Interac e-Transfer Fraud: How Canadian Businesses Lose Money to Payment Redirection
Spear phishing cost Canadians approximately $57.7 million in reported losses during the first six months of 2026, according to the Canadian Anti-Fraud Centre. That figure already approaches the $68 million lost in all of 2025. The CAFC estimates only 5% to 10% of fraud is reported, meaning actual losses are likely far higher. These frauds often involve compromised or spoofed communications and may target businesses by impersonating executives, suppliers, contractors, or other trusted contacts to redirect payments or change banking information. For Canadian businesses, two patterns stand out: payment redirection (where criminals impersonate a supplier to change banking details) and Interac e-Transfer interception (where attackers hijack incoming customer payments).
What Is Payment Redirection Fraud?
Payment redirection fraud occurs when criminals impersonate a trusted contact and convince a business to send money to a fraudulent account. A CAFC advisory from May 2026 describes how partners helped recover approximately $3.5 million linked to a payment redirection fraud targeting a Quebec business. The victim had authorized two wire transfers after fraudsters manipulated email communications. The fraud was identified shortly afterward when financial institutions detected concerns, and quick reporting enabled the recovery. According to that advisory, payment redirection frauds commonly target small and medium enterprises, with businesses in the construction and contracting industry and real estate sector among the common targets.
How Do Criminals Redirect Business Payments?
Payment redirection fraud follows a predictable pattern: an attacker sends an email appearing to be from a trusted supplier, claims the supplier's banking details have changed, and requests a wire transfer to a new account. A 2026 Ontario decision illustrates how the scheme works and what happens afterward.
Air Liquide Canada Inc. v. 1001020467 Ontario Corp., 2026 ONSC 2254 involved Air Liquide Canada, an industrial gases company that owed $221,422.38 to a Quebec supplier, H. Blanchette Ltée, for steel and metalwork. In March 2025, Air Liquide received an email purporting to be from Blanchette claiming the supplier had changed its banking arrangements and wanted payment by electronic transfer instead of cheque. Air Liquide wired $221,422.38 to a Bank of Nova Scotia account in Ottawa. The account was not Blanchette's. The court found it was owned or controlled by the defendants, who include 1001020467 Ontario Corp., an Ontario numbered company. The court found it reasonable to assume the defendants were behind the fraud.
Air Liquide obtained a court order requiring the bank to identify the account holders, then sued. The defendants did not respond, and the court granted default judgment ordering return of the funds, $5,000 in damages for interference with the business relationship, and $100,000 in punitive damages. However, a judgment is not the same as recovery. At the time of the decision, Air Liquide still owed Blanchette the original $221,422.38, and Blanchette had sued Air Liquide in Quebec.
How Does Interac e-Transfer Interception Work?
Interac e-Transfer interception exploits compromised email accounts or fraudulently created Autodeposit registrations. According to Interac's fraud guidance, attackers who gain access to a business email can lay in wait for messages that would be lucrative to intercept, such as money transfer notifications, and divert funds into their own accounts. CityNews reported in March 2026 that a North York business, Beyond Marble and Granite, discovered on March 13 that customer e-transfers were going to another person's account. An Interac spokesperson told CityNews that someone had fraudulently created an Autodeposit registration: the business's email address remained the same, but a different name had been attached to the account.
Which Businesses Are Most at Risk?
The CAFC's May 2026 advisory identifies construction, contracting, and real estate as common targets for payment redirection fraud. These industries involve large payments, multiple parties, and frequent changes to banking details, all of which make fraudulent requests less likely to raise suspicion. Small businesses are particularly vulnerable because they often lack segregation of duties in accounts payable, meaning one person can both receive a payment request and execute the transfer without independent verification.
What Are the Warning Signs of Interac e-Transfer Fraud?
