Buy a top-up and send a photo: the scam targeting drivers and couriers
CERT Orange warns about criminals obtaining top-up codes from drivers and couriers. Learn how to recognise the request and set clear rules for extra purchases.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 3 October 2026
- READING TIME
- 5 min read
- TOPIC
- Human Security
CERT Orange Polska issued a warning on 1 October about a scam targeting drivers and couriers. Someone posing as a customer asks them to buy a gift card or prepaid top-up with their own money, then send a photograph of the code. Once the code is received, its value can be used before the driver arrives and discovers that the promised reimbursement will not happen.
The warning describes an abuse of trust during customer service. It does not report a breach of transport platforms. The problem arises when an extra request bypasses the order, payment and delivery confirmation process.
Why a photograph can transfer monetary value
A worker may think of a photograph as a simple proof of purchase. If it displays a code that can redeem the card’s value, the recipient receives much more than confirmation. They do not need to accept a delivery or pay for a ride to attempt to use the exposed code.
Breachroad’s conclusion: training should help people recognise what they are actually handing over. The same question is useful when dealing with a login code, password reset link or invitation to a company resource. What matters is the capability the recipient gains, regardless of whether the requester calls it “confirmation”.
Training example: an extra request during a trip
Consider a fictional exercise. A driver receives a message asking them to buy a top-up. The sender promises reimbursement on arrival and says that a photograph will confirm the correct product was purchased. The order in the app includes neither this purchase nor a payment arrangement for it.
The safe decision is to pause the extra task. The driver can reply: “An additional purchase needs confirmation through the official channel and an agreed payment method. I do not send redemption codes.” They then use the app’s help function or the agreed contact for their dispatcher. A number supplied by the person making the unusual request should not independently establish that person’s credibility.
This is our training scenario, not an account of an identified victim. Its purpose is to practise declining the request without having to recognise every card brand or variation of the story.
What a driver should do with this request
- Compare it with the order. Check whether the official service covers the purchase, cost and recipient. A promise in a message does not replace a confirmed payment arrangement.
- Pause payment and disclosure of the code. Do not fund an unconfirmed service with personal money. Do not send a photograph of a card or receipt containing a redemption code.
- Use an established help route. Report the request through the official app or a previously agreed company contact. The person asking for money should not choose the verification channel.
- Keep details of the attempt. Record the order identifier, time and conversation in line with company procedure. Remove customer details and all usable codes before sharing material for training.
If a code has already been disclosed, promptly contact the card or top-up issuer’s support and the platform through their official channels, providing the time and relevant details. Whether the value can be stopped depends on the product and whether it has already been redeemed; reporting does not guarantee reimbursement.
How an employer can make the right decision easier
We recommend one short rule across the team: an extra purchase needs an approved scope and payment method before it is made. The procedure should name a person available during the shift, an escalation channel and a fallback if nobody responds. Otherwise, a worker may have a written rule without practical help when it matters.
It is also useful to separate reporting from blame. A worker who promptly reports a disclosed code gives the company an opportunity to respond. Hiding a mistake extends the period in which nothing can be checked or stopped.
Cybersecurity and phishing training can include scenarios for field teams: unexpected purchases, customer impersonation and contact verification. For anyone who also disclosed login details, we have a first-hour response plan after phishing.
Source and our recommendations
The report of the scam comes from CERT Orange Polska’s warning of 1 October 2026. The exercise, proposed approval procedure and guidance for managers are Breachroad recommendations. We do not attribute them to particular platforms or suggest that every company uses the same payment arrangements.

