← All Posts Jamaica Cybersecurity · AI Fraud Detection

A WhatsApp Scam Spread Contact to Contact Across Jamaica. AI Detection Is the Circuit Breaker the Region Doesn't Have

Adrian Dunkley, the AI Boss July 23, 2026 13 min read

Two men in Kingston lost control of their WhatsApp accounts in June 2026. Neither found out from WhatsApp. Neither found out from a bank alert. One found out because friends and relatives started calling him, confused about messages he had never sent, according to reporting by the Jamaica Gleaner. By then the account had already spent hours pretending to be him, asking his own contacts for money in his own voice, or close enough to it in text that nobody paused to check.

That is the actual failure at the centre of this story. Not that a scam happened. Scams happen constantly. The failure is that a compromised account can operate inside someone's trusted network for hours, sending message after message to person after person, before a single system anywhere, not the platform, not the bank, not the telecom carrier, flags that something is wrong. AI-based anomaly detection, the kind that already reads login patterns, message phrasing, and device fingerprints for exactly this signature, could interrupt that spread in minutes. Jamaica does not yet run that detection at the messaging layer, and this scam is thriving in the gap that leaves behind.

I have spent close to two decades building AI capacity across this region, and one thing I have learned is that Caribbean institutions are usually quite good at responding to fraud after it is reported. What we are consistently bad at is catching it while it is still moving. This story is a clean example of why that distinction matters, and of exactly which tools would close it.

A Familiar Voice, a Stolen Account

The Jamaica Gleaner's account, published on 25 and 26 June 2026 under the headline "WhatsApp Web of Deception," follows two victims. Victim A, in his forties, and Victim B, in his sixties, both had their WhatsApp accounts taken over by criminals who then used them to solicit money from the victims' own contact lists. Victim B did not discover the breach through any warning from WhatsApp itself. He learned about it because people who knew him began calling to ask why he was sending them strange messages.

The mechanics were consistent across both cases. Whoever controlled the hijacked account opened with an ordinary, friendly greeting, the kind that would not raise suspicion from someone who trusted the sender. Only after that opening did the request for money follow, in one documented instance a request for US$820, transferred through Zelle, with a promise the money would be repaid the next day. The attacker avoided phone calls throughout, always claiming to be busy, always keeping the exchange in text, because a single voice call would have exposed the whole thing immediately.

One victim's case was reported at the Cross Roads police station in Kingston. Multiple divisional police commanders told the Gleaner they had heard of comparable incidents beyond the two cases documented in the article, which suggests this is not two isolated victims but a pattern that has not yet been formally counted anywhere.

What Jamaica's Cyber Incident Response Team Is Doing About It

Godphrey Sterling, director of the Jamaica Cyber Incident Response Team, responded to the Gleaner's questions by saying the agency would "do a deeper dive" into the pattern. He also noted that JaCIRT had not seen a recent uptick in formal reports, even as divisional police commanders were describing the opposite on the ground.

That gap between what police are hearing informally and what a national cyber agency is tracking formally is itself a data problem, and it is one AI can help close directly. JaCIRT's existing advice to the public remains sound: enable two-step verification, never share a verification code, check the linked devices list in WhatsApp settings, and independently verify any money request before sending funds. But that advice asks every individual Jamaican to personally recognise a fraud pattern in the middle of a friendly conversation with someone they trust. It is guidance aimed at victims, not detection aimed at the fraud itself, and it arrives after the fact rather than during the attack.

This Is Not One Scam. It's a Regional Pattern

Zoom out from these two Kingston cases and the numbers get considerably harder to look past. The Bank of Jamaica reports an 890 percent rise in Internet banking fraud since 2020, with losses exceeding J$800 million, roughly US$5 million, by the end of 2023. Card theft alone now accounts for 69 percent of total fraud losses tracked by the central bank. Jamaica had approximately 3.06 million active mobile connections at the start of 2025, a market split almost entirely between Digicel and Flow, which means a fraud pattern that exploits mobile messaging has a nearly nationwide surface to move across.

The region's other territories are seeing their own variants of the same underlying problem, which is that trust in a familiar name, a familiar app, or a familiar-looking website is being weaponised faster than institutions are adapting to it. In Trinidad and Tobago, one of the fastest-growing scams uses fake news articles built on cloned newspaper layouts, complete with real reporters' names and photographs, to promote bogus investment platforms that harvest money and personal data from anyone who clicks through. In Barbados, police issued a public alert in May 2026 over SMS messages impersonating a government traffic penalty notice. Business email compromise scams, where criminals pose as a supplier or executive to redirect a payment, average more than US$39,000 per successful attempt worldwide, and Caribbean small and medium enterprises, which make up an estimated 99.5 percent of businesses in the region, are especially exposed because most cannot afford a dedicated cybersecurity function.

