TransferLog
/Blog
Log inGet started free
Back to blog
Small Business

Fake Interac e-Transfer Email: A Canadian Business Checklist

What a Canadian business should verify, preserve, and report after a suspicious e-Transfer notice, changed payment instruction, or email compromise.

TransferLog Team
August 11, 2026
8 min read

If a Canadian business receives a suspicious Interac e-Transfer email or text, do not click its link, reply, send money, or mark an invoice paid. Open online banking through the financial institution's known app or website, check whether the transaction exists, and confirm the sender or payment instruction through contact details you already trust.

If money or credentials may already have been sent, contact the financial institution immediately. Preserve the original messages and transaction records, involve whoever manages the business's email and devices, contact local police when appropriate, and report the incident to the Canadian Anti-Fraud Centre. Fast action can matter, but no recovery is guaranteed.

Which e-Transfer Fraud Scenario Are You Handling?

Start by separating three incidents that can look similar in an inbox:

  • A fake incoming-payment notice: a message claims a customer sent money, but no matching deposit exists in known online banking.
  • Changed payment instructions: someone impersonates a supplier, contractor, employee, or executive and asks the business to send an e-Transfer to a new address or account.
  • A compromised email or banking account: an attacker may read messages, add forwarding rules, reset credentials, or initiate or redirect real transactions.

The response differs. A fake notice should not close a customer balance. A changed instruction should stop the outgoing payment until independently verified. A suspected compromise requires account containment as well as transaction review.

Interac's e-Transfer FAQ says money does not travel by email or text and advises people to be suspicious of unexpected notifications, confirm with the sender, and forward an unconfirmed notification to phishing@interac.ca. The bank account—not the email—is where the business confirms whether money actually moved.

What Should You Do Before Clicking or Paying?

1. Stop the transaction and keep the message intact

Do not use a link, attachment, phone number, QR code, or reply address inside the suspicious message. Do not forward it around the business as a normal attachment, because another person may click it. Preserve the original email or text, including the date, sender address, subject, links shown without opening them, and any available message headers.

Avoid deleting the record after reporting it as spam. A copy may be needed by the financial institution, email provider, police, insurer, accountant, or Canadian Anti-Fraud Centre.

2. Verify the transaction in known online banking

Open the financial institution through a saved bookmark, known app, or manually entered address. Check the intended account and compare the amount, other party, status, date, and reference with the notice.

A matching-looking email is not settlement. A legitimate sent notification can also describe a payment that remains pending or later expires. Use the e-Transfer status reconciliation guide when a real transaction has not reached its final state.

3. Confirm the person through a trusted channel

Call the customer, supplier, employee, or executive using a phone number already in the contract, vendor master file, payroll record, or another trusted source. Do not use the contact details introduced in the suspicious message.

Ask about the exact amount, invoice, destination, and reason for any change. A familiar display name, writing style, invoice attachment, or copied email thread does not prove that the sender controls the real account.

4. Escalate any changed payment instruction

Interac's business-payment protection guidance recommends verifying payment requests, training staff to recognize suspicious messages, and reconciling accounts regularly. Treat a new recipient, changed email, urgent exception, secrecy request, or attempt to bypass approval as a reason for an independent check.

Use the business's normal approval process even when the request appears to come from an owner or important supplier. If the organization supports dual authorization or another commercial-banking control, do not waive it because a message says the payment is urgent.

What If Money or Credentials Were Already Sent?

1. Contact the financial institution immediately

Use the phone number on the bank card, statement, known website, or banking app. Explain which transaction or account may be affected and follow the institution's incident instructions. Interac directs customers with a current transaction issue to their bank or credit union.

Do not wait to finish an internal investigation before making that contact. Record the time, representative, case number, transaction reference, instructions received, and later updates. Do not promise a customer or supplier that money will be recovered until the institution confirms an outcome.

2. Contain a suspected email compromise

The Canadian Centre for Cyber Security advises organizations to involve IT, change affected passwords, notify relevant contacts, scan devices, consider stronger authentication, contact the corporate email platform, and contact the financial institution immediately when money or financial information may have been transferred.

Review active sessions, forwarding and inbox rules, delegates, recovery addresses, connected applications, and recent sign-in activity according to the email provider's current guidance. Changing only the visible password may leave another access path in place. Preserve evidence before removing rules or sessions where the incident team or authorities ask for it.

