On 17 September 2026, the Barbados Police Service's Cybercrime Department confirmed what finance departments across the Caribbean have not been saying out loud: financial controllers, the people who approve wire transfers, are now the most targeted employees in the region. Business email compromise, a fraudster posing as a vendor, a director, or a bank to redirect a payment, does not require breaching a firewall. It requires one convincing message and one rushed approval. AI trained on a company's own payment history can flag the moment an invoice departs from that pattern, before the transfer clears, which is the one point in the process where stopping the fraud still costs nothing.
A Warning From Bridgetown
The Barbados Police Service issued two separate warnings on the same day. The first, from the Cybercrime Department, said financial controllers within business organisations are increasingly being targeted by threat actors, and that the unit has seen a rise in compromised business emails, the technical term for messages that appear to come from a trusted internal or vendor account but do not.
The second warning, from the Fraud Department, came from Inspector Dudley Walrond, who flagged a broader rise in phishing emails, investment scams, online vehicle scams, and bank card fraud across the island. Walrond urged the public to "be more cautious with their bank cards, as these can be easy targets for perpetrators." Two units inside the same police service, publishing warnings on the same day about related but distinct schemes, is not a coincidence. It is what a genuine spike in reported cases looks like from the inside.
Barbados is not describing a new phenomenon so much as naming one that has been building for years. The island recorded a 700% increase in direct electronic transfers between 2013 and 2024, according to an analysis published on 14 September 2026 by Ambassador Dr Clarence E. Pilgrim in Antigua News Room and CaribPulse. Every one of those transfers is a moment a fraudster can try to intercept, and the volume has grown roughly eightfold in a decade while the controls around who approves a payment have, in most Caribbean businesses, not changed at all.
The Numbers Behind the Warning
Pilgrim's analysis pulls together central bank and financial regulator data from across CARICOM, and reading the figures side by side makes clear that Barbados is one data point in a regional pattern, not an isolated case. The Bahamas processed an estimated B$10.4 billion in retail clearing transactions in 2024. Belize recorded a 75.3% increase in instant transfers in 2025. Guyana's electronic funds transfers total an estimated G$881.7 billion. The Bank of Jamaica received 443 consumer complaints in 2025, 87 of them fraud-related. Trinidad and Tobago's cybersecurity incidents more than doubled between 2023 and 2024. The Eastern Caribbean Central Bank logged an estimated EC$765,000 or more in losses from phishing attacks between January 2023 and March 2024 alone.
Trinidad and Tobago's own Cyber Security Incident Response Team, TT-CSIRT, published a 2025 annual report with the sharpest breakdown of the mechanism at work. Of 91 reported cyber incidents that year, down from 118 in 2024, 63 incidents, nearly 70%, were attributed to combined phishing and business email compromise campaigns. Ransomware, by contrast, fell from 9 incidents to 5. The same report disclosed over TT$3 million in cyber-enabled fraud losses within the local banking community for the fiscal year reported in October 2025, and cited regional data showing Caribbean hospitality and tourism organisations facing more than 2,500 cyber-attacks a week, with 42% of successful breaches traced to misconfigured devices and systems, not sophisticated hacking.
The SOCRadar CARICOM Threat Landscape Report 2026 adds the sectoral picture. Data breach and compromise account for 71.84% of all observed threat activity across the region. Finance and insurance alone draw close to 69% of regional phishing activity, more than any other sector, including government. That is the industry Barbados's financial controllers work in, and it is not a coincidence that they are the ones being named in a police warning.
Why Financial Controllers Are the Target
A financial controller sits at the one point in a company where a single approval moves real money. Fraudsters know this, and business email compromise is built around it. The typical attack does not look like malware or a suspicious link. It looks like a routine request: a long-standing supplier writing to say its bank account has changed, a managing director emailing from a slightly altered domain to ask for an urgent transfer before a deal closes, a bank officer calling to confirm a wire that was never actually initiated.
What makes these messages work is specificity, not sophistication. A fraudster who has read a company's public tender documents, LinkedIn announcements, or a leaked invoice already knows the vendor's real name, the usual payment amount, and the controller's own title. The message does not need to be perfect. It needs to match what the controller already expects to see on an ordinary Tuesday.
Volume and pressure work in the fraudster's favour here. A controller processing dozens of legitimate payment instructions a week has little time to interrogate each one individually, and the fraudulent request is deliberately timed to arrive close to a deadline, a payroll run, a contract signing, a public holiday, when the instinct to move quickly outweighs the instinct to verify. None of the human failure here is carelessness in any meaningful sense. It is what happens when a manual verification step depends on a person having the time and suspicion to apply it consistently, every single time, with no exceptions.
