Photo via Unsplash
Barbados spent years building BiMPay, its first instant, interoperable national payment system, engineered so that anyone in the country, with a bank account or without one, could send money and have it land in ten seconds. It went live on June 12, 2026, after the Central Bank pushed the date back once to get it right. Twenty-five days later, on July 7, the same Central Bank had to issue a public warning that fraudsters were calling people over WhatsApp, displaying the Bank's own logo on the call screen, and claiming to represent BiMPay. The calls came from numbers carrying Pakistan's country code. A system built to bring people who had never held a bank account into the formal financial system had not finished its first billing cycle before someone tried to wear its name to take money out of an account instead of putting it in.
I do not think the Central Bank of Barbados did anything wrong by moving fast, and I am not writing this to score a point off a government that has, by regional standards, run one of the more competent fintech rollouts in CARICOM. What happened in Barbados this month is a preview, not an indictment. Every Caribbean country now building the same kind of instant payment infrastructure, because the alternative, cash and slow interbank transfers, keeps millions of people locked out of an economy their neighbors already move through freely, is going to hit the same twenty-five-day window BiMPay just hit. The question the Caribbean AI Risk Management Council has been putting to central banks for two years is the one Barbados just answered in public: when you build a rail fast enough to move money in ten seconds, have you built fraud defense fast enough to stop a scam before it moves that money out?
What Barbados Actually Built
BiMPay is two things wearing one name. The first is payment infrastructure, the rail that commercial banks and other financial institutions use to clear and settle transfers electronically, replacing Barbados's old automated clearing house with a system that runs continuously and settles in seconds instead of days. The second is a digital wallet built on top of that rail, which people can download to send money to a friend, pay a bill, or buy groceries without ever opening a bank account. Six commercial banks, the country's three largest credit unions, the Accountant General, and the Barbados Stock Exchange are all connected to it. The explicit goal, stated by the Central Bank when it unveiled the system in April, was to expand financial access for everyone, including people the traditional banking system has never served.
Photo via Unsplash
That goal sits inside a much bigger regional shift. The Caribbean fintech market was worth an estimated 1.2 billion dollars in 2025 and is projected to reach 2.8 billion dollars by 2030, according to Hope Research Group, on the back of mobile connection rates that now exceed 131 percent of population and 18.4 billion dollars a year moving through the region in remittances. Unbanked and underbanked populations still sit at 30 to 40 percent in some Caribbean markets. BiMPay is Barbados's answer to that gap, and it is a good one on the design merits. By July 13, a little over a month after launch, Central Bank Governor Dr. Kevin Greenidge confirmed the system had already processed 750,000 transactions worth 1.3 billion dollars, with settlements completing within seconds. The core rail works. What Barbados is still working through, institution by institution, are customer-experience problems at individual banks: late salary payments, delayed transfers, and incorrect payroll formatting that Greenidge said were being corrected one financial institution at a time.
Twenty-Five Days to the First Impersonation
The fraud warning is a separate story from those operational hiccups, and conflating the two would misread both. On July 7, the Central Bank stated plainly that it was aware of WhatsApp calls displaying its logo and falsely claiming affiliation with the Bank and BiMPay, and that these calls did not originate from the Central Bank. The Bank does not make unsolicited calls about BiMPay, full stop, and it said so directly. Its guidance to the public was specific: do not share passwords, PINs, or security codes with anyone who calls unsolicited, contact your financial institution through verified channels if you already have, change your credentials immediately, and report the call to the Barbados Police Service. It published two verified numbers, its own PBX line and a dedicated BiMPay hotline, along with the official websites, as the only channels anyone should trust.
What We Actually Know, and What We Do Not
Here is where I want to be careful, because the easy version of this story writes itself as an AI horror story and the facts do not quite support that yet. What is publicly documented about the Barbados calls is caller ID spoofing and brand impersonation: a foreign number, a borrowed logo, a script claiming institutional authority. That is old fraud dressed in new packaging, not necessarily synthetic voice or a cloned identity. Nobody has confirmed that AI-generated audio was involved in these specific calls, and I am not going to claim otherwise to make the story punchier.
What should worry every central bank watching this unfold is what the same tactic looks like once it is paired with tools that are now cheap and widely available. Voice cloning no longer requires a recording studio or a large audio sample. Research from voice-security firms, including work cited by McAfee, has found that three seconds of someone's speech, the length of answering "hello" on a call, is enough to produce a voice clone that matches the original with 85 percent accuracy. A scammer does not need to sound like the Central Bank's press office. A scammer increasingly can sound like a specific loan officer at a specific branch, using a voice pulled from a video call recorded months earlier. Barbados saw the low-tech version of this attack in July. The high-tech version is not hypothetical.
