The Bank of Nevis has alerted its customers to two cybersecurity developments identified by law enforcement partners, warning that the threats extend beyond St Kitts and Nevis to the wider Organisation of Eastern Caribbean States.
The financial institution said it had been advised by the Eastern Caribbean Central Bank to take all necessary measures in response to the developments, according to a statement issued from Charlestown.
The bank did not disclose the specific nature of the two threats in its public statement, but its decision to notify customers directly signals that the matter is being treated as a live risk to account holders and to the regional financial system.
The ECCB, which supervises the Eastern Caribbean currency union and issues the EC dollar, is the central monetary authority for eight member states, including Dominica. Its involvement places the warning at a regional level rather than a single-island concern.
For customers in Dominica and across the OECS, the practical effect is a renewed emphasis on basic account security. Banks in the sub-region routinely advise account holders never to share personal identification numbers, one-time passwords or online banking credentials, and to verify any unsolicited message that appears to come from a financial institution before responding.
Cyber threats to Caribbean banks have grown in recent years as more customers move to digital and mobile banking. Regional institutions have faced phishing attempts, card fraud and social engineering attacks designed to extract login details from customers, while lenders themselves have had to harden internal systems against intrusion.
The Bank of Nevis is a long-established indigenous bank headquartered in Charlestown, the capital of Nevis. It serves individual depositors, businesses and the Nevis Island Administration, and its customer base includes account holders connected to other OECS territories through trade, employment and family ties.
Its statement follows a pattern in which regional regulators and law enforcement agencies share threat intelligence with supervised institutions, which then pass on protective guidance to the public. The ECCB has previously urged banks under its remit to strengthen cybersecurity controls and to report incidents promptly.
No details were released about whether any customer accounts had been compromised, whether funds had been lost, or whether any arrests or charges were linked to the two developments. The bank's statement did not name the law enforcement partners involved.
The warning is a reminder that the OECS operates as a single financial space in many respects. A threat detected in one member state can quickly affect customers in another, particularly where banks share payment networks, correspondent relationships and digital platforms.
Customers who suspect fraudulent activity on their accounts are advised to contact their bank immediately through official channels, monitor statements for unfamiliar transactions, and report suspicious messages rather than clicking on links or attachments they contain.
The Bank of Nevis said it would continue to act on the guidance of the ECCB and its law enforcement partners. Further information is expected as the institutions assess the two developments and determine what additional safeguards may be required.