Where AI Actually Fits
None of what follows removes the need for a human to authorise a payment. What AI changes is what that human sees before they approve it, and how much of the pattern-matching that catches fraud no longer depends on one person's attention on one particular morning.
1. Payment-anomaly detection on the finance inbox
An AI model built on a company's own accounts payable history learns which vendors it pays, in what amounts, on what schedule, and to which bank accounts. When an incoming invoice or payment instruction breaks that pattern, a new account number for a supplier of five years, a request outside normal business hours, an amount inconsistent with the vendor's usual invoices, the system flags it for a second check before the transfer is queued, not once it has already gone out. This is the direct answer to what the Barbados Cybercrime Department described: a rise in compromised business emails aimed specifically at the people who approve payments.
2. Callback verification against voice cloning
Business email compromise is increasingly paired with a phone call, sometimes using a cloned voice of a real director or bank officer, to add urgency and legitimacy to a fraudulent request. A written policy requiring any change to payment details to be confirmed by calling a number already on file, never one supplied in the suspicious message itself, defeats this regardless of how convincing the voice sounds. AI liveness-detection tools can add a technical layer on top of that policy for organisations processing large transfer volumes, but the callback discipline works even without the technology. It belongs in the process, not just a vendor's product brochure.
3. A shared regional fraud fingerprint network
Fraud infrastructure gets reused. A domain registered to impersonate a Barbadian vendor this month may resurface targeting a Jamaican or Trinidadian company next month, using the same hosting provider, the same wording template, the same payment redirect pattern. Pilgrim's proposed CARICOM Cyber Fraud and Citizen Protection Network, linked to CARICOM IMPACS, is the natural home for an AI correlation layer that checks new fraud reports against a shared regional database of known infrastructure, the same principle CARICOM IMPACS already applies to smuggling networks through operations like Operation Eclipse. A fraud pattern flagged in Bridgetown could be checked automatically against reports filed in Kingston, Port of Spain, or Georgetown, instead of each jurisdiction discovering the same scheme independently, months apart.
4. Role-specific simulated training
TT-CSIRT's own guidance already calls for simulated phishing exercises and role-specific training for finance teams on invoice fraud and impersonation. AI can generate realistic, regularly refreshed simulated BEC attempts tailored to a specific company's real vendor relationships and communication style, which trains financial controllers against the actual pattern of attack they are likely to face, not a generic phishing template that stopped resembling real fraud years ago.
The Core Argument
Barbados cannot stop fraudsters from sending fake invoices, and a human still has to approve every payment. What AI changes is how much of the pattern-recognition behind that approval depends on one controller's attention on one particular morning. A model trained on a company's own payment history, a callback policy that defeats voice cloning by default, and a regional fraud-fingerprint network built on infrastructure CARICOM IMPACS already runs would close most of the gap the Barbados Police Service just named publicly. The data to build all three exists today, scattered across TT-CSIRT, the Eastern Caribbean Central Bank, and Barbados's own Cybercrime Department. What is missing is a shared system to act on it before the transfer clears, not after.
The Fix Nobody Is Funding Yet
Pilgrim's proposal, a common Fraud Loss and Recovery Reporting Framework paired with a six-month technical working group to design a CARICOM Cyber Fraud and Citizen Protection Network, is specific enough to act on and has not, as of this writing, been formally adopted by any regional body. That gap is worth closing before the next Barbados-style warning lands in a different capital with a different set of numbers attached.
Barbados's own Cybercrime Department and Fraud Department already collect exactly the kind of case data an AI anomaly model needs to train on: confirmed fraudulent invoices, confirmed compromised accounts, confirmed vendor impersonation attempts. Formalising that data into a shared training set, even one used only within Barbados to start, would sharpen detection faster than waiting for a regional framework to be agreed by consensus among fourteen member states.
For individual businesses, the fix costs far less than the fraud does. A written callback policy for any change to vendor payment details, a second sign-off on transfers above a set threshold, and a payment-anomaly tool priced for a small business rather than a multinational bank would have stopped the majority of the cases TT-CSIRT logged as phishing and BEC in 2025. None of it requires waiting on CARICOM.
