The Central Bank of Barbados is warning the public never to share their BiMPay verification codes, tokens, passwords or other security credentials with anyone, following a reported social engineering fraud involving an online loan offer.
There is no indication that the BiMPay platform itself was compromised. The fraud occurred after the customer provided a third party with a mobile verification code, an email verification code, and a BiMPay token in connection with a purported loan application. A transaction was subsequently made without the customer’s authorisation.
BiMPay verification codes and tokens are security information. They should only be used by the customer for their own BiMPay registration and access and should never be given to another person.
The Bank particularly cautions customers against requests received through social media, messaging platforms or other online channels. A legitimate lender or financial institution does not need a customer’s BiMPay verification codes, BiMPay token, or password in order to provide a loan or make a payment to the customer.
Customers should independently verify the identity and legitimacy of any person or organisation requesting financial or personal information, particularly where the approach originates through social media.
Anyone who has disclosed a BiMPay verification code, token, password or other security information to another person should contact their financial institution immediately and take steps to secure or disable their BiMPay access. Anyone who believes they have been the victim of fraud should also report the matter to the Barbados Police Service.
The Central Bank continues to work with participating financial institutions to protect users and strengthen awareness of social engineering and other forms of payment fraud.