Red flags include unexpected requests to change banking or payment information, pressure to act quickly or bypass normal procedures, email addresses that closely resemble but do not match legitimate ones, notices about past-due invoices you have already paid, and any wire or e-transfer instructions that arrive outside your usual communication channels. Interac's fraud prevention page recommends a "Stop, Scrutinize, Speak Up" approach: pause before acting, examine the request carefully, and verify through a separate channel.
How Can a Business Verify Payment Requests?
The single most effective defence is out-of-band verification: before processing any change to payment details, call the supplier or client at a phone number you already have on file, not one provided in the request. The CAFC advises businesses to "confirm banking changes using trusted contact information" and to treat any urgency in the message as a reason for more scrutiny, not less. If a supplier genuinely changed banks, they will not object to a phone call confirming the new details.
Does Autodeposit Prevent Interception Fraud?
Enabling Interac e-Transfer Autodeposit can reduce interception risk by eliminating the email-and-security-question step that attackers exploit. When Autodeposit is on, funds go directly to the registered account with no link to click or question to answer. However, Autodeposit is not a complete solution. If an attacker compromises your email and registers Autodeposit under your address with their own bank account, incoming transfers will go to them. Check your bank's Autodeposit settings periodically and monitor email forwarding rules, as attackers often set these up without the account owner noticing.
What Should a Business Do After a Suspected Fraud?
Time is critical. Contact your financial institution immediately and request a recall of the funds. The faster you act, the higher the likelihood of recovery. Then report the incident to the Canadian Anti-Fraud Centre at 1-888-495-8501 or online, and file a report with local police. Preserve all emails, invoices, and communication records related to the transaction. If you have cyber insurance, notify your insurer promptly. Follow your incident response plan for next steps.
How Does This Connect to Business Email Compromise?
Payment redirection is a subset of business email compromise, the broader category of fraud that exploits trust rather than technical vulnerabilities. BEC can also include CEO impersonation, payroll diversion, and legal-closing fraud. The common thread is that attackers manipulate human processes, not software. Technical controls like multi-factor authentication on email accounts reduce the risk of account compromise, but procedural controls (verification calls, dual authorization for large transfers) are what stop the fraud after an attacker has already gained a foothold.
What Procedural Controls Should a Business Implement?
Effective controls include: requiring phone verification for any change to vendor banking details, requiring dual authorization for wire transfers or e-transfers above a defined threshold, training accounts payable staff to treat urgent requests with more scrutiny rather than less, and conducting periodic reviews of your Autodeposit registration, email forwarding rules, and account access logs. These procedures should be written, communicated to all staff who handle payments, and treated as non-negotiable. The authentication and incident response control pages on this site summarize what the Canadian Centre for Cyber Security recommends for these areas.
Next Step
If you are not sure where your business stands on email security, payment verification procedures, or incident response readiness, our free cybersecurity assessment evaluates your organization against 13 control areas based on federal guidance. It takes under 30 minutes and produces a plain-language report showing where your current posture may leave you exposed to payment fraud.
How prepared is your business?
Find out where you stand against Canada's 13 Baseline Cyber Security Controls. The assessment takes under 30 minutes and your answers stay in your browser.
Check Your ScoreCite This Page
Suggested citation:
Cybersecurity Canada (2026). Interac e-Transfer Fraud: How Canadian Businesses Lose Money to Payment Redirection. Retrieved from https://cybersecuritycanada.ca/news/posts/interac-e-transfer-fraud-payment-redirection-canadian-businesses/
Permanent URL: https://cybersecuritycanada.ca/news/posts/interac-e-transfer-fraud-payment-redirection-canadian-businesses/ · Published October 2, 2026
Disclaimer: This article is intended for general informational purposes only and does not constitute professional cybersecurity, legal, IT, or compliance advice. While we strive to ensure accuracy, the cybersecurity landscape changes rapidly and information may become outdated. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation and develop appropriate security policies. Use of this information is at your own risk. See our Privacy Policy for more information.
Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.
How does your organization measure up?
Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential. Your answers never leave your browser.
Take the Free Assessment