Egypt's Central Bank warns InstaPay users about fraud calls and fake links
Egyptian media reports published this week cited a Central Bank of Egypt warning about fraud attempts involving callers impersonating InstaPay representatives and fraudulent links designed to obtain sensitive banking information.

CAIRO — Egyptian media reports published this week cited a warning from the Central Bank of Egypt to customers about fraud attempts involving callers who impersonate InstaPay representatives and attempt to obtain sensitive personal and banking information.
Cairo Stream was not able to locate a published statement carrying this specific warning on the Central Bank's own website, and this article does not present the warning as a document Cairo Stream has read in original form. What follows distinguishes throughout between the reported Central Bank warning, official InstaPay information verified directly by Cairo Stream, and general consumer-safety guidance.
The warning comes as digital payments continue to grow in Egypt and more consumers rely on mobile applications to transfer money and access financial services.
According to reports citing the Central Bank's warning, fraudsters may contact users by telephone while claiming to represent InstaPay or related banking services. Some attempts are also reported to involve links intended to direct victims to fraudulent websites designed to collect confidential information. Customers have been urged not to disclose sensitive banking information to unexpected callers.
The reported warning is consistent with earlier, separately reported Central Bank messaging. In mid-August the Central Bank launched a nationwide customer-awareness campaign with banks operating in Egypt under the slogan “Together Against Fraud”, urging customers not to share personal or banking details with anyone. In late August the bank published an awareness message on its official Facebook page warning customers not to share one-time passwords with anyone.
How the reported fraud attempts work
The reported attempts rely primarily on impersonation and social engineering rather than on any technical compromise of banking systems.
A caller may claim that there is a problem with an InstaPay account, that a transaction needs to be verified, that the account requires an urgent update, or that banking information must be confirmed.
The customer may then be pressured to share a password, provide a PIN, reveal a one-time verification code, hand over card or banking information, or open a link sent through SMS or a messaging application.
Fraudulent links may lead to websites built to resemble legitimate financial services. Once sensitive information is entered, criminals may attempt to access financial accounts or authorise transactions.
Cairo Stream is not reporting how many people have been targeted, how much money may have been lost, or whether any of these attempts are connected to one another or to a single group. No such figures or findings have been officially published, and none should be assumed.
What InstaPay users should never share
As a general safety rule, none of the following should be provided to an unexpected caller: one-time passwords, an InstaPay or transaction PIN, bank passwords, debit or credit card details, banking login credentials, or sensitive personal information requested through an unsolicited call or message.
This is grounded in InstaPay's own documentation rather than in general advice alone. InstaPay's published terms define confidential user data as the data used to authenticate transactions and access the service — including authentication PINs and one-time codes — and place responsibility for keeping those credentials confidential on the customer. InstaPay's published customer information also states that the application itself has no access to the sensitive data secured by the customer's bank.
A legitimate representative therefore has no operational reason to ask a customer to read out an OTP or a PIN over the telephone.
Why fake links are dangerous
Fraudulent links are the standard instrument of phishing. A link may open a website that closely resembles a bank or financial service, copying logos, colours, login pages, banking forms and payment interfaces. The purpose is to convince the user that the page belongs to a legitimate organisation.
Unexpected links deserve caution whatever the channel — SMS, WhatsApp, Facebook Messenger, Telegram, email or a social-media message.
When in doubt, the safer action is to close the message, open the official application directly, or type the organisation's verified website address manually rather than following a link sent by an unknown caller or account.
The same pattern appears in other consumer cases Cairo Stream has documented, including a customer who paid an account for Facebook followers and then lost contact with the seller.
What to do if someone calls claiming to be from InstaPay
First, do not provide confidential information. Passwords, PINs, OTP codes and banking credentials should never be shared on a call you did not initiate.
Second, do not open links sent during or after the call, even if the caller says a link is needed to verify, update or protect the account.
Third, end the conversation. Urgency and pressure are the mechanism the approach depends on, and there is no cost to hanging up and checking independently.
Fourth, contact official channels directly. InstaPay's official contact page lists 15989 as the customer-service number for InstaPay inquiries, and states that complaints related to registration or to a financial transaction should go to the customer's own bank. Member-bank call-centre numbers are published on the same page.
