Countries

Kenya

Kenya

What to hide on an M-PESA receipt before you share it

Since 24 March 2026, Safaricom hides part of the sender's name and number on the M-PESA confirmation SMS. The receipt looks safer than it used to. It still shows five things, and two of them identify you. Blank those two before you forward the screenshot to the family group.

What the SMS still shows

After the masking, the confirmation SMS carries five things:

  • The amount that was sent.
  • The date and time of the transaction.
  • The transaction code. Ten characters, something like TJ4A5B6C7D.
  • Two of the three names on the sender's M-PESA account. The middle name is dropped. John Maina Wao becomes John Wao.
  • The phone number, with the middle digits hidden. 0722***000, or in the international form 254725***568. The last three digits are still there.

The amount, the date and time, and the transaction code are the proof. They are why the family wants to see the SMS in the first place.

The name and the phone number are what identifies you.

The first four digits of a Safaricom number are 0722, 0725, 0729, and so on. They say "this is a Safaricom customer". They do not say which one. The last three digits are what names the specific line. Those three digits plus a first and last name are enough for a scammer harvesting WhatsApp groups to try the three missing digits one at a time, land on your real number, and call you back sounding like they already know you.

The two to blank before you share it

Before you forward it, blank these two fields.

  1. Paint over the sender's name on the first line. The whole name, not one word of it.
  2. Paint over the phone number. The whole string, including the masked bit. The last three digits still identify you.

Leave the amount, the date and time, and the transaction code visible. That is the proof the money arrived. That is what the group came for.

This is the same job at both ends. The daughter in the UK forwarding the "Confirmed. Ksh 20,000 sent to..." SMS, and the mother in Nairobi screenshotting the "You have received Ksh 20,000 from..." reply.

Catch

The ten-character transaction code is harmless on its own. It becomes the hook when a scammer pairs it with the name and the last three digits, so the call that comes an hour later sounds like it already knows you. Blank the two identifying fields and the code does nothing by itself.

The follow-up calls, the "I sent you money by mistake, please return it" messages, the fake Safaricom calls, those are covered in the M-PESA scams to warn your family about right now. This piece is only about the receipt, which is where the harvesting pipeline starts.

Corrections

None so far. If we get something wrong, the fix is dated here.