3. Preserve one incident file

Keep an incident log that includes:

  • Original emails, texts, attachments, and available headers
  • Known legitimate messages used for comparison
  • Invoice, contract, purchase order, or payroll record involved
  • Intended and substituted recipient details
  • Banking status, amount, date, and transaction reference
  • Who approved, sent, received, or discovered the transaction
  • Calls and case numbers from the bank, email provider, police, insurer, and CAFC
  • Password, session, device, forwarding-rule, and access-control actions
  • Accounting entries, reimbursements, recoveries, or losses recorded later

Use exact observations and timestamps. Keep assumptions such as “mailbox compromised” separate from facts already confirmed by the provider or investigator.

4. Report the incident

The Canadian Anti-Fraud Centre's victim guidance says to gather documents, receipts, and copies of messages; contact the financial institution that transferred the money; contact local police and obtain a file number; and report the fraud or cybercrime online or by phone.

Report a suspicious Interac notification to phishing@interac.ca when it cannot be confirmed, as Interac instructs. Reporting to Interac is not a replacement for contacting the financial institution about an active transaction or reporting an actual fraud to police and the CAFC.

How Should the Books and Customer Records Be Updated?

Keep the operational truth visible while the incident is unresolved:

  • A fake incoming notice does not pay a customer invoice. Leave the balance open unless the bank confirms the deposit.
  • A fraudulent outgoing transfer does not erase the legitimate supplier payable. Preserve the original obligation and record the disputed cash movement separately.
  • A recovered amount is a separate bank event linked to the incident; do not delete the original withdrawal.
  • Fees, insurance proceeds, writeoffs, GST/HST consequences, and deductible-loss treatment need their own source documents and professional review.

Use a review or suspense status until the bank and business records support a final entry. The proof-of-payment checklist explains why a notification, bank entry, invoice, and receipt are different parts of the evidence file.

If the disputed item was a supplier payment, preserve the legitimate invoice and use the business-expense e-Transfer workflow after the recipient and settlement are confirmed.

Which Warning Signs Deserve an Independent Check?

No single sign proves fraud, but these combinations should stop the normal workflow:

  • An unexpected payment notice with no matching bank activity
  • A sender address or domain that differs slightly from the usual one
  • A request to change a supplier, payroll, refund, or deposit destination
  • Pressure to pay immediately, keep the request secret, or skip approval
  • A request for passwords, security answers, one-time codes, or banking credentials
  • An invoice number or amount that does not match the source record
  • A reply that avoids a known phone or in-person verification process
  • New forwarding rules, missing messages, unexpected password resets, or unfamiliar sign-ins

Build the check into the payment process instead of relying on one employee to recognize every possible message design. Interac's guidance for business payments emphasizes staff training, trusted recipients, account reconciliation, and the controls available through the financial institution.

How TransferLog Fits Into a Fraud-Resistant Record Workflow

TransferLog organizes details found in supported Interac e-Transfer notification emails from connected Gmail, Outlook, and iCloud inboxes. Businesses can search, filter, categorize, and export supported transaction notifications, then reconcile the export with invoices and bank activity.

TransferLog is not a fraud detector, email-security product, bank monitor, or incident-response service. It does not verify that a message is genuine, confirm settlement, block a payment, recover money, inspect all mailbox security settings, or report an incident. Preserve suspicious messages in the form requested by the bank, provider, insurer, or authorities even if the message is not recognized by TransferLog.

Official Sources

  • Interac e-Transfer FAQ and phishing guidance
  • Interac: How Interac protects business payments
  • Canadian Centre for Cyber Security: Managing email
  • Canadian Anti-Fraud Centre: What to do if you're a victim of fraud
  • Canadian Anti-Fraud Centre: Report fraud and cybercrime

This article provides general record-keeping and incident-response information, not legal, cyber-security, insurance, or accounting advice.

Organize supported e-Transfer notifications with TransferLog. Start free, then reconcile the notification history with your bank and source records.

Ready to automate your e-Transfer tracking?

Connect your inbox and organize supported e-Transfer notifications in one dashboard.

Try TransferLog free

No credit card required · Free to get started

Keep reading

Small Business

How to Reconcile Autodeposit e-Transfers for a Business

A Canadian workflow for matching Interac e-Transfer Autodeposit receipts to customers, invoices, bank deposits, and bookkeeping records.

8 min read
Tax Tips

How Long Should You Keep e-Transfer Records in Canada?

CRA retention rules and a practical workflow for keeping Interac e-Transfer emails, bank evidence, invoices, receipts, and readable exports.

8 min read

Stop tracking e-Transfers by hand.

Connect your inbox and organize supported e-Transfer notifications in one dashboard.

Try TransferLog free
© 2026 TransferLog. All rights reserved.
PrivacyTermsRSS