Booking from abroad

Is it safe to send card details on WhatsApp to pay for a ride?

Why card numbers never belong in a WhatsApp chat, five payment scam patterns to recognise in Pakistan transport bookings, how to check a genuine checkout link, what to share with the traveller instead, and who to call in the UK and Pakistan if the digits have already gone.

15 minute read English Free to read

Published Last reviewed Next review Editorial owner Shuaib Sakunder Fact reviewer Shuaib Sakunder

Hands holding a blank bank card and a smartphone at a desk beside a computer keyboard and mouse

Is it safe to send card details on WhatsApp to pay for a ride? No. Not to a driver, not to a “booking office”, not to a number that has your cousin’s name saved against it. WhatsApp encrypts the message on its way across, but once it lands, your card number, expiry date and security code sit in a chat that can be screenshotted, backed up, forwarded or read by whoever controls that phone. You have no way to check who that is. A genuine transport company does not need those digits typed into a chat, because it can send you to a payment page where you enter them yourself.

So the working rule for anyone paying from London, Dubai or Toronto for a parent landing in Lahore is simple: WhatsApp is for journey details; money goes through a checkout. The rest of this guide covers how the common fake-supplier tricks work, what a real checkout link looks like, what to share with the traveller instead, and exactly what to do and who to call if the card digits have already gone.

The decision in four lines

  • Card number, expiry, CVV, PIN or one-time passcode in a chat: never, whoever asks.
  • A payment link sent in a chat: do not open it from the chat. Go to the company’s website yourself and pay from your booking there or from the booking email.
  • Bank transfer to a personal account because “the card machine is down”: treat it as a warning sign, not a workaround.
  • Journey details for the traveller (reference, pickup point, time, driver name and vehicle once assigned): share freely on WhatsApp. That is what the app is good at.

Why card details in a chat are the wrong place, even with encryption

WhatsApp’s own privacy page says end-to-end encryption keeps “your personal messages, photos, calls and more” between you and the people you choose. That is true and useful. It is also the whole problem. Encryption protects the message in transit; it says nothing about who is holding the phone at the other end, or what they do next.

What happens to the digits after you press send

  • They persist. A card number in a chat stays in the chat history on both phones, in any chat backup, and in any screenshot, unless someone deliberately removes every copy. You cannot delete the recipient’s copy.
  • They travel. A dispatcher can forward the message to a colleague, a driver, a “manager”. Each forward is another phone you have never seen.
  • They are complete. Number, expiry and the three-digit code on the back are exactly what an online merchant asks for. In a chat, you have handed over the full set in one bubble.
  • They are unverifiable. A profile photo, a business name and a logo cost nothing to copy. A WhatsApp number tells you very little about the company behind it.

Compare that with a hosted payment page. You type the digits into a form run by a payment provider; the transport company sees a confirmation that you paid, not the card itself. Your bank may ask you to approve the payment in its own app. Nobody in the middle ever holds the full card details in a message thread.

The account itself can be taken over

There is a second risk that has nothing to do with the person you are paying. If your own WhatsApp account is hijacked, the attacker can read your history, including any card details you sent in the past. WhatsApp’s security page puts it plainly: “Set up a secret pin and never share it with anyone to prevent someone from stealing your account.” That PIN is two-step verification. Turn it on, and never read out a six-digit registration code to anyone who messages you asking for it.

WhatsApp payment scam patterns to recognise in Pakistan transport bookings

None of the patterns below needs technical skill. They work because a relative abroad is booking under time pressure, for someone else, in a country where WhatsApp really is how most drivers and small operators do business. The scammer borrows that normality. The following are illustrative examples of how the approaches are typically framed, not quotes from real cases.

1. The copied supplier

You search for an airport pickup, message a number from an advert or a social media post, and get a professional reply with a logo, a price and a request for “card details to secure the booking”. The name may be a real firm’s name. The number is not theirs. Example: “Salaam, your Islamabad Airport pickup is confirmed. Please send card number, expiry and CVV for the advance.”

