Business email compromise in BC: what Canada's 2025 fraud numbers mean for small businesses
Canadians reported $67.9 million lost to spear phishing in 2025. How fake payment emails are hitting BC businesses, and what to change this week.
Canadians reported losing more than $704 million to fraud in 2025, across more than 112,000 reports, according to the Canadian Anti-Fraud Centre’s 2025 figures published on February 25, 2026. Spear phishing, the CAFC category that includes business email compromise, was second by dollar loss at $67.9 million, behind only investment fraud.
For small businesses weighing the risk of business email compromise in BC, the per-victim number stands out. That $67.9 million came from 571 victims, or about $119,000 each on average (our math, not the CAFC’s). And the CAFC estimates only 5 to 10% of victims report at all.
How the scam works
The RCMP describes business email compromise as a criminal posing as someone you trust, like a supplier or your boss, to get you to send money. The email comes from a spoofed address or from a real account the criminal has broken into.
On July 24, 2025, the CAFC said it had worked with the Hong Kong Police Force to recover $2.3 million for a law firm in the Vancouver area. A spear phishing attack had tricked the firm into wiring the money to an account in Hong Kong. A Hong Kong bank flagged the suspicious transfer, and quick work with Canadian authorities got the full amount back. The CAFC’s advice in the release was to confirm any change in banking details by calling a phone number you already trust, turn on multi-factor authentication for email and banking, and have two people approve wire transfers.
Business email compromise in BC: recent cases
The Lawyers Indemnity Fund, which insures BC lawyers, said in a January 22, 2026 notice that fraudsters had targeted two medium-sized Vancouver law firms. At the first, the fraudster got into the firm’s email system, watched the conversation with the client, and sent a fake “verification complete” message from the partner’s own account. About $1.4 million went out, and LIF said it “remains to be seen how much can be recovered.” At the second firm, a trust accounting clerk noticed the payee didn’t match the client’s name and checked the account in person at the bank, which stopped the payment. In May, LIF reported another BC firm wired $900,000 after confirming payment instructions by email only.
In Surrey, Business in Vancouver reported on May 7, 2026 that a local property developer is suing to recover about $1.34 million. Its BC Supreme Court claim says someone intercepted emails between the developer and its Delta-based general contractor, then sent messages from a lookalike domain directing payment to a bank account in Brampton, Ontario. The claims haven’t been tested in court, and the contractor isn’t accused of any wrongdoing.
On May 7, 2026, Cranbrook RCMP said it was investigating several cases where criminals got into Microsoft 365 business email accounts, including ones with two-factor authentication, and emailed clients from the real address asking them to pay invoices into a different account. In December 2025, Fort St. John RCMP warned that fake vendor addresses are often “off by one letter or one number.”
What DMARC stops, and what it doesn’t
DMARC is a DNS setting that, once enforced, tells other mail servers to reject or quarantine email faking your exact domain. LIF’s January notice tells law firms to talk to their IT professional about SPF, DKIM and DMARC. When we checked the public DNS records of 3,392 businesses across 12 industries in the Lower Mainland in September 2026, 81% had no enforced DMARC. In Burnaby it was 84% of 445 businesses. These are businesses we researched, not a random sample.
DMARC does nothing about a lookalike domain like the one in the Surrey lawsuit, and it can’t help when the criminal is inside your real mailbox, as in the LIF and Cranbrook cases. So pair it with multi-factor authentication, regular checks of forwarding rules and sign-in logs (Cranbrook RCMP recommends both), and a firm rule that nobody changes payment details because of an email.
Warning signs and what to do
The RCMP’s business email compromise guidance lists warning signs such as pressure to pay quickly or keep quiet, a request that skips your normal process, a sender address that’s slightly altered (abc_123 instead of abc-123), and a supplier asking for payment outside its usual schedule.
The RCMP’s “Reject it” steps include training staff, registering domains that look like yours, confirming payment requests by phone, and requiring two signatures for wire transfers. Under “Report it,” it says to act whether or not money left: tell your IT people, file a police report that calls it “BEC” or wire fraud, and report it to the CAFC. If money went out, call your bank right away and ask about recalling the transfer. You can report online at reportcyberandfraud.canada.ca or by calling 1-888-495-8501.
Invoice fraud checklist for small businesses in Vancouver
An office in Vancouver or Richmond can do all six of these this week:
- Write down a call-back rule: any new or changed banking details get confirmed by phone, using a number from your own records or an old invoice, never the one in the email.
- Turn on multi-factor authentication for every email account, including shared ones like accounts@.
- Check each mailbox for forwarding rules nobody remembers setting up, and look at recent sign-ins for places that don’t fit.
- Look up your domain’s DMARC record. If it’s missing or set to p=none, start with our DMARC guide.
- Require a second person to approve any wire transfer.
- Put 1-888-495-8501 and your bank’s fraud line where the person who pays the bills can find them.
Umbrella IT has looked after Metro Vancouver businesses since opening in Burnaby in 2013. Setting up DMARC and MFA is part of our cybersecurity work, and our regular staff security training covers emails like these.
Common questions
What should I do if we already paid a fake invoice?
Call your bank first and ask them to recall the transfer, since the CAFC says sent money is often moved quickly. Then report it to local police and to the CAFC.
Would DMARC have stopped these BC cases?
Not the ones where the method is public. The LIF and Cranbrook cases involved real mailboxes that criminals had got into, and the Surrey lawsuit describes a lookalike domain. A call to a number you already have is what catches those before money moves.
Is business email compromise only a problem for law firms?
No. The RCMP lists payroll and supplier versions, and the Surrey case involved a developer and its contractor.
If you’d like us to check your domain’s email records and your payment approval steps, book a free IT assessment.
Want this checked against your own setup?
Book a free IT assessment and a senior tech will review where your business stands, with no obligation.