Home › Industries › Wealth Management
Wire Fraud and Business Email Compromise at Canadian Wealth-Management Firms
Last updated: August 2026 · Reviewed by Mike Pearlstein, CISSP
The costliest cyber incident at a wealth-management firm is rarely exotic. It is usually a redirected client transfer that began with a compromised or spoofed email. Here is exactly how the attack works, the one control that breaks it, and what a Canadian advisory firm has to do in the first hour after it happens.
- Spear phishing and business email compromise drove CA$67.9 million in reported losses to the Canadian Anti-Fraud Centre in 2025, second only to investment fraud by dollar loss.
- The attack is a patient, watched email thread, not a clumsy phishing blast. The fraudster sends revised banking details at the exact moment a transfer is expected.
- One process control stops it cold: out-of-band callback verification on any change to payment or banking instructions.
- Multi-factor authentication and email-impersonation protection close the door the attacker came through, and a written 60-minute incident plan decides whether the money comes back.
How big is the wire-fraud problem for Canadian firms?
Big, and growing. According to the Canadian Anti-Fraud Centre (2026), Canadians filed more than 112,000 fraud reports in 2025 carrying over CA$704 million in reported losses. Spear phishing, the category that captures business email compromise, accounted for CA$67.9 million across 813 reports and 571 victims. It ranked second by dollar loss, behind investment fraud.
Where the CA$704 million actually goes
The loss is concentrated in exactly the work advisory firms do every day. Investment fraud topped the 2025 table at CA$351 million. Spear phishing followed at CA$67.9 million from only 813 reports, which works out to roughly CA$119,000 per victim. That average is what makes a single incident existential for a small practice.
That figure understates the real scale. Only 5 to 10 percent of victims ever report, so the true loss to Canadian businesses is a multiple of the published number. South of the border the pattern is identical. The FBI Internet Crime Report (2024) tied business email compromise to US$2.77 billion in losses across 21,442 complaints.
How the attack actually works
The attack is patient, not clumsy. According to Statistics Canada (2024), 16 percent of Canadian businesses absorbed a cyber security incident in 2023, with large firms hit hardest at 30 percent. Advisory practices are not over-represented in that count. What is unusual about them is the size of a single loss.
The four stages, in order
Forget the broken-English phishing email. A modern business email compromise is patient and quiet. The attacker first gains access to a real mailbox, or registers a look-alike domain that reads correctly at a glance. Then they wait, reading the genuine conversation about a pending transfer or fee payment.
At the moment money is expected, they insert one believable message with revised banking details. The tone matches. The thread is real. Nothing about it trips the recipient’s instinct, because almost everything in it is genuine. The RCMP describes the same playbook: impersonate a trusted party, exploit a real payment, redirect the funds.
Every business email compromise case I have worked started the same way. A real, watched email thread with revised banking details arrived at the exact moment of a pending transfer. Never a clumsy blast. In my experience the hardest part afterward is the partner accepting that the message looked completely normal, because that is the part that feels like a personal failure.
The mechanics matter because they tell you where defence works. The attacker does not need to break encryption or defeat your firewall. They need one believable message to land at one vulnerable moment. That is a human and process problem first, and a technology problem second.
Why wealth-management firms are a prime target
Advisory firms are targeted for what they can move. According to a peer-reviewed study of Microsoft Azure Active Directory accounts (2023), MFA cut compromise risk by 99.22 percent across the population and 98.56 percent where credentials had already leaked. That closes the mailbox door. It does nothing about a look-alike domain, which is why the callback rule carries the payment.
Three things fraudsters look for in an advisory practice
Advisory practices combine three things fraudsters love. You move client money on instructions that often arrive by email. You hold detailed know-your-client and banking records that make impersonation convincing. And client transfers are frequently large and time-sensitive, so urgency is built into the work.
The same attack pattern hits Canadian builders, only the target is a milestone release rather than a client transfer. See our companion guide to cybersecurity for construction firms in Canada for the progress-draw version of this kill-chain.
There is a compliance dimension too. A redirected transfer is not only a loss. It can trigger client-information duties under PIPEDA and a conversation with your regulator about whether reasonable safeguards and supervision were in place. For the broader regulatory picture, see our guide to CIRO cybersecurity for wealth firms.
BEC vs ransomware: what the 2026 DBIR changed
Ransomware gets the headlines. Business email compromise takes the money. According to the 2026 Verizon Data Breach Investigations Report, exploited vulnerabilities now open 31 percent of breaches, ahead of stolen credentials at 13 percent, while ransomware appears in 48 percent. The entry point moved. The payout mechanism did not.
That inversion matters for how I would sequence a security budget at an advisory firm. In 2025 the standard advice was to spend first on credential hardening. I now put edge and third-party patching alongside it, because the 2026 data says an unpatched internet-facing device is the more likely front door.
[CONTRARIAN THESIS] What has not changed is the payment step. Credential theft, a look-alike domain, and an exploited VPN appliance all converge on the same final move, which is a revised set of banking details arriving at the right moment. I have never seen a firm lose a transfer that ran a real callback.[REGULATOR QUOTE] RCMP warning signs.
“Financial transaction requests with pressure to act quickly; demands for secrecy; not following normal procedures; involving direct contact with a senior official you are not normally in contact with.”
RCMP. Business Email Compromise. Print these 4 signs and tape them beside the payments desk.
Want this reviewed against your firm’s current setup?