What This Doesn't Solve
The same generative tools that can flag a fraudulent invoice can also write one. A controller who receives an AI-drafted BEC message today is reading prose that is grammatically flawless, stylistically consistent with the impersonated sender, and free of the spelling errors that used to be the easiest tell. Detection has not caught up to generation in every case, and it will not stay caught up permanently; the fraud infrastructure gets better at the same pace the defences do, which is the honest limit of everything described here.
Nor does any of this fix the decision a busy controller makes under deadline pressure to skip the callback because the request looks routine and the day is already full. A tool can surface the anomaly. It cannot make someone stop and check it. Barbados's warning names a real and growing problem with real regional data behind it. Whether the region closes the gap with a shared system, or keeps absorbing the loss one company at a time, is still an open question, and the answer to that one has nothing to do with the technology.
Frequently Asked Questions
What is business email compromise?
Business email compromise, or BEC, is a fraud in which a criminal impersonates a trusted party, a vendor, a company director, or a bank, by email or a spoofed lookalike account, and convinces someone with payment authority to redirect a transfer. On 17 September 2026, the Barbados Police Service's Cybercrime Department confirmed that financial controllers inside Barbadian businesses are increasingly being targeted this way, describing a rise in compromised business emails.
Is business email compromise a real risk for small Caribbean businesses, or only large companies?
It applies to businesses of any size that make electronic payments, which in 2026 means almost every registered business in the region. Barbados recorded a 700% increase in direct electronic transfers between 2013 and 2024, and Belize saw a 75.3% jump in instant transfers in 2025 alone. A small firm with one person approving payments is often an easier target than a large one with a finance team, because there is no second person to question an unusual request.
How does AI detect business email compromise before the money is sent?
AI payment-anomaly systems build a working model of a company's normal financial behaviour: which vendors it pays, what amounts, what bank details, and how often those details change. When an incoming invoice or payment instruction departs from that pattern, a new account number for a long-standing supplier, an urgent request outside normal hours, wording that mimics a director's usual style but is not quite right, the system flags it for manual verification before the transfer is approved rather than after the money has already left.
How much has business email compromise cost Caribbean businesses?
Trinidad and Tobago's Cyber Security Incident Response Team recorded over TT$3 million in cyber-enabled fraud losses within the local banking community in the fiscal year disclosed in October 2025. The Eastern Caribbean Central Bank logged an estimated EC$765,000 or more in losses from phishing attacks between January 2023 and March 2024. Neither figure captures losses that companies choose not to report, which most fraud investigators believe is the larger share.
What is the difference between phishing and business email compromise?
Phishing casts a wide net with a generic lure, a fake login page or a malicious attachment sent to many recipients, hoping a few click. Business email compromise is targeted and personal: the fraudster researches a specific company, learns who approves payments and who its real vendors are, and crafts a message that looks exactly like a routine internal request. Trinidad and Tobago's 2025 data shows the two often overlap in practice: of 91 reported cyber incidents, 63, nearly 70%, were attributed to combined phishing and BEC campaigns.
Are Caribbean governments regulating business email compromise and cyber fraud?
Enforcement runs through existing cybercrime and fraud law in most territories, and dedicated units are already active: the Barbados Police Service runs both a Cybercrime Department and a Fraud Department, and Trinidad and Tobago's TT-CSIRT publishes an annual incident report. What does not yet exist is a shared CARICOM-wide reporting standard. Ambassador Dr Clarence E. Pilgrim's September 2026 proposal calls for a common Fraud Loss and Recovery Reporting Framework and a CARICOM Cyber Fraud and Citizen Protection Network linked to CARICOM IMPACS, with a six-month technical working group to design it. As of this writing, that proposal has not been formally adopted.
Can voice cloning make business email compromise worse?
Yes. The next step beyond a fraudulent email is a fraudulent phone call using a cloned voice of a real director or bank officer, instructing a financial controller to approve a transfer immediately. A written callback policy, calling a vendor or director back on a number already on file rather than one supplied in the suspicious message, defeats this regardless of how convincing the voice sounds, and AI liveness-detection tools can add a technical check on top of that human process for organisations handling large transfer volumes.
What should Caribbean businesses expect on cyber fraud over the next two years?
Expect the volume to keep rising with the volume of electronic payments themselves. Guyana's electronic funds transfers already total an estimated G$881.7 billion and the Bahamas processed roughly B$10.4 billion in retail clearing transactions in 2024, and neither figure is levelling off. The SOCRadar CARICOM Threat Landscape Report 2026 found that finance and insurance already account for close to 69% of regional phishing activity. Barring a coordinated regional response, that share is likely to grow before it shrinks.