Why This Isn't Just a Jamaica Story

Every one of these scams, the WhatsApp hijack, the cloned news article, the fake traffic fine, the fraudulent wire request, relies on the same mechanic: a familiar channel used to bypass the scrutiny that channel is supposed to earn through trust. That mechanic does not respect borders. A detection system built to catch it in Kingston would catch the same pattern in Port of Spain or Bridgetown with only minor adjustment, which is exactly why this is a regional opportunity and not a single-country fix.

Why the Scam Works So Well

Social engineering succeeds by exploiting exactly the instincts that make a contact list valuable in the first place. A message from a known number, in a familiar tone, asking for something reasonable rather than alarming, does not trip the same alertness as a message from a stranger. The avoidance of phone calls is the tell that a trained eye would catch immediately, since a real emergency involving money rarely survives a thirty-second conversation, but the person receiving the message is not looking for a tell. They are responding to someone they believe they already know.

Institutions, meanwhile, are still built around single-channel fraud review. A bank watches transactions. A telecom watches network activity. A messaging platform watches for spam at scale, not for one compromised account quietly targeting a hundred people who already trust it. None of those three institutions currently shares what it sees with the others in a way that would let a Zelle transfer request, a SIM-level anomaly, and an unusual pattern of outgoing WhatsApp messages get connected into a single, obvious signal before the money moves.

What AI Detection Actually Looks Like

This is not a hypothetical capability waiting on future research. It already runs, at scale, outside the Caribbean. Commonwealth Bank of Australia operates an AI system that issues more than 40,000 proactive fraud warnings to customers every single day, alongside a Live Threat Detection layer that scans specifically for SMS forwarding, hidden background app launches, and accessibility overlay misuse, the technical signature of an account takeover in progress rather than the money request that follows it. Mastercard has reported that AI-driven payment fraud prevention is saving issuing banks millions of dollars annually, and industry survey data puts the figure concretely: 42 percent of card issuers and 26 percent of acquirers have saved more than US$5 million each in fraud losses over the past two years using AI-based detection.

Three layers, applied together, would have caught the Kingston case while it was still happening rather than after friends started calling to check. Behavioural biometrics flag the moment a login pattern, device, or typing rhythm on an account changes abruptly, the first sign of a takeover. Language models trained on known fraud scripts can scan message content in real time for the specific markers this scam relied on: urgency without emergency, insistence on text over calls, and phrasing patterns that recur across thousands of prior scam messages. Bank-side transaction risk scoring can then combine those signals with the destination account and requested amount to hold or challenge a transfer automatically, rather than approving it and only investigating once a victim files a report weeks later.

None of that infrastructure currently runs at the messaging layer for Jamaican consumers, and none of Jamaica's commercial banks apply transaction risk scoring calibrated to this specific social engineering pattern. The tools exist. They are proven. They are simply not deployed where this scam is operating.

The Opportunity Caribbean Fintechs and Telecoms Are Leaving on the Table

Digicel and Flow together carry nearly all of Jamaica's 3.06 million active mobile connections, which puts both companies in the best possible position to detect a SIM swap or an unusual account access pattern before a hijacked WhatsApp account ever sends a single message. Neither currently offers that detection as a consumer-facing service. Commercial banks are similarly placed to add transaction risk scoring tuned to exactly the pattern documented in this scam: a request that arrives through a personal channel, carries urgency without a stated emergency, and specifies a transfer method like Zelle that is difficult to reverse once sent.

The bigger prize sits at the regional level. A CARICOM-wide shared scam-signature database, pooling flagged phrases, known fraudulent payment destinations, and confirmed account-takeover patterns across member states, would let a scam identified in Kingston get blocked in Bridgetown or Port of Spain within hours instead of surfacing there independently months later as its own unconnected news story. Building that database, and the AI models that would query it in real time, is squarely the kind of infrastructure the Caribbean's own growing AI and fintech sector should be building, not importing. The region has spent nearly two decades training the AI talent this exact problem calls for. This is the moment to point that talent at it.

What to Do Before the Next Message Arrives

Until that infrastructure exists, the defence is manual, and it is not complicated. If a contact asks for money over WhatsApp, call them, using a number saved from before the message arrived rather than any number supplied in the conversation itself. If they will not take the call or keep finding reasons to avoid it, treat that refusal as the clearest signal available that the account has been compromised. Enable two-step verification on WhatsApp. Never share a six-digit verification code with anyone under any circumstance, no matter how the request is framed. Check the linked devices list in WhatsApp settings periodically for anything unfamiliar. If money has already gone out through a service like Zelle, contact the bank immediately, since these transfers are built to be difficult to reverse once they clear.

None of that replaces the detection layer this article describes. It is what protects a household while the region builds it.

Frequently Asked Questions

What is the WhatsApp hijacking scam spreading in Jamaica?