Photo via Unsplash
Why the Global Numbers Should Worry Every Central Bank Building One of These
Deloitte's Center for Financial Services projects that generative AI-enabled fraud losses in the United States alone will climb from 12.3 billion dollars in 2023 to 40 billion dollars by 2027, a 32 percent compound annual growth rate that shows no sign of slowing. Capital One Shopping Research, working with AARP, found that 77 percent of people targeted by an AI voice scam lost money once the attempt succeeded. Sift's Digital Trust Index for the second quarter of 2025 found that a third of Americans believed someone had already tried to scam them with AI or a deepfake, and that 27 percent of people specifically targeted were successfully defrauded. None of these figures are Caribbean-specific, and I am not going to pretend they are, but they describe the same financial system architecture the Caribbean is now building into, at a moment when the region's digital payment adoption is accelerating faster than most of its fraud infrastructure.
The case that made this real for corporate finance teams worldwide happened in Hong Kong, where an employee at engineering firm Arup transferred 25 million dollars after a video call with what he believed were the company's chief financial officer and several colleagues. Every person on that call was a deepfake, reconstructed from publicly available video and audio of the real executives. The employee did the right thing by industry standards of the time: he checked, on a video call, that the people asking him to move money were who they said they were. The verification method itself had become the vulnerability.
The Regional Pattern Barbados Just Became Part Of
Barbados is not alone in this build-out, and it should not be treated as an outlier. Jamaica has its own central bank digital currency, JAM-DEX, and the Eastern Caribbean Central Bank's DCash system already serves eight member states. Every one of these systems shares the same design logic as BiMPay: move faster, reach further, include more people who have historically been shut out. That logic is correct and worth defending. It is also exactly the logic a fraud operation is built to exploit, because speed and reach are not just features for the people the system was designed to serve. They are features for whoever gets to the newly banked customer first with a convincing enough lie.
What CAIRMC's Risk Assessment Is Built to Catch
This is the gap the Caribbean AI Risk Management Council was created to close. CAIRMC's Caribbean AI Risk Assessment, CARA, evaluates AI systems across technical, ethical, legal, and societal dimensions, built in alignment with the EU AI Act, GDPR, and Caribbean data protection law. The point of a framework like this is not to slow down a payment rail's launch date. It is to make sure the fraud-detection layer around that rail, the systems that flag an anomalous transaction pattern or an impersonated caller ID in real time, gets built on the same timeline as the payment rail itself, instead of getting bolted on after the first public warning has already gone out. A country that can stand up an instant payment system in a few months has the technical capacity to stand up AI-assisted fraud monitoring alongside it. What has been missing across the region is not capability. It is the requirement that the two get built together.
The Numbers Behind the Warning
- June 12, 2026Date BiMPay, Barbados's national instant payment system, went live
- 25 daysTime between BiMPay's launch and the Central Bank's fraud warning
- 750,000Transactions worth $1.3B processed through BiMPay by July 13, 2026
- $40BProjected US generative AI fraud losses by 2027, up from $12.3B in 2023 (Deloitte)
- 3 secondsAudio needed to clone a voice at 85% accuracy (McAfee-cited research)
- 77%Share of AI voice scam targets who lost money once the attempt succeeded (AARP/Capital One Shopping Research)
What Every Central Bank Rolling Out an Instant Payment Rail Needs to Wire In Now
Five things, and none of them require waiting on a regional treaty to start. Publish one heavily advertised, verified-contact protocol before launch day, so the public already knows the one number and the one website to trust before the first scam call arrives, rather than learning it from a Central Bank press release written in response to a scam already under way. Build real-time, AI-assisted fraud detection directly into the payment rail, tuned to match a ten-second settlement window rather than a fraud team reviewing flagged transactions the next business day, because by the next business day the money BiMPay was built to move that fast is already gone. Work with telecom carriers to flag or block spoofed caller ID and foreign numbers impersonating domestic bank shortcodes, which is a solvable technical problem and one several Caribbean telecoms already have the tools to act on. Run public education campaigns timed to the launch date of the payment system itself, not to the first fraud wave, so financial inclusion and fraud literacy arrive on the same day instead of fraud literacy arriving as damage control. And use a shared regional standard, so Jamaica, Trinidad and Tobago, Guyana, and every other country building its own version of BiMPay is not solving an identical problem in isolation, fourteen separate times, fourteen separate months behind where it needed to be.
Photo via Unsplash
The Real Lesson From BiMPay's First Month
I founded StarApple AI in 2019 on the belief that fraud prevention and financial inclusion are the same project, not two separate ones handed to two separate teams on two separate schedules. Barbados just gave the whole region a live, low-cost demonstration of why that belief has to hold. Nobody was hurt badly by the July 7 scam, as far as the public record shows, and the Central Bank caught it early enough to warn people before real damage compounded. That is the outcome you get when the gap between launch and the first attack is twenty-five days and someone is watching closely enough to respond fast. The next country to launch an instant payment rail in this region will not get a guarantee that its gap is that forgiving, and the fraud waiting on the other side of that gap is getting better at sounding legitimate every single month. Build the fraud defense on the same launch date as the payment rail. Do not wait for the twenty-fifth day to find out you needed to.