What is the single control that stops a fraudulent transfer, explained
Out-of-band callback verification. Treat any change to banking or transfer instructions as unverified until a person confirms it by phone, on a number from your own records, never a number or link supplied in the email. This one step breaks the attack even when the mailbox is fully compromised, because the fraudster does not control the client’s real phone line.
Everything else is defence in depth around that core rule. If you adopt one thing from this article, write the callback rule down and make it non-negotiable. Writing it down is what turns a good habit into a control your auditor and your cyber-insurer will credit. I have watched that single page change an insurance renewal conversation.
The callback-verification protocol: steps and criteria you can adopt this week
Most firms already do callbacks informally, and informal is the part that fails at 4pm on a Friday. Formalizing the rule is what makes it reliable under pressure. This is the protocol I put in place for advisory clients, and it fits on one page:
- Treat any change to banking or transfer instructions as unverified until a person confirms it.
- Call the client back on a number from your own records or CRM, never a number or link supplied in the email.
- Read the destination account detail back and have the client confirm it verbally.
- Record who verified the change, when, and how, in the client file.
- For transfers above a set threshold, require a second staff member to sign off before funds move.
The written record in step four matters as much as the call itself. When a regulator or insurer asks how you prevent fraudulent transfers, a documented, dated verification log is the difference between a strong answer and an uncomfortable silence.
The technical controls that close the door
Process stops the fraudulent payment. Technology stops the mailbox compromise that makes the fraud possible in the first place. Three layers do most of the work.
Three layers, in priority order
Enforced multi-factor authentication on email and any system that touches money makes a stolen password far less useful on its own. Email-impersonation protection flags spoofed senders, look-alike domains, and auto-forwarding rules that attackers quietly set up to watch a thread. Staff awareness training keeps the human layer alert to the pattern, which is decisive when the message itself looks legitimate. Our security awareness training is built around exactly these scenarios.
When I review an advisory firm, the gap I find most often is not missing MFA on the main login. It is a forgotten mailbox rule. An attacker quietly set up auto-forwarding months earlier and has been reading transfer threads ever since. I budget ten minutes for forwarding and delegation rules, and that check has surfaced compromises nobody in the firm had noticed.
What should a firm do in the first 60 minutes?
Move fast and in a fixed order. Speed decides whether the funds are recovered, and a recall has the best odds in the first hours. A short written plan that names who does each step saves the time that matters most:
- Call the receiving and sending banks’ fraud lines immediately to attempt a recall of the transfer.
- Report to the Canadian Anti-Fraud Centre and to local police.
- Preserve the relevant emails, full headers, and sign-in logs before anything is deleted.
- Reset the compromised mailbox password and revoke active sessions, app passwords, and forwarding rules.
- Notify the affected client, and assess whether a privacy-breach report to the Office of the Privacy Commissioner or a CIRO notification is required.
Rehearse it once, around a table
A firm that has rehearsed these five steps, even once around a table, recovers faster and demonstrates the diligence a regulator and an insurer expect to see.
What do you have to report, and to whom?
It depends on what was exposed. A pure financial loss with no client data exposed is reported to the banks, the CAFC, and police. If client personal information was accessed, PIPEDA breach-reporting duties to the Office of the Privacy Commissioner may apply where there is a real risk of significant harm.
Firms regulated by the Canadian Investment Regulatory Organization should also weigh their own notification and recordkeeping duties. When in doubt, document the assessment and the decision, because the reasoning itself is evidence of diligence.
Who gets told, and when
Vendor exposure is a related blind spot. If a fraud reaches you through a third-party platform or a partner’s compromised mailbox, your vendor and third-party risk is part of the story your regulator will want to understand.
How we would set this up
[ORIGINAL DATA] Across our 60+ Canadian SMB security engagements, we measured which firms lost a transfer and which did not. The ones that never lost one were not the ones with the biggest security budget. In my experience they are simply the firms with a written callback rule and a team that follows it under pressure.For a firm without an internal security lead, I anchor on that rule first. Then we enforce MFA across email and money-movement systems, turn on impersonation protection, audit mailbox forwarding and delegation, and write a one-page incident plan the team can actually follow.
That package addresses the threat that costs the most, for a fraction of what a single redirected transfer would. It is the core of our managed cybersecurity work for regulated firms. If you are still picking a partner, compare IT providers for wealth-management firms first. The federal Get Cyber Safe program publishes the same baseline controls for Canadian organizations.
Frequently asked questions
What is business email compromise?
How do wealth firms prevent fraudulent transfers?
What is out-of-band callback verification?
What should a firm do if it suspects a fraudulent transfer?
Do we have to report a wire-fraud incident to a regulator?
How common is business email compromise in Canada?
Will multi-factor authentication alone stop wire fraud?
Is Fusion Computing the same as Fusion Cyber Group?
Talk to Fusion about your firm’s security
If your firm wants a partner that understands CIRO expectations and protects client money, talk to us. I will review your current posture and show where the evidence gaps are before they cost you a transfer.
Book a consultation or call (416) 566-2845
Written by Mike Pearlstein, CISSP, founder of Fusion Computing, a Canadian managed IT and cybersecurity provider serving regulated SMBs since 2012.
Regulated industries we secure: law firms · accounting firms · financial services · wealth management · industries
Related: CIRO cybersecurity for wealth firms · vendor and third-party risk · wealth management.