Criminals are taking over people's WhatsApp accounts, most likely through phishing or social engineering, and then messaging the victim's own contacts in a friendly, familiar tone. They ask for money, often through services like Zelle, promise to repay quickly, and deliberately avoid phone calls to prevent voice verification. The Jamaica Gleaner documented two Kingston-area cases in June 2026, one involving a request for US$820, and divisional police commanders reported hearing of similar incidents beyond those two.

How does the scam actually work step by step?

The attacker first compromises a victim's WhatsApp account, typically through a phishing link or a social engineering trick that captures a verification code. Once inside, they message the victim's contacts with an ordinary greeting to establish familiarity, then introduce a request for money, often framed as urgent but not dramatic enough to invite scrutiny. They insist on text over calls, claiming to be busy or somewhere with bad signal, because a voice call would immediately reveal that the person speaking is not who the contact expects.

What has Jamaica's Cyber Incident Response Team said about the scam?

Godphrey Sterling, director of the Jamaica Cyber Incident Response Team, told the Jamaica Gleaner in June 2026 that the agency would do a deeper dive into the pattern, while noting it had not seen a recent uptick in formal reports even as police commanders described hearing about similar incidents. JaCIRT's standing guidance includes enabling two-step verification, protecting verification codes, monitoring linked devices, and independently verifying any money request before sending funds.

How big is the online scam problem across the Caribbean beyond this one case?

The Bank of Jamaica has reported an 890 percent rise in Internet banking fraud since 2020, with losses exceeding J$800 million, roughly US$5 million, by the end of 2023, and 69 percent of total fraud losses now coming from card theft alone. In Trinidad and Tobago, one of the fastest-growing scams uses fake news articles built on cloned newspaper layouts to promote bogus investment platforms. In Barbados, police issued a public alert in May 2026 over fraudulent SMS messages posing as a traffic penalty notice. Business email compromise scams average more than US$39,000 per attempt globally and hit Caribbean small businesses hard, since small and medium enterprises make up an estimated 99.5 percent of the region's companies and rarely employ dedicated cybersecurity staff.

Can AI actually detect an account hijacking scam like this in real time?

Yes, through several layers that already operate elsewhere. Behavioural biometrics flag a sudden change in typing rhythm, device, or login location the moment an account is accessed. Large language models trained on fraud patterns can scan message content for urgency markers, call avoidance, and phrasing that resembles known scam scripts, then flag the conversation before money changes hands. Bank-side transaction risk scoring can combine those signals with the destination account and amount to hold or challenge a transfer that fits the pattern, rather than approving it and investigating afterward.

Are any banks or telecoms already running this kind of AI fraud detection?

Commonwealth Bank of Australia runs an AI system that sends more than 40,000 proactive fraud warnings to customers every day and a Live Threat Detection layer that scans for SMS forwarding, hidden background app launches, and accessibility overlay misuse, the technical fingerprints of an account takeover in progress. Mastercard has reported that AI-based payment fraud prevention is saving banks millions of dollars a year, and industry data shows 42 percent of card issuers and 26 percent of acquirers saved more than US$5 million in fraud losses over the past two years using AI. None of this infrastructure is deployed at the messaging layer by Jamaica's telecom providers or by Caribbean commercial banks today.

What should Digicel, Flow, and Caribbean banks build to close this gap?

Telecom providers such as Digicel and Flow, which together dominate Jamaica's roughly 3.06 million active mobile connections, are positioned to detect SIM swaps and unusual account access at the network layer before a hijacked WhatsApp account ever sends a message. Commercial banks can add AI transaction risk scoring that flags a transfer request matching known social engineering patterns, the way behavioural analytics already do overseas. A CARICOM-wide shared scam-signature database, pooling flagged phrases, account patterns, and known fraudulent payment destinations across member states, would let a scam identified in Kingston get blocked in Bridgetown or Port of Spain within hours instead of months.

What should someone do right now if a contact asks them for money over WhatsApp?

Call the person, using a number saved before the message arrived, not one supplied in the conversation. If they refuse or cannot take a call, treat that as the clearest signal available that the account is compromised. Enable two-step verification on WhatsApp, never share a six-digit verification code with anyone, and check the linked devices list in WhatsApp settings for anything unfamiliar. If money has already been sent through a service like Zelle, contact the bank immediately, since these transfers are typically designed to be difficult to reverse.

Could a Caribbean-built AI scam detection platform actually work, and who should build it?

Yes, and the region has the AI talent to build it rather than wait for an imported solution. A regional platform combining telecom-side SIM anomaly detection, bank-side transaction risk scoring, and a shared scam-signature database would need coordination between JaCIRT, the Bank of Jamaica, Digicel, Flow, and their counterparts in other CARICOM states, alongside Caribbean AI companies and researchers with the capacity to build and operate it. That is a live market opportunity for the Caribbean's growing fintech and AI sector, not a hypothetical one, given the scale of losses the Bank of Jamaica has already documented.

Get the Weekly Post

New thinking on Caribbean AI, governance, and technology, delivered every week.