Downtown Kingston, home to the banks, insurers and importers whose finance teams approve the wire transfers this kind of fraud is built to intercept.
- Security firm Barracuda published a red-team demonstration on August 4, 2026, showing an AI assistant redirect a simulated US$247,500 wire transfer from a single compromised email inbox.
- Fortinet's FortiGuard Labs recorded 46.7 million attempted cyberattacks against Jamaica in 2025, plus 5.4 million more in the first quarter of 2026 alone.
- The FBI attributes US$3.05 billion of 2025's US$20.9 billion in reported cybercrime losses to business email compromise, with 86% of those transactions moving by wire or ACH.
- The core defence costs nothing to implement: never confirm a payment instruction on the same channel it arrived on, and call back using a number already on file.
- The Bank of Jamaica regulates the national payment system but has not issued AI-specific fraud-verification guidance, leaving individual businesses to set their own protocols today.
A security firm's red team turned one compromised email account into a redirected US$247,500 wire transfer, and did it with an AI assistant instead of the weeks of manual snooping business email compromise used to require. Jamaica logged 46.7 million attempted cyberattacks in 2025 alone. The finance teams approving payments at Jamaican companies this month are the audience that demonstration was built for.
Barracuda's red team published the exercise during Black Hat week in Las Vegas on August 4, 2026. It was not a warning about some future threat. It was a working demonstration of a fraud technique available to anyone with access to Microsoft Copilot or a comparable AI assistant, run against a simulated target that looked exactly like a mid-sized Jamaican business: a managing director whose approval carries weight, a finance team, and an accounts payable clerk who releases the funds.
What Barracuda's Demonstration Actually Showed
The attack chain ran in seven steps, starting from a single compromised email account and ending with a wire transfer redirected to an account the attacker controlled. What made it notable was not the outcome, business email compromise has cost companies money for over a decade, but the mechanism. Barracuda's red team used Microsoft Copilot, working inside the compromised inbox, to read the account's message history, learn the tone and habits of the person it belonged to, and draft replies convincing enough to pass as genuine. Work that used to take a human attacker roughly eleven weeks of patient, manual email monitoring to pull off was compressed into an automated sequence a single operator could run in far less time.
Barracuda's own assessment did not frame this as a Copilot-specific flaw. The technique, the red team noted, "applies equally to other widely available AI assistants." That distinction matters for any Jamaican business deciding this is a Microsoft problem rather than theirs. It is not. Any organisation whose staff use an AI assistant with access to email, calendars, or documents carries some version of this exposure, regardless of vendor.
The Numbers Say Jamaica Isn't a Bystander
Writing in the Jamaica Observer on August 21, Peta-Gaye Hardy, founder of PGH Consulting LLC, connected Barracuda's demonstration directly to Jamaica's own exposure. Fortinet's FortiGuard Labs recorded 46.7 million attempted cyberattacks against Jamaica in 2025, with a further 5.4 million logged in the first quarter of 2026 alone. Those figures cover the whole spectrum of attempted intrusions, not business email compromise specifically, but they establish something worth sitting with: Jamaican networks are already being probed at a scale that has nothing to do with whether any individual company feels like a plausible target.
The financial picture behind business email compromise specifically is just as blunt. The FBI attributes US$3.05 billion of 2025's total US$20.9 billion in reported cybercrime losses to business email compromise on its own, and 86% of those fraudulent transactions moved through wire transfer or ACH, the exact payment rails a Jamaican import business, hotel group, or professional services firm uses every week to pay suppliers and settle invoices. AI does not need to touch Jamaica's numbers directly to matter here. It only needs to make the existing playbook faster and cheaper to run at scale, and Barracuda's demonstration shows it does exactly that.
Why "We'd Never Fall for That" Doesn't Hold Anymore
Jamaican finance teams have spent years training staff to spot the old tells: awkward phrasing, an unfamiliar sender address, a request that arrives with unusual urgency. Those tells assumed a human attacker was writing under time pressure, often in a second language, and would eventually make a mistake worth catching. An AI assistant reading months of real correspondence before drafting a reply does not make that mistake. The message that lands in an accounts payable inbox reads exactly like the executive who normally sends it, because in a meaningful sense, it was built from that executive's own words.
Hardy's column distills the defence that survives this shift into one rule: no instruction about money is confirmed on the same channel it arrived on. An email asking for a changed account number gets a phone call back, using a number already on file, not one supplied in the message. A voice note asking for an urgent transfer gets verified against the person's actual calendar and location before anyone moves money. The rule does not require new software. It requires finance teams to treat every payment instruction as unverified until it has been confirmed somewhere else.
