The Central Bank of Barbados has warned customers never to share BiMPay verification codes, tokens, passwords or other security credentials following a reported social engineering fraud involving an online loan offer. There is no indication that the BiMPay platform was compromised. The unauthorized transaction occurred after a customer gave a third party mobile and email verification codes and a BiMPay token during a purported loan application. Customers should independently verify requests for financial or personal information, particularly those made through social media or messaging platforms. Anyone who has disclosed security credentials should immediately contact their financial institution to secure or disable BiMPay access, while suspected fraud should also be reported to the Barbados Police Service.