A Loan Offer Asked for Two Codes and a Token. Then Came an Unauthorised Transaction.

What the Central Bank of Barbados' 15 September 2026 BiMPay fraud warning describes, what a BiMPay token actually does, how a loan offer could give a scammer a pretext for asking for one, and what to do if you have already handed one over.
What the Central Bank said
On the 15th of September 2026 the Central Bank of Barbados warned the public never to share BiMPay verification codes, tokens, passwords or other security credentials, after a reported fraud that started with an online loan offer. The customer gave a third party three things: a verification code sent to their phone, a verification code sent to their email, and a BiMPay token. A transaction was then made without their authorisation.
The Bank made two points. It said there was no indication BiMPay itself had been compromised:
There is no indication that the BiMPay platform itself was compromised.
And no real lender needs what the customer handed over:
A legitimate lender or financial institution does not need a customer's BiMPay verification codes, BiMPay token, or password in order to provide a loan or make a payment to the customer.
How those three things fit the setup steps
The Central Bank did not say how the transaction was made. But the three items in its warning line up exactly with the steps for setting up the BiMPay app and connecting it to a bank account, which the Bank and the banks have published.
The Central Bank's guide to the BiMPay e-wallet sets it out. You download the app, enter your phone number and email address, and confirm both with a one-time password sent by SMS and another sent by email. Then you say which bank or credit union you want to link, and you enter a token from that institution. The token is what connects your account to the app. The Bank describes that link as token-based consent, and for someone who already banks somewhere, it says the link is instant.
How the token reaches you depends on where you bank. RBC's own instructions have you generate it in digital banking, where it stays valid for 15 minutes while you paste it into the app. First Citizens' BiMPay page has you generate it in online banking and sends it to your email, and its app setup also asks for your Barbados National Identification Number. Republic Bank sends the token by email, according to the Central Bank's list.
Put that next to the warning. A phone code, an email code and a token are the set of things the app asks for to register a wallet and link a bank account to it. If someone else is holding the phone where that app is being set up, reading those three things to them is the step that joins your bank account to their wallet. From there, money can be sent out of it. That is my reading of how this kind of fraud works, based on the published setup steps. The Central Bank has not confirmed it was the method in this case.
Why a loan offer
A loan application could give a scammer a cover story for each of these requests. A "lender" could ask for your national ID number as part of the application. It could say it needs to verify your phone and email, and ask you to read back the codes that arrive. It could describe a token as the way the loan gets paid into your account. Each request can come with a reason that sounds plausible, and none of those reasons is true.
The Central Bank particularly warned about approaches that arrive through social media, messaging apps and other online channels, and said to check the identity of anyone asking for financial or personal information on your own terms.
A similar trick to the WhatsApp code scam
I wrote in August about a caller who tried to get a WhatsApp verification code read back to them. The shape here is similar. Something is sent to you, and a stranger has a reason why you should read it to them. With WhatsApp, the prize was the account. With BiMPay, it is a link to your money.
The rule carries over. The Central Bank puts it this way:
BiMPay verification codes and tokens are security information. They should only be used by the customer for their own BiMPay registration and access and should never be given to another person.
What to do
If a verification code arrives that you did not ask for, do not read it to anyone or type it anywhere. Someone may be trying to register your phone number or email on a device you do not control.
If you have already given a code, token, password or other security information to someone, the Central Bank's advice is to contact your bank or credit union immediately and take steps to secure or disable your BiMPay access. Use a number you look up yourself, never one the other person gives you.
If you think you have been the victim of fraud, report it to the Barbados Police Service as well as your bank, as the Central Bank advises.
Questions about this topic?
Financial terms can be confusing. If you have questions about the article or ideas for what I should cover next, send me a DM.
Chat on Instagram