Quick answer

Fake M-Pesa screenshots are images edited to look like real confirmation messages. They are easy to produce and visually identical to genuine ones. The only reliable way to stop them is to verify payments in real time using M-Pesa STK Push via the Safaricom Daraja API. Your POS receives a direct, API-confirmed payment notification from Safaricom before the sale completes: no screenshot involved.

What fake M-Pesa screenshots look like

A real M-Pesa confirmation SMS looks something like this: "ZA1B2C3D4E Confirmed. KES 2,500.00 paid to SHOP NAME on 2/7/26 at 3:04 PM. New M-Pesa balance is KES 1,234.56."

A fake screenshot reproduces this format exactly. The transaction code, amount, recipient name, date, and balance are all editable. Several websites and apps let you generate a convincing fake in under 30 seconds: for free.

The fraud pattern at a retail shop is simple: a customer claims to have paid, shows a screenshot, and walks out with the goods before the cashier has had time to verify. In a busy shop, cashiers are under pressure to move fast, and a quick glance at a message is rarely enough to catch a fake.

The core problem: There is nothing in an M-Pesa SMS screenshot that a cashier can definitively verify without checking the Safaricom system directly. The transaction code on a fake screenshot is just made-up text.

Why screenshots are so easy to fake

M-Pesa confirmation messages follow a fixed, predictable format: which makes them straightforward to replicate. The message contains:

  • A transaction code (10 characters, alphanumeric)
  • The amount paid
  • The recipient name (which matches what you registered with Safaricom)
  • A date and time
  • A "new M-Pesa balance" figure

All of these are just text. An edited screenshot or a generator website can produce a message that is pixel-for-pixel identical to a real one. Even the green Safaricom sender header can be replicated.

The four ways shops verify M-Pesa: and why three of them fail

Look at the screenshot

Fails. Fakes are indistinguishable visually.

Check your M-Pesa SMS

Slow and unreliable during busy hours. SMS delays of 1โ€“5 minutes are common.

Call Safaricom to verify

Not practical for every transaction. Hold times make it unusable at the till.

STK Push via Daraja API

Works. Confirmation comes directly from Safaricom to your POS.

How STK Push eliminates screenshot fraud entirely

With M-Pesa STK Push integrated into your POS, the payment flow is completely different from the screenshot method:

  1. You ring up the sale and select M-Pesa as payment
  2. You enter the customer's Safaricom number
  3. The POS sends a payment request directly to Safaricom via the Daraja API
  4. A payment prompt appears on the customer's phone. They enter their PIN
  5. Safaricom sends a real-time confirmation callback to your POS
  6. Only when the POS receives that callback does the sale complete

The customer never sends a screenshot. There is no message for them to fake. The confirmation is a server-to-server API call that goes directly from Safaricom's systems to your POS. A customer cannot intercept, edit, or generate this.

Result: If the Safaricom callback does not arrive, the sale does not complete. No confirmation from Safaricom = no goods released. There is no way around this without the customer actually paying.

What about verifying M-Pesa via your statement or business portal?

Safaricom does provide a M-Pesa business portal and the MySafaricom Business app where you can see incoming transactions. Some shops use this as a verification method: the cashier checks the portal to confirm the transaction code from the customer's screenshot matches one in the system.

This is better than looking at a screenshot alone, but it is slow. In a queue of 5 people, checking a portal for every M-Pesa payment creates a bottleneck. And it still requires a cashier to manually match numbers: which means human error is still in the loop.

STK Push removes the human verification step entirely. The system checks with Safaricom automatically, before releasing the goods.

What to do about past M-Pesa fraud losses

If you have already experienced fake screenshot fraud, the most important steps are:

  • Do not pay out of pocket. Report the incident to Safaricom Business (0722 002 100 or your dedicated account manager). They can confirm whether the transaction code on the screenshot exists in their system.
  • Review your transaction history in the M-Pesa business portal. Any amount that appears in the fraud screenshot but not in your statement is a confirmed fake.
  • Retrain cashiers on the protocol: never release goods on a screenshot alone until you have moved to integrated STK Push.
  • Set up STK Push as soon as possible so that future payments bypass the screenshot step entirely.

Practical steps to protect your shop today

If you are not yet on integrated M-Pesa, here is what to do:

  1. Register a Safaricom Daraja developer account at developer.safaricom.co.ke if you do not have one
  2. Get your Daraja Consumer Key, Consumer Secret, and Passkey from the Daraja portal
  3. Connect your POS to Daraja, WebpinnPOS supports this in Settings โ†’ Integrations โ†’ M-Pesa
  4. Run a KES 1 test transaction to confirm the connection
  5. Instruct cashiers that M-Pesa payments now go through the POS: no screenshot is needed or accepted

For a complete walkthrough of the Daraja setup, see How to Accept M-Pesa Payments at a Physical Shop in Kenya.

Not sure whether to use a Paybill or Till Number with STK Push? See M-Pesa STK Push vs Paybill vs Till Number for the full comparison.

Frequently asked questions

Stop accepting screenshot payments today

WebpinnPOS integrates directly with Safaricom Daraja. Every M-Pesa payment is verified in real time: no screenshot, no fraud risk.

Start Free Trial
14 days free. No credit card required.