Asking to "Read Back the Number" Made the Scam Sound Normal.

Asking to "Read Back the Number" Made the Scam Sound Normal.

A first-person account of a WhatsApp verification-code scam targeting a Barbados community group: what the caller actually asked for, why the pretext worked, what a stolen WhatsApp account is really used for, and how to lock yours down.

The call

The call came in from a United Kingdom number. That part alone was not strange. Some members of the WhatsApp group I belong to live abroad and call in on foreign numbers, so an overseas number ringing in is normal, not a tell on its own. What did not line up was the accent, which did not sound like it matched the number it was calling from, a softer thing to notice than any of what came next but a real one. The person opened by naming a member of that group, the one whose word would carry weight, then asked whether I had received the link for a meeting that evening at 8:30, the way someone follows up on something they had arranged rather than someone fishing for information. I had no way to check any of that in the moment. But the group's name was right, and that, on top of the number not being odd to begin with, was enough to make me think "that's plausible" and keep listening. I put two things back to them. Meetings for that group run at 7, not 8:30, so were they sure of the time. And a Zoom link for that group always arrives with advance notice in the group chat itself, not from someone calling around asking whether people had received it. They did not answer either point. They stayed on script: they would send me a link, and I should read back the number I received. I told them to go ahead and send it, I would read it later. That was not acceptable to them. They wanted me to stay on the call, on speaker, so I could read the number back the moment it arrived.

That last sentence is the entire scam. Everything before it, including talking past two direct questions and refusing to let me hang up and check in my own time, was them working to keep control of the call long enough to reach it.

While they were still talking I checked my own phone. There was no link waiting anywhere. Instead there was a WhatsApp system alert on screen, and I know what a Zoom link looks like well enough to know that alert was not one. I did not read it closely enough in the moment to know it was a verification code. I only needed to know it was not what they had told me to expect. I laughed and hung up. Then I blocked the number and reported it.

Within fifteen minutes at least seven other people in the same group had received the same call from the same number, and two more numbers turned up before lunchtime. All three were United Kingdom numbers.

What they were actually asking for

The alert I was looking at was a WhatsApp registration code, six digits long. One of those arrives when somebody has entered your phone number on a device and is trying to put your account on it. The code is how WhatsApp checks that the person holding that device is the person who holds the number.

So when a stranger asks you to read that code back, they are not verifying anything. They are already standing at the door with your number typed in, waiting for you to hand them the key. Read it out and the account moves to their phone, group memberships and all. You get signed out.

The actual WhatsApp call screen from the incident, showing the attacker's contact card and the "Enter this verification code on your new phone" prompt. The attacker's number and display name have been redacted.

A different member of the group watched a second code arrive after the attacker's first attempt on their account failed. Worth knowing, since the code regenerates every time an attacker tries again, so a code arriving twice means a second attempt is underway.

The part that made this one different

Most scam calls are a wide net. This one was not.

They knew which group to name. They knew the name of a person whose word would carry weight inside it. And they rang about a meeting on an evening when something was in fact happening, before the group had been told about it. Whether that last part was research or coincidence, I cannot say. What is not in doubt is that somebody had access to multiple phone numbers belonging to the group, and one name from inside it worth dropping into every call. I cannot say whether they knew who they were calling each time, or just that the number was one of the ones they had.

The usual advice assumes you can spot a scam by its sloppiness: bad grammar, a strange greeting, a story that does not fit. There was a story that did not fit here too, but not in a way any checklist could catch. The meeting time was an hour and a half off from when that group actually meets, and the caller had no answer for it beyond repeating themselves. Catching that took knowing how the group actually runs, day to day, closely enough to feel the gap. I know the real time because I was once heavily involved in that group. Somebody who checks in only occasionally, or who joined more recently, would have had nothing to measure the caller's story against, and no reason to doubt it. The accent was there to notice as well, and it is on no generic checklist either, but on its own it stayed a gut read that never hardened into anything.

A different scam, the same morning

Separately, and on the same morning, two people in that group reported seeing something else: Google Meet invitations carrying CIBC branding. I did not see one myself, so the specific invitation is a sighting, not something I can describe first-hand. But that lure is not speculative, and it is the one Barbadian financial institutions have actually been warning about.

CIBC Caribbean named it in a public statement on the 4th of May: calls displaying the bank's logo over Google Meet and other social media apps, paired with a lookalike Gmail address, seeking to have people confirm personal banking details. It repeated the warning directly to customers by email on the 8th of July. The day before that, on the 7th of July, the Central Bank of Barbados published its own fraud alert about WhatsApp calls carrying the Bank's logo and claiming to be associated with BiMPay. Its language was direct:

We strongly encourage persons not to share sensitive information such as passwords, PINs, or security codes with anyone who contacts you.