Fifth, if information may already have been shared, contact your bank immediately using a customer-service number you have verified independently — from the back of your card, the bank's official application, or the bank's own website — rather than a number supplied by the caller.
Digital payments bring convenience — and new security risks
InstaPay has become an increasingly important part of Egypt's digital financial ecosystem. The application, operated by the Egyptian Banks Company for Technological Advancement and licensed by the Central Bank as a payment service provider on the Instant Payment Network, gives users access to linked bank accounts and instant transfers from a mobile device.
The growth of digital financial services also creates opportunities for criminals to exploit public trust in well-known applications and brands. Financial fraud of this kind depends on impersonation and social engineering rather than on technical attacks against banking infrastructure: in many cases the objective is to persuade a customer to voluntarily hand over the information needed to reach the account.
That is what makes public awareness a component of digital security rather than a supplement to it — a point that also runs through Egypt's wider digital identity and eKYC framework.
Cairo Stream's digital safety checklist
Before responding to any unexpected financial call or message, four questions are worth asking — STOP.
S — Suspicious: did the person contact you unexpectedly? T — Time pressure: are you being told you must act immediately? O — Official verification: can you independently confirm who is contacting you? P — Personal information: are you being asked for passwords, PINs or OTP codes?
If any of those raise a concern, stop the interaction and contact the organisation yourself through its official website, application or an independently verified telephone number.
What users should remember
No legitimate security process requires a customer to casually disclose passwords, OTP codes, PIN numbers, banking login credentials or complete card details on an unsolicited telephone call.
When in doubt: hang up, open the official application yourself, and contact your bank or InstaPay through an independently verified official channel.
Why this matters
The reported warning matters because Egypt's digital financial ecosystem keeps expanding. Millions of users now rely on instant payment applications and mobile banking for routine transactions, and the same growth in digital financial services that has made those tools normal has also widened the pool of people an impersonation attempt can reach.
As more financial activity moves online, protecting users from phishing, impersonation and social-engineering attempts becomes a larger part of the work — and digital safety awareness has to grow alongside Egypt's digital transformation rather than behind it.
Sources
- Reports citing a Central Bank of Egypt warning to InstaPay users about impersonation calls and fraudulent links, published 3–4 September 2026 (secondary reporting; Cairo Stream could not locate the original warning on the Central Bank's own published channels)
- Amwal Al Ghad — “Egypt’s central bank launches nationwide campaign to combat banking fraud”, reporting the Central Bank’s “Together Against Fraud” awareness campaign with banks, 13 August 2026
- Egypt Independent — “Central Bank of Egypt issues urgent message regarding OTPs”, reporting an awareness warning published on the Central Bank’s official Facebook page, 29 August 2026
- InstaPay — official website
- InstaPay — official Contact Us page (InstaPay inquiries: 15989; registration and transaction complaints directed to the customer’s bank; member-bank call-centre numbers)
- InstaPay — official Q&A and information-security information (sensitive data secured by the customer’s bank; InstaPay has no access to it; card PIN used during onboarding)
- InstaPay — official Terms and Conditions (definition of confidential user data covering authentication credentials such as PINs and one-time codes; InstaPay described as a Central Bank-licensed PSP application on the IPN network)
- Central Bank of Egypt — cybersecurity awareness pages
Sourcing note: Cairo Stream searched the Central Bank of Egypt’s website and published channels and could not locate the original text of the InstaPay-specific warning. The existence and content of that warning are therefore attributed to Egyptian media reports citing the Central Bank, and are described as reported rather than as a document Cairo Stream has read. Separately reported Central Bank messaging — the “Together Against Fraud” campaign and the OTP awareness post on the bank’s official Facebook page — is attributed to the outlets that reported it. All statements about InstaPay’s credentials, confidentiality rules and customer-service channels are taken directly from InstaPay’s own published pages and terms. The remaining guidance is general consumer-safety advice and is presented as such. No victim counts, loss figures or attributions to any identified group appear in this article, because none have been officially published.
Cairo Stream attributes every factual claim to a named source and links to the specific document, release or bulletin wherever one is publicly available. Figures are reported as published by the organisation named above.
Share
These buttons let readers share this article from their own accounts. Cairo Stream does not operate accounts on X, LinkedIn or Facebook.
