Skip to main content
Business scam
• Feb. 27, 2024

For almost anyone who works in an office, receiving a flood of emails is just part of the daily routine.

And while working through them as efficiently as possible is also part of the job, responding quickly sometimes means we aren't taking time to verify every email coming in.

For example, what if you were to get a message from your boss asking you to pay an overdue invoice from a new vendor? Chances are you'd make that a priority.

But it's possible that the email didn't actually come from your boss. If you're not careful, it would be easy not to notice that it could have been sent by a fraudster trying to scam your company.

This is a common tactic called a business email compromise (BEC) scam, and unfortunately, it's often very effective.

In 2020, the Canadian Anti-Fraud Centre reported that Canadian victims lost almost $30 million to this scam, and more than $26 billion was stolen from victims worldwide.

"Virtually every type and size of business is vulnerable to business email compromise scams," says Dennis Parker, Vice President, Business Banking at TD.

"Unfortunately, it doesn't take a lot of technical savvy to trick people into making fraudulent payments."

How the scam typically works

BEC scams generally start with reconnaissance. Fraudsters may spend weeks harvesting information from your company website, social media platforms, press releases and other reliable sources, and sometimes even intercept email exchanges before deciding who to target and when to strike.

At the same time, fraudsters need to determine who to impersonate – usually a senior leader, known vendor or employee – and whether they will hack or spoof that person's email account.

What typically happens next is the fraudsters craft a well-timed email with an urgent and authoritative tone that instructs their target to:

  • Pay an invoice via wire payment or electronic funds transfer (EFT),
  • Update account information for existing vendors, or
  • Update employee payroll information

It is usually an email that appears to come from someone you know, has a sense of urgency, and sounds confident and convincing. The email is a piece of cleverly tailored social engineering, designed to make the recipient act on instructions and reluctant to question its contents before taking action.

How to protect yourself and your business

  • Don't assume that email is a secure way of communicating – it's easy for a fraudster to spoof an email address
  • Encourage a questioning culture within your business – employees should feel confident in being able to question an unusual request
  • Pick up the phone or speak in person to confirm payment instructions received by email
  • Establish policies and procedures to validate changes to vendor or employee information
  • Treat emails that ask for information related to account numbers, banking or other financial information as red flags
  • Ask your bank about additional security features like dual authentication to reduce your chances of being impacted by fraud

If you think you've been the victim of a business email compromise scam

Report it: BEC scams are a criminal offense. Even if funds weren't transferred, it is wise report the incident to local police, your financial institution and the Canadian Anti-Fraud Centre. These reports are valuable tools for investigators.

Talk about it: If you've fallen victim to a scam or even received a spoofed email, tell your story. Knowledge is power. Spreading the word helps prevent others from falling victim to these scams.


Want to learn more about your money?
Five ideas for what you could do with your tax refund
Some tips on how to possibly lower your tax bill
(Almost) everything you need to know about renewing a mortgage

See you in a bit

You are now leaving our website and entering a third-party website over which we have no control.

Continue to site Return to TD Stories

Neither TD Bank US Holding Company, nor its subsidiaries or affiliates, is responsible for the content of the third-party sites hyperlinked from this page, nor do they guarantee or endorse the information, recommendations, products or services offered on third party sites.

Third-party sites may have different Privacy and Security policies than TD Bank US Holding Company. You should review the Privacy and Security policies of any third-party website before you provide personal or confidential information.