Book a demoBook a demo
Back to blog

Phishing Scams in Canada: How Fake Vendor Emails Cost Millions

Canadians reported losing more than C$704 million to fraud in 2025. Some of the largest business losses began with an ordinary-looking email about new banking details or an urgent payment.

C$704M+reported fraud losses
112,000+fraud reports
C$11.8MMacEwan vendor-email case

The employee authorized the transaction. The bank processed it correctly. The money went to a criminal.

These attacks are known as vendor impersonation, invoice fraud, spear phishing, or business email compromise. The names vary, but the strategy is the same: impersonate someone the victim already trusts.

How much money do Canadians lose to fraud?

The Canadian Anti-Fraud Centre received more than 112,000 fraud reports involving over C$704 million in losses during 2025.

Only an estimated 5% to 10% of fraud is reported in Canada, so the recorded losses represent a fraction of the likely total.

Selected reported Canadian fraud losses in 2025
Fraud typeReported victimsReported losses
Investment fraud3,867C$351 million
Spear phishing571C$67.9 million
Relationship fraud933C$63.3 million
Job fraud1,726C$50.6 million
Fraud-investigator scams1,137C$28.3 million
Recovery scams569C$25.9 million

Spear phishing is especially costly for businesses and public institutions. Its 571 reported victims lost an average of approximately C$118,900 each.

Source: Canadian Anti-Fraud Centre fraud statistics for 2025 and Canada’s National Anti-Fraud Strategy discussion paper.

What is a vendor impersonation scam?

A vendor impersonation scam occurs when a criminal pretends to be a trusted supplier and asks a company to send payments to a different bank account. The request usually arrives by email and may include realistic invoices, company branding, employee names, and details about an existing business relationship.

It is also called:

  • Vendor email compromise
  • Supplier impersonation
  • Fake invoice fraud
  • Payment-diversion fraud
  • Business email compromise

The criminal may create an email address that closely resembles the vendor’s address or take control of a genuine employee account.

What is business email compromise?

Business email compromise, or BEC, is a targeted scam in which criminals impersonate executives, employees, vendors, or professional advisers. They use trusted business communications to convince someone to transfer money, change banking information, disclose confidential data, or provide account access.

Unlike conventional phishing, a BEC email may contain no dangerous link, attachment, or malware. The fraudulent instruction is the attack.

Case study 01

How did MacEwan University lose C$11.8 million to a fake vendor email?

In 2017, employees at MacEwan University received emails that appeared to come from Clark Builders, a construction company working with the university.

The sender claimed that the vendor had changed its banking information. Employees updated the payment details and sent three payments totalling C$11.8 million to fraudulent accounts in Canada and Hong Kong.

The fraud was discovered when the real Clark Builders contacted the university about its unpaid invoices. Investigators later traced and froze most of the transferred money.

The university’s computer systems had not been compromised. The scammers reproduced the vendor’s identity and supplied a convincing payment request.

Source: Maclean’s investigation into the MacEwan University phishing scam.

Why did the MacEwan phishing scam work?

The request involved:

  • A real vendor
  • An existing commercial relationship
  • A normal business process
  • Professional branding and documentation
  • Banking instructions that appeared credible

The payment team had no immediate, independent way to confirm whether Clark Builders had authorized the change.

The case shows why checking spelling, logos, and writing quality is insufficient. Every visible part of a business identity can be copied.

Case study 02

How did a fake vendor email cost the City of Hamilton C$274,000?

Between November 2023 and January 2024, the City of Hamilton received emails from someone posing as an existing vendor.

Employees changed the vendor’s electronic-payment details based on those messages. Subsequent payments were diverted to bank accounts controlled by the fraudster.

The city lost C$274,000 and did not expect to recover the money. The scheme was discovered when the real vendor contacted the city about its overdue invoices.

Hamilton’s internal audit found that employees had overlooked warning signs and failed to follow existing verification procedures.

Source: City of Hamilton vendor-fraud and internal-audit findings.

Why did Hamilton’s vendor-verification process fail?

The city had fraud training and due-diligence procedures, but employees still needed to remember and apply them manually.

The banking change was processed using information received through the same email channel that needed to be verified. No independent confirmation prevented the fraudulent request from entering the payment system.

A security policy offers limited protection when the workflow does not enforce it.

How can you tell if a vendor email is fake?

A vendor email may be fraudulent if it:

  • Requests unexpected changes to banking information
  • Uses a slightly altered domain name
  • Changes the normal payment process
  • Creates unusual urgency
  • Discourages contact with other employees
  • Supplies a new phone number for confirmation
  • Requests secrecy
  • Changes tone or writing style
  • Sends an invoice with unfamiliar account details
  • Pressures staff to bypass approval procedures

However, the absence of these warning signs does not prove that an email is legitimate. A compromised vendor account may use the correct address, pass domain-authentication checks, and continue a genuine email conversation.

How should a business verify a vendor banking change?

Businesses should verify every vendor banking change through a process independent of the original request.