2. The changed instructions

A booking starts genuinely, then a new message arrives: the “office” has a new account, the card system has failed, please transfer to this personal account instead. Take Five, the UK banking industry’s anti-fraud campaign, lists “payment instructions that suddenly change” among its key warning signs. Treat any change of payee that arrives in a chat as unconfirmed until you have checked it through a channel you found yourself.

3. The lookalike payment link

Instead of asking for the digits, the scammer sends a link. It opens a page that looks like a checkout, sometimes with a padlock, sometimes with your booking details pasted in. The address is a near-miss of a real domain, or an unrelated site entirely. The UK National Cyber Security Centre warns about exactly this: phishing messages that point you to fake storefronts, and its advice is to type the official website address yourself rather than follow the link.

4. The one-time passcode request

Example: “We sent a code to your phone to verify the payment, please share it.” The code your bank texts you is the bank asking you to approve something. Reading it out to a third party is approving it for them. The same trick is used for WhatsApp’s own registration code, which is how accounts get hijacked.

5. The refund that needs your card

After a cancelled or failed job, someone offers a refund and asks for card details “to send the money back”. Refunds on card payments go back to the card that paid through the payment provider. Nobody needs the number again for that.

The common thread, and the one Take Five builds its advice around: pressure to act quickly, an unexpected request for money or security details, and a channel you did not choose. Stop, challenge, then act.

The comparison is not “online versus chat”. It is about who ends up holding your card data and what recourse you have when something goes wrong.

Question Card details sent in a chat Hosted checkout page Bank transfer to a personal account
Who sees the full card number? Everyone with access to that phone, backup or screenshot The payment provider; the merchant sees a payment confirmation No card involved, but the payee is often unknown
Can you check who you are paying? Barely: a name and a profile photo Yes: the domain, the merchant name and the reference on the page Only the account name, which you cannot easily verify
Does your bank get a say? Not until the card is misused Often: your bank may ask you to approve in its app You authorise it yourself; hard to reverse
Is there a receipt tied to the booking? A chat message An emailed receipt with the booking reference A transfer slip, not linked to any booking
What UK guidance says Do not share security details Pay by card, preferably credit card NCSC: never pay by direct bank transfer

That last row matters for anyone paying from Britain. The NCSC’s guidance on shopping online securely recommends paying by credit card, noting that many card purchases are protected under the Consumer Credit Act, and says debit cards may give access to a voluntary chargeback scheme. On bank transfers it is blunt: “Never pay by direct bank transfer.”

What a genuine checkout link looks like

A real payment link is boring, and that is the point. Before you type a single digit, check:

  1. Where you got it. From the company’s own website, from your account there, or from the booking confirmation email sent after you booked on that website. Not from a stranger in a chat.
  2. The address bar. The domain is the company’s own, or a well-known payment provider’s hosted page that it hands you to. Read the whole domain, not just the start.
  3. Your journey on the page. The booking reference, route, date and amount match what you booked, in the currency you expected.
  4. Only card fields. A checkout asks for the card number, expiry and security code, and sometimes billing details. It never asks for your PIN or online banking password.
  5. Your bank’s own approval step. If your bank asks you to confirm, that request appears in your banking app or comes from your bank, not in a WhatsApp message from the supplier.
  6. A receipt afterwards. An email confirming payment against the same reference.

On iDrive, this is how payment is designed to work. You request the journey on the iDrive booking page, and where online payment is offered for that booking, the pay link arrives in the booking email and opens on idrive.pk before handing you to a Stripe-hosted card page. Stripe’s documentation describes this option as a redirect to “a Stripe-hosted page” where customers enter their payment details. The iDrive secure checkout is the only place card details are taken; iDrive has no reason to ask for them in a chat, and a message that does should be treated as not from us. Fares, availability and vehicle assignment are confirmed on the booking itself, not promised in a chat thread.

