lost EGP 50k to an identical, repeatable con. The pattern is circulating widely enough that Instapay posted this warning on their official instagram page on 14 June.
The people falling victim to the scam that we spoke to are all financially and digitally literate professionals. “In hindsight, I know that I should have known better and that the aggressive way that I was being manipulated to transfer money out of my account should have immediately raised alarm bells, but there was something about the assertiveness of the communication that compelled me to act on their requests,” says one of the victims. “I also received an SMS alert that indicated that I had received money that I needed to transfer back as well as a fake OTP that appeared as if it had come from my bank. The way that the whole thing was carried out that tells me this is part of a large criminal organization,” she adds.
Criminal organizations are run like corporations. When Charles Lobo, Visa senior vice president and regional risk officer for Central Europe, the Middle East, and Africa (CEMEA) describes the people trying to steal your money, he reaches for an org chart. “Global crime has never been more organized, it is no longer only banks and businesses that have a CEO and a CTO,” he said at a recent industry gathering at the Visa Payments Forum (VPF) in Paris attended by EnterpriseAM. “Criminal organizations now have exactly the same structure. They have KPIs, targets, and mission statements,” he added.
Local scams have been linked to larger international organizations. Last February, the Interior Ministry reported the arrest of a criminal network that collaborated with “international criminal elements” to defraud Instapay users through “flash SMS” that included unsafe links.
Fraud as an industry
Modern attacks are multimodal and multi-channel. The mechanics of what transpires in Egypt’s recent wave of Instapay impersonations track almost precisely with how Lobo describes a modern attack. What looks like an isolated call is usually “the end of a long chain of preparation,” he said: a stray verification call to confirm a number belongs to you, a message with a link to capture another data point, each fragment stitched into a profile convincing enough to survive a live phone conversation. By the time the “representative” establishes contact, the target has already been researched. And the attack is designed to move across rails — what starts as one suspicious contact, in Lobo’s telling, “very quickly morphs into an account-to-account domestic transaction and then gets cashed out.”
AI as a force multiplier for good and for bad: What makes these types of scams scalable is the same technology the legitimate economy is racing to adopt. Close to half of attempted fraud, Lobo said, is now orchestrated through AI. “Gone are the days where you have bad guys sitting in garages with phones and swapping Sim cards. Criminal elements have access to the same tech that we are so proud to use, as a result, the sophistication with which they are able to put those technologies to use and craft an attack is like never before,” he said.
Visa’s annual Stay Secure study, conducted across 17 CEMEA markets, puts financial scam exposure in Egypt at 36%. Among those who were exposed, 46% said it happened on social media, the single largest channel. The generational data is even more alarming: 91% of Egyptian respondents worry that children cannot recognize a scam, and 61% have watched a child fall victim while gaming or shopping online.
Who’s responsible for keeping consumers safe?
The survey findings expose a gap between where consumers place responsibility and where they sit in the chain. Only 13% of Egyptians think they should be primarily responsible for protecting themselves online; 47% point to the government and regulators, 43% to banks, and 28% to payment providers. The majority, 64%, said real-time alerts from their bank or payment app when something looks suspicious would make them feel more secure.
That points to the conclusion Visa executives keep returning to: it’s everyone’s responsibility. “But consumers expect financial institutions, governments, and payment providers to take the lead, underscoring the importance of secure-by-design payment systems,” said Leila Serhan, Visa’s group country manager for North Africa, Levant, and Pakistan. “Security has to be embedded intentionally into every product, not bolted on after the loss,” Lobo added.
“Security and fraud detection is at the top of the list in every single conversation I’ve had with CEOs, heads of state, government officials, fintechs, and venture capitalists over the past four years,” Oliver Jenkyn, Visa’s group president, told the VPF. “[And] for good reason, because if we are not able to provide that solid foundation, trust, security, and fraud protection, then we’re not going to be able to continue to enjoy the wonderful growth and innovation in digital payments. It is critically important that we achieve this.”