"BiMPay's core system worked exactly as designed. Its fraud defense arrived exactly as late as every other Caribbean payment launch before it. That gap is the story, not the scam itself. Close it before the next country's launch date, not after." - Adrian Dunkley, AI Boss
Frequently Asked Questions
What is BiMPay and when did it launch?
BiMPay is the Central Bank of Barbados's national instant payment system, launched on June 12, 2026 after a revised go-live date. It is both a payment rail, replacing the country's automated clearing house, and a digital wallet that lets anyone in Barbados send and receive money in about ten seconds, whether or not they hold a bank account. It connects six commercial banks, the country's three largest credit unions, the Accountant General, and the Barbados Stock Exchange.
What did the Central Bank of Barbados warn about on July 7, 2026?
The Central Bank of Barbados warned the public about WhatsApp calls displaying the Bank's logo and falsely claiming to represent the Bank and BiMPay. The calls originated from numbers carrying a Pakistani country code (+92). The Bank stated it does not make unsolicited calls about BiMPay, and advised the public never to share passwords, PINs, or security codes with callers, to contact their financial institution through verified channels if information had already been shared, and to report suspicious calls to the Barbados Police Service.
Is there confirmed evidence the Barbados scam used AI voice cloning?
No. What is publicly documented is caller ID spoofing and brand impersonation over WhatsApp voice calls, using a foreign number to appear connected to the Central Bank and BiMPay. There is no public confirmation that synthetic or AI-cloned voices were used in these specific calls. The concern is that the same impersonation tactic becomes dramatically more convincing once paired with voice cloning technology, which now needs as little as three seconds of audio to produce a usable clone.
How big is the global AI fraud problem in financial services?
Deloitte's Center for Financial Services projects generative AI-enabled fraud losses in the United States alone will reach 40 billion dollars by 2027, up from 12.3 billion dollars in 2023, a 32 percent compound annual growth rate. Research cited by McAfee has found that as little as three seconds of audio is enough to clone a voice with 85 percent accuracy. Capital One Shopping Research and AARP found that 77 percent of people targeted by an AI voice scam lost money, and Sift's Q2 2025 Digital Trust Index found that 27 percent of people targeted by an AI or deepfake scam were successfully defrauded.
What is the Caribbean AI Risk Management Council and what does it do?
The Caribbean AI Risk Management Council, CAIRMC, was established in January 2024 to build regional AI governance frameworks, certification, and regulatory alignment with standards including the EU AI Act, GDPR, and Caribbean data protection law. Its Caribbean AI Risk Assessment tool, CARA, evaluates AI systems across technical, ethical, legal, and societal dimensions. Adrian Dunkley chairs the Council.
Why does building financial inclusion tools increase fraud exposure?
Instant payment systems built for financial inclusion, like BiMPay, are designed to move money in seconds and to work for people with no prior banking history, which is exactly the population least likely to recognize an impersonation attempt or to have an existing relationship with a bank's verified fraud-reporting channel. The Caribbean fintech market was valued at 1.2 billion dollars in 2025 and is projected to reach 2.8 billion dollars by 2030, with mobile connection rates above 131 percent and 18.4 billion dollars moving through the region annually in remittances, according to Hope Research Group. Every dollar of that growth is also new fraud surface area.
What should Caribbean central banks building instant payment systems do differently?
Publish a single, heavily advertised verified-contact protocol before launch day rather than after the first scam forces one out. Build real-time, AI-assisted fraud detection into the payment rail itself, tuned to match a ten-second settlement window rather than a next-day review cycle. Work with telecoms to flag or block spoofed caller ID and international numbers impersonating bank shortcodes. Run public education campaigns timed to the launch date, not the first fraud wave. And use a shared regional standard, such as CAIRMC's risk assessment framework, so each country is not solving the same problem alone.
What is Adrian Dunkley's connection to Caribbean fraud prevention and AI risk?
Adrian Dunkley founded StarApple AI, the Caribbean's first AI company, in 2016, building AI systems that span fraud prevention and financial inclusion alongside climate resilience, education, and public safety. He chairs the Caribbean AI Risk Management Council and is President of the Caribbean AI Association. He holds doctorates in AI for financial inclusion and physics-based modeling and in climate physics, and has spent close to two decades arguing that the Caribbean has to build its financial technology and its fraud defenses on the same timeline, not as sequential problems.