"Dem tell wi seh check di email good an' spot di bad grammar. Now di email read perfect, so wi haffi call back pon a number wi already have, every time, no matter how much di boss soun' like demself inna it." An accounts payable officer at a Kingston financial services firm, describing the callback verification rule introduced after the Barracuda demonstration made the rounds internally
Where Jamaica's Own Institutions Fit
The Bank of Jamaica regulates the national payment system and is currently amending the Payment, Clearing and Settlement Act, 2010, to create a formal licensing and supervision regime for payment service providers. That work addresses who is allowed to move money through Jamaica's payment rails and under what conditions. It has not, as of this writing, produced AI-specific guidance on verifying payment instructions, which means the callback discipline described above is something individual banks and businesses are left to adopt on their own rather than something a regulator has mandated.
JAMPRO's role sits one step removed but is not irrelevant. The agency promotes Jamaica to investors across computer services, business process outsourcing, and financial technology, sectors built entirely on the trust that money moving through Jamaican systems moves safely. A single well-publicised AI-assisted fraud case at a Jamaican financial services firm does more to undercut that pitch than a dozen investment briefings can repair, which puts basic payment-verification discipline closer to an investment-climate issue than a back-office one.
On the workforce side, UWI Mona's computing programmes already supply much of the island's cybersecurity talent, and HEART/NSTA Trust, the agency already certifying Jamaica's national AI skills curriculum under the government's GAINS programme, is positioned to extend that same certification apparatus into AI-fraud literacy for finance and accounts payable staff specifically. Neither institution currently runs a module built around this exact scenario, verifying an AI-drafted payment instruction rather than spotting a poorly written phishing email, which leaves a training gap between what Jamaica's workforce pipeline teaches today and what Barracuda's demonstration shows attackers can already do.
The Blue Mountains overlooking Kingston. The city below is where most of the payment instructions this fraud technique targets get approved and released.
What Jamaican Finance Teams Should Do This Week
- Verify on a second channel, always. Never confirm a changed account number, an urgent wire request, or a payment instruction using only the channel it arrived on. Call back using a number already on file.
- Audit inbox rules on financial accounts. Compromised accounts are frequently modified with hidden forwarding rules that route replies away from the real owner. Check the finance team's mailboxes for rules nobody set up deliberately.
- Limit what an AI assistant can read and send. If staff use Copilot, a browser-based assistant, or any AI tool with inbox access, restrict its permissions on financial accounts to the minimum needed, and remove access entirely from accounts that handle payment approvals.
- Move to phishing-resistant authentication. Passkeys or hardware security keys close off the credential-theft route that starts most of these attacks in the first place, and cost little per user against the size of a single successful fraud.
- Keep JaCIRT's contact details on hand before you need them. Jamaica's Cyber Incident Response Team publishes reporting guidance at cirt.gov.jm. Knowing who to call before an incident happens saves the hours that matter most for recalling a wire transfer.
Where StarApple AI Jamaica Fits
This is exactly the terrain StarApple AI Jamaica, the Jamaican arm of StarApple AI, the first AI company established in the Caribbean, founded by Adrian Dunkley, the region's leading AI authority, was built to work in. The AURA readiness assessment gives an organisation an honest look at where its AI exposure actually sits, including who has AI assistant access to financial systems and what permissions those tools carry, before a business finds out the hard way. The LUCID training programme takes staff through practical scenarios built around real workflows, the same kind of callback verification and permission discipline this article describes, rather than generic phishing-awareness slides that do not address what an AI-drafted instruction looks like.
Neither exists to sell a Jamaican business software it does not need. Both exist because the gap Hardy's column identifies, staff trained to catch bad grammar rather than to verify instructions on a second channel, is the same applied gap StarApple AI Jamaica works to close across every sector it serves.
What Comes Next
Barracuda's demonstration will not be the last of its kind. AI assistants keep getting better at exactly the tasks that made this attack work: reading context, matching tone, drafting quickly. The defence that survives that improvement is not a smarter spam filter. It is a verification habit that does not depend on spotting anything at all, confirming money instructions on a channel the attacker does not control, every time, regardless of how convincing the request looks. Jamaican finance teams that build that habit now are the ones who will not be reading about their own company in next year's version of this story.