How to pay a driver without sharing card details: the booker and the traveller

Most of these payments are made by one person for another. A daughter in Birmingham books a car for her father arriving at Allama Iqbal International; a son in Riyadh arranges a driver day for his mother in Faisalabad. The payer and the passenger are different people, in different time zones, often on different phones. That split is where scammers operate, and it is also easy to manage well.

What stays with the payer

  • The card and everything on it.
  • The login to the booking account. If you pay through your iDrive customer account, the booking history, receipts and payment state stay there, visible to you and not to anyone you forward a message to.
  • Any code your bank sends to approve the payment.
  • Refund and cancellation questions, handled with the company through its own channels.

What goes to the traveller on WhatsApp

  • The booking reference.
  • Pickup point and time, written the way the traveller will recognise it: the terminal, the arrivals exit, the gate number of the housing society.
  • Drop-off address and any stops.
  • Driver name, phone number and vehicle, once the company has assigned them and told you. Not before.
  • A single line saying: “It is paid (or: payment is handled by me). If anyone asks you for money or card details, do not send anything; call me.”

That last line does most of the work. An elderly passenger who is told in advance that no one should ask for payment is much harder to pressure at the kerb or over the phone. If the traveller is the one who receives a call “from the booking office” asking for a card or a code, the answer is already agreed.

Our sister service Pakistan Taxi, which runs on the same iDrive network, has a practical walkthrough for families on booking and paying for someone else’s airport ride, including how to brief the passenger.

What to do if you already sent card details on WhatsApp

Speed matters more than embarrassment. The NCSC’s advice is to contact your bank immediately if you have shared sensitive information with scammers. In practice, work through this in order.

  1. Freeze or cancel the card now. Many banking apps let you freeze a card in seconds. Then call the bank on the number printed on the back of the card or in the app, never a number from the chat. In the UK you can also dial 159, which Stop Scams UK says connects to banks covering more than 99% of UK retail current accounts and “cannot be spoofed or impersonated”.
  2. Tell the bank exactly what was shared. Card number, expiry, CVV, any one-time code, any bank transfer made. Ask about disputing any payment you did not authorise.
  3. Keep the evidence. Screenshot the chat, the number, the profile, any link and any payment page before you block. Deleting your side does not delete theirs, and the record helps the bank and the police.
  4. Report and block the number in WhatsApp. WhatsApp says reporting messages, people or businesses helps keep the service safe, and that it will not tell the sender.
  5. Secure your own WhatsApp. Check that two-step verification is on. If you shared a WhatsApp registration code, treat the account as possibly compromised.
  6. Warn the traveller. If the scammer knows the flight and pickup, they may contact the passenger next.
  7. Be wary of a second approach. Treat any “refund”, “fraud team” or “recovery service” that contacts you afterwards and asks for details again with the same suspicion as the first message.
  8. Report it to the police service for where you live, as below.

Reporting taxi booking payment fraud in the UK and in Pakistan

Report where you live and where the money went. For a UK-based payer scammed by a Pakistan-based number, that can mean both. Always go to your bank first; the police report supports the bank’s work, it does not replace it.

Where you are First call Then report to Also useful
England, Wales, Northern Ireland Your bank (or 159) Report Fraud, online or 0300 123 2040 Suspicious texts to 7726; emails to report@phishing.gov.uk
Scotland Your bank (or 159) Police Scotland on 101 Same NCSC text and email routes
Calling from outside the UK Your bank’s overseas line Action Fraud’s international number +44 161 234 9230 (listed on its contact page) Online reporting runs 24/7
Pakistan (card or account with a Pakistani bank) Your bank’s helpline FIA complaint portal or helpline 1991 SBP’s Sunwai portal for banking complaints

In the UK

Report Fraud describes itself as the place to report cyber crime and fraud, and says that if you live in England, Wales or Northern Ireland, it is the service to speak to; residents of Scotland are directed to report via 101. Its phone line is 0300 123 2040. Action Fraud’s contact page lists the same number, weekday and weekend hours, and an international line, and adds a line worth remembering: it “will never ask for your bank details”. Anyone who calls claiming to be the fraud service and asks for your card is not.