And:

The Bank will not make unsolicited calls to anyone about BiMPay.

One of the two people who mentioned the CIBC invitation does not bank with CIBC at all, which suggests that arm of it is being sprayed at whoever answers rather than aimed at customers.

If you get a meeting invitation that appears to come from your bank, treat the invitation itself as the suspicious object. Barbadian banks do not open relationships with you over a video call you did not arrange.

Update, 16 September 2026: the Central Bank of Barbados has since warned about a similar trick on BiMPay. A fake loan offer got someone to hand over two verification codes and their BiMPay token, and an unauthorised transaction followed. I explain how that works here.

What a stolen account is actually for

Worth being precise about what my own call was. Those bank warnings all describe someone posing as a financial institution to get financial credentials: a PIN, a card number, a login. The person who rang me never mentioned a bank, never asked about an account, and never claimed to be from one. They wanted six digits that unlock a messaging app. That is a different scam with a different target, and it deserves saying plainly rather than filing both under "phone fraud" and moving on.

It is still about money, though, and the reason is worth understanding. Whoever takes your WhatsApp account cannot read your old conversations. WhatsApp is end-to-end encrypted and those messages sit on your phone rather than on the account, which the company states plainly in its own recovery guidance. What the attacker gets instead is you. Your name, your photo, your place in every group you belong to, and whatever credit you have built up with the people in them.

The money part arrives later, and it does not arrive from a stranger. WhatsApp's advice on that same page is to notify family and friends if your account is taken, because whoever holds it can impersonate you in chats and groups. In practice that means a message to your sister, your business partner, the people in your church group, asking for something urgent and small, from an account they have every reason to trust. The account is the instrument. That is the connection worth claiming, and it is the only one I would.

What to actually do

Turn on two-step verification, and put an email address on it. In WhatsApp: Settings, then Account, then Two-step verification, then Enable. Choose a six-digit PIN that is not your birthday and not your bank PIN. Then add an email address. WhatsApp treats that step as optional and it is easy to skip past, but it is the part that saves you later: forget the PIN with no email on the account and WhatsApp makes you wait seven days to reset it, while an email on file lets you reset the PIN yourself. WhatsApp's own instructions are here, if the menu has moved by the time you read this.

Two-step verification does not stop the call. What it does is make the stolen code useless on its own, because the attacker would then also need your PIN, which never gets sent to your phone and never arrives in a message anyone can talk you into reading out.

If a caller refuses to let you hang up and get back to them, that refusal is the tell. A legitimate sender does not care whether you read a message now or in ten minutes. Someone who insists you stay on the line, on speaker, ready to read something back the second it arrives, is working to stop you checking it on your own terms. Hang up. You can always call back on a number you looked up yourself.

Never read a code to anyone, for any reason. Not to your bank, not to a courier, not to someone calling from a group you belong to. There is no legitimate situation in which a person on a phone call needs a code that was sent to you.

If a code arrives that you did not ask for, somebody is trying to take your account right now. Do not enter it anywhere. Do not forward it. Turn on two-step verification immediately if it is not already on.

If you have already read a code out, re-register your number on your own phone straight away, following WhatsApp's own recovery steps. Entering a fresh six-digit code on your own device logs out every other device on the account, which is how you put the attacker off it. One catch: if they have already set a two-step verification PIN on your account, re-registering will ask you for it, and without it WhatsApp makes you wait seven days before you can reset it and get back in. Once you're back in, turn on two-step verification yourself, then tell the groups you belong to, because your account is the tool that will be used on them next.

Report it. These go to the Barbados Police Service, which is where the Central Bank sent people over the impersonation calls it warned about in July. Blocking the number protects you. Warning the people around you and reporting the call are the parts that protect everyone else.

The uncomfortable part

Most scams I come across are easy to laugh at. This one was not, and I want to be honest about why it nearly worked on people who are not gullible.

It arrived with a name attached. Somebody had done the work of finding out which group I am in and who in it has standing. In a country this size that work is not hard, and it is a reasonable assumption that it is being done to other groups right now. Church groups, school parent groups, sports clubs, staff chats. Any group with a list and a leader, a recurring meeting people expect a link for, and members who trust each other more than they distrust a stranger on the phone.

Set the PIN and the recovery email up now, while the phone is quiet.

Questions about this topic?

Financial terms can be confusing. If you have questions about the article or ideas for what I should cover next, send me a DM.

Chat on Instagram

Share this article