  1. Do not use the phone number included in the email.
  2. Retrieve the vendor’s contact information from an existing contract, verified record, or previous payment file.
  3. Contact an authorized vendor representative.
  4. Confirm the new account details verbally or through an approved portal.
  5. Require a second employee to approve the change.
  6. Record who requested, verified, and approved it.
  7. Send a confirmation to the vendor’s previously established contact.
  8. Monitor the first payment made to the new account.

The employee who enters the banking change should not be the only person who verifies and approves it.

What should you do after sending money to a scammer?

If your organization discovers a fraudulent payment, act immediately:

  1. Contact the sending bank and request a transfer recall or freeze.
  2. Ask the bank to notify the receiving financial institution.
  3. Preserve emails, headers, invoices, call records, and payment documents.
  4. Notify the organization’s finance, security, legal, and insurance teams.
  5. Report the incident to local police.
  6. File a report with the Canadian Anti-Fraud Centre.
  7. Secure any compromised email or employee accounts.
  8. Contact legitimate vendors whose identities may have been used.
  9. Review other recent banking changes and pending payments.

Recovery becomes less likely as the money moves through additional accounts or leaves Canada.

How common is fraud in Montreal?

The Service de police de la Ville de Montréal recorded 11,617 fraud offences in 2024.

That represented:

  • An 11.2% increase from 2023
  • A 23.7% increase over the 2019–2023 average

The SPVM attributed much of the growth to card and computer fraud.

Its public report does not identify how many incidents involved vendor emails, business impersonation, or unrecovered transfers. The figures nevertheless demonstrate that fraud is a significant and growing local problem.

Source: SPVM 2024 Annual Review.

How is AI making phishing scams harder to detect?

Generative AI helps criminals create personalized emails, realistic documents, cloned voices, synthetic video, and convincing professional profiles.

It removes warning signs that employees traditionally associate with scams, including:

  • Poor grammar
  • Awkward phrasing
  • Inconsistent branding
  • Unnatural speech
  • Low-quality images
  • Generic messages

AI does not need to invent a new type of fraud. It allows criminals to conduct established scams more convincingly and at a larger scale.

The relevant question is no longer whether a message looks professional. It is whether the communication can be independently connected to the party it claims to represent.

Why don’t email security and phishing training stop every scam?

Email filters, multifactor authentication, and employee training protect different parts of an organization, but they do not prove who authorized a business request.

Where common fraud controls stop
Existing controlWhat it does not confirm
Spam and phishing filtersWhether a harmless-looking payment request is genuine
SPF, DKIM and DMARCWho controls a legitimate compromised account
Multifactor authenticationWhether an authenticated employee is being manipulated
Transaction monitoringWho issued the payment instruction
Employee trainingWhether a convincing communication belongs to the claimed sender
Manual callbacksWhether staff used independently verified contact information

These controls remain necessary. The unresolved issue is the identity and authority behind the communication.

How can identity verification prevent business email compromise?

Identity verification can prevent business email compromise by checking the sender and request against information registered by the claimed organization.

An effective system should verify:

  • The organization’s legal identity
  • Its official communication channels
  • The sender’s role and authority
  • Whether the channel is approved for the requested action
  • Whether a high-risk request received independent authorization

This changes the decision from “Does this email look real?” to “Can this request be connected to an authorized and accountable party?”

How Gemisis verifies business communications

Gemisis is building a verification and traceability layer for digital communications.

Organizations register their legal identities, departments, authorized representatives, and official channels. Recipients can then verify supported calls, emails, and messages inside the applications where those communications occur.

For a vendor banking change, Gemisis could verify whether:

  1. The sender’s channel is registered to the vendor.
  2. The sender is authorized to request banking changes.
  3. The request followed the vendor’s approved process.
  4. A separate authorized representative confirmed the instruction.

A copied logo, familiar name, or professional email would not produce verification by itself.

Gemisis does not guarantee that every registered organization will behave honestly. It establishes whether the party is identifiable, traceable, and accountable—and warns the recipient when that relationship cannot be verified.

Can verification protect against a compromised vendor account?

Verifying an email address alone cannot stop every vendor scam.

If a criminal controls a vendor’s genuine mailbox, the email may originate from the correct domain and pass technical authentication. Sensitive actions therefore require request-level authorization that is separate from the message itself.

A secure verification process must confirm both the communication channel and the authority behind the requested action.

Frequently asked questions

What is the most costly type of fraud in Canada?

Investment fraud produced the highest reported losses in 2025 at C$351 million. Spear phishing caused C$67.9 million in losses and was particularly relevant to businesses and public institutions processing payments or changing vendor information.

Is a vendor email safe if it comes from the correct address?

Not necessarily. Criminals can compromise a genuine vendor mailbox and send messages through the correct domain. Any request to change banking information should be confirmed independently using previously verified contact information.

What is the safest way to confirm new banking details?

Contact a known vendor representative using information stored in an existing contract or verified vendor record. Do not use the phone number or link supplied in the banking-change email. Require a second employee to approve the update.

Where should a phishing scam be reported in Canada?

Contact your financial institution and local police immediately. Fraud and attempted fraud should also be reported through the national reporting system operated by the Canadian Anti-Fraud Centre. Preserve all related communications and payment records.