Pathwise

Stay Safe Online · Lesson 7 of 12 · 12 min

Pay without handing over your card

Know which card details let someone send you money and which let them spend it, check a payment page before you type, and read the one-time code message properly.

TWO KINDS OF DETAILS

Details to receive, details to spend

To send you money, someone needs only your card number or your account number (IBAN). That's it. Everything else on or around your card is for spending: the security code on the back (CVV2), the expiry date, your password and any one-time code. Nobody ever needs those to pay you.

A buyer who says "enter your expiry date and the code we just texted you so I can deposit the money" is asking for spending details. Whatever the story, the answer is no.

Check yourself

Arash is selling his bike on an online marketplace. A buyer agrees the price without haggling and sends a link: "to receive the money, open this and confirm your card." The page asks for his card number, CVV2, expiry and one-time password. What should Arash do?

  1. Fill it in, but only if the page shows a padlock and his bank's logo
  2. Fill in the card number and CVV2 but leave the password blank, to be safe
  3. Close it and send only his card number or IBAN as a text message
  4. Ask the buyer to call him and read the details out on the phone instead
Show the answer

Close it and send only his card number or IBAN as a text message

Right. Receiving money never needs spending details. A page that asks for them to "receive" a payment is built to take money out, not put it in.

Payment gateway

NOUN · PAYMENTS

The page where you actually type your card details when you buy something online. The shop sends you there, the gateway talks to your bank, then sends you back. In Iran, genuine card payment pages are run through Shaparak, and their address ends in shaparak.ir right before the first single slash. Elsewhere, the page usually belongs to the shop, a known payment company or your own bank.

https://sep.shaparak.ir/… ends in shaparak.ir. https://shaparak-pay.com/… and https://shaparak.ir.pay-online.net/… do not: the first ends in shaparak-pay.com, the second in pay-online.net.

Five seconds before you type a card number

  1. How did you get here?

    From a shop you opened yourself: fine so far. From a link in an SMS, a chat or an ad: stop. Open the service yourself instead.

  2. Read the address, not the logo

    Find the part right before the first single slash. For an Iranian card payment it must end in shaparak.ir. Logos and colours are free to copy.

  3. Check the shop name and amount

    A real gateway shows who you are paying and how much. If either is wrong or missing, leave.

  4. Be careful inside apps

    A payment page opened inside a messenger or an app's built-in browser may hide the address bar. If you can't see the address, you can't check it.

Check yourself

Does this Iranian payment address pass the check?

  • https://sep.shaparak.ir/payment
  • https://shaparak-ir.com/pay
  • https://shaparak.ir.pay-online.net/card
  • https://pec.shaparak.ir/NewIPG
  • https://shaparrak.ir/ipg
  • https://my-bank.ir/shaparak.ir/pay
Show the answer

Passes the check: https://sep.shaparak.ir/payment, https://pec.shaparak.ir/NewIPG

Fails the check: https://shaparak-ir.com/pay, https://shaparak.ir.pay-online.net/card, https://shaparrak.ir/ipg, https://my-bank.ir/shaparak.ir/pay

Why one-time codes help, and where they don't

A fixed password

The same every time. If a fake page captures it once, it works again and again until you change it.

A one-time code

Made for one payment and valid for a short time. The message usually says the amount and the shop. It protects you only if you read that message before you type the code.

Check yourself

Mina is buying mobile credit through a link someone sent her. She asks for a one-time code, and the message shows a much bigger amount and a shop she has never heard of. It's safe to type the code, because it came from her own bank.

Show the answer

False

The code is genuine, but the payment it approves isn't hers. The mismatch means someone is using her card details for their own purchase right now. She should not type it, and should call her bank to block the card if she already entered her details.

Everyday payment habits

  • Turn on your bank's SMS or app alerts, so you see every payment the moment it happens.
  • Keep a separate card with a small balance for online shopping, and move money onto it when you need it.
  • Only save your card on sites and apps you use often and trust.
  • Open shops and your bank yourself, from a bookmark or the official app, not from links.
  • If you think your card details leaked, call your bank and block the card first. Ask questions after.

Check yourself

Hamid's cousin abroad, Laura, wants to send him money for his birthday. She messages: "Send me a photo of both sides of your card so I get the numbers right." What is the best reply?

  1. Send only the front, since the security code is on the back
  2. Type out just the card number or IBAN and send that
  3. Send both sides, because she's family and the chat is private
  4. Send both sides, then delete the photo from the chat once she has it
Show the answer

Type out just the card number or IBAN and send that

Yes. The card number or IBAN is all she needs. A photo carries more than you mean to share, and a chat can be read by whoever gets into either phone.

Lesson recap

  • To pay you, people need only your card number or IBAN. CVV2, expiry, passwords and codes are for spending.
  • Before typing card details, read the address: for Iranian card payments it must end in shaparak.ir right before the first slash.
  • A padlock means encrypted, not honest.
  • Read the one-time code message: if the amount or shop is wrong, don't type it and call your bank.

Keep it, don't just read it

Pathwise brings each idea back just before you'd forget it, with a quick question. Free on Android and on the web, in English and Persian.

Cafe Bazaar Myket Open the web app

All lessons in this course

  1. How accounts really get taken
  2. Strong passwords you don't have to remember
  3. Two-step login: a stolen password isn't enough
  4. Phishing: the message that wants you to hurry
  5. Fake pages, fake payment gates and fake apps
  6. SMS, call and messenger scams
  7. Pay without handing over your card
  8. Public Wi-Fi and your home network
  9. Share less, on purpose
  10. Stop pressing "later"
  11. Backups: the 3-2-1 rule
  12. If you get hacked: the first hour