The NCSC runs the forwarding routes for the scam message itself. Its phishing guidance covers each channel: forward scam texts free to 7726, forward suspicious emails to report@phishing.gov.uk, and use its separate reporting route for scam websites and adverts. A fake payment page sent to you on WhatsApp is a website: report the address.

In Pakistan

If the card or account is Pakistani, start with the bank’s own helpline and complaint process. Beyond that, the Federal Investigation Agency lists an online complaint portal at complaint.fia.gov.pk, helplines 051-111-345-786 and 1991, the email complaints@fia.gov.pk, and an Overseas Pakistani Complaint Cell. Complaint routes and contact numbers can change, so check the FIA site for the current route before filing. For complaints against a bank’s handling, the State Bank of Pakistan runs Sunwai, a portal for complaints on general banking and Roshan Digital Accounts, available in English and Urdu after you register.

Travelling on to Saudi Arabia for Umrah

Families booking a Pakistan airport run often arrange ground transport in Makkah and Madinah for the same trip. The same rules apply: verify the company, book on its own site, pay only through a checkout. Our sister company Hajj Umrah Taxi explains how to confirm a Saudi transport booking is genuine before you pay a deposit.

Questions people ask

Is WhatsApp end-to-end encryption enough to make sending card details safe?

No. Encryption protects the message while it travels. It does not control who reads it on the other phone, who it is forwarded to, or where backups and screenshots end up. The risk is the recipient, not the network.

Can I send just the last four digits to confirm which card I used?

Last four digits alone cannot be used to pay, and a genuine company can usually find your payment from the booking reference anyway. Never add the expiry date or the security code.

The driver says my payment has not arrived and asks me to pay him directly. What should I do?

Do not send anything. Check the payment state in your account or on the receipt, then contact the company through its website or booking email. If it was paid through the checkout, the company can see it.

Is a payment link from a WhatsApp Business account safe?

A business name and logo on a WhatsApp profile do not, on their own, prove the account belongs to the firm it names. Open the company’s website yourself and pay from your booking there.

The iDrive privacy policy sets out what booking and contact data we hold and why. When you are ready, request your journey on iDrive and keep the payment inside the checkout.

Sources and checking

We opened these sources during factual review. External pages can change; use the review date above to judge freshness.

  1. WhatsApp: End-to-end encryption keeps personal messages, photos and calls between you and the people you choose
  2. WhatsApp: Set up a secret PIN (two-step verification); reporting messages, people or businesses; sender not told; blocking
  3. Take Five to Stop Fraud (UK Finance): Stop, Challenge, Protect; warning signs incl. urgency and suddenly changed payment instructions; Report Fraud 0300 123 2040
  4. UK National Cyber Security Centre: Use a credit card (Consumer Credit Act protection), debit chargeback scheme, 'Never pay by direct bank transfer'; type official address your
  5. UK National Cyber Security Centre: Separate reporting routes for texts, emails, websites/adverts; contact bank immediately if sensitive details shared
  6. UK National Cyber Security Centre: Forward suspicious text messages free to 7726
  7. UK National Cyber Security Centre: Forward suspicious emails to report@phishing.gov.uk
  8. Report Fraud: The place to report cyber crime and fraud for England, Wales and Northern Ireland; Scotland reports via 101; phone 0300 123 2040
  9. Action Fraud: 0300 123 2040, international +44 161 234 9230, online reporting 24/7; will never ask for your bank details
  10. Stop Scams UK: 159 reaches banks covering more than 99% of UK retail current accounts and cannot be spoofed
  11. Federal Investigation Agency, Pakistan: Complaint portal complaint.fia.gov.pk, helplines 051-111-345-786 and 1991, complaints@fia.gov.pk, Overseas Pakistani Complaint Cell
  12. State Bank of Pakistan: Sunwai portal for complaints on general banking and Roshan Digital Accounts; English and Urdu; registration required
  13. Stripe: Checkout full-page option redirects customers to a Stripe-hosted page to enter payment details

Keep reading

A request, not a booking. No payment is taken. Check availability