TransferLog
/Blog
Log inGet started free
  1. Home
  2. Blog
  3. Is This Interac e-Transfer Email Real? Fraud Checklist
Small Business

Is This Interac e-Transfer Email Real? Fraud Checklist

Verify a suspicious Interac e-Transfer email in online banking, recognize fake deposits and payment requests, and respond safely after a click or transfer.

TransferLog Team
Updated September 13, 2026
9 min read

Do not trust an Interac e-Transfer email because it has the right logo, wording, sender name, or an “Interac Verified” label. Open your bank or credit union through its known app or a bookmark—not the message—and look for the transaction. Then confirm an unexpected sender or payment request through a separate contact method you already trust.

If there is no matching transaction in banking, treat the payment as unconfirmed. Do not release goods, mark an invoice paid, send a refund, answer a security question, or enter banking credentials from the email.

How Can You Check Whether an Interac e-Transfer Email Is Real?

Use the bank record as the payment check and the sender as a separate identity check. One clue in an email is never enough.

Checks for a suspicious Interac e-Transfer email
CheckWhat it can tell youWhat it cannot prove
Known banking app or bookmarked websiteWhether a matching deposit, incoming transfer, or Request Money item appearsWhy the payment was sent or whether a separate instruction is legitimate
Sender reached through an established channelWhether the person or business intended the transactionWhether the transfer completed in your account
Email address and message detailsWhether misspellings, odd domains, or unexpected instructions are presentThat the message is genuine; sender details and branding can be imitated
Interac reference or notification detailsA way to compare records when the same reference appears in bankingThat funds settled, who controls an email account, or what the payment is for

Interac says a legitimate email notification will contain the sender’s full legal name and use notify@payments.interac.ca in the email field. Those are useful checks, but a business should still verify the transaction in known online or mobile banking. The Canadian Centre for Cyber Security warns that display names, addresses, links, and familiar email threads can be spoofed or compromised.

Build a searchable e-Transfer record

Connect Gmail, Outlook, or iCloud. TransferLog organizes supported Interac notification details so you can search, filter, and export when you reconcile.

Start organizing freeSee how it works

Does a Suspicious “Interac Verified” Message Mean Interac Was Hacked?

Not by itself. Words such as “verified,” familiar logos, a realistic footer, or a convincing email thread do not establish that Interac’s service was compromised. The message could be an imitation, a spoofed sender, a compromised customer or vendor inbox, a legitimate but unexpected transaction, or a different Interac service being referenced.

Check three separate systems:

  1. Banking: Is there a matching transaction, and what is its actual status?
  2. Business records: Is there a real customer, invoice, refund, payroll item, or supplier payment for that amount?
  3. The other party: Can the known person confirm the transaction through a channel that did not come from the suspicious message?

For a current transaction or account concern, contact the bank or credit union.

What Should You Do Before Clicking, Depositing, Paying, or Shipping?

1. Stop and preserve the message

Do not click a link, scan a QR code, open an attachment, reply, or call a number supplied in the message. Preserve the original email or text, including headers when your mail system allows it. Record when it arrived, the displayed sender, address, subject, amount, reference, links, and any request or deadline.

2. Open banking independently

Use the financial institution’s app, a saved bookmark, or an address you type yourself. Do not use a search ad or link from the notification. Look for the exact amount, direction, date, recipient or sender, and status.

An email saying money was sent is not proof that a deposit completed. If Autodeposit is enabled, verify the actual credit in the intended account. If a manual deposit is expected, first confirm the transaction exists before following any instructions.

3. Identify which event is being claimed

A fake deposit, a Request Money notice, a cancellation message, and a changed supplier-payment instruction require different actions. Read the banking record carefully: a request for you to send money is not an incoming payment, and a pending item is not a completed deposit.

Use the e-Transfer status guide to keep unsuccessful attempts and replacements separate.

4. Match the business purpose

Find the invoice, order, payroll item, refund authorization, or supplier bill that should explain the amount. Confirm that the party, amount, and direction match. A real bank transaction can still be a mistake or part of an overpayment scam.

5. Verify the person separately

Call a saved number, use a previously established portal, or start a new message to a known address. Do not rely on contact details, a reply thread, or a “new banking information” notice contained only in the suspicious email.

The RCMP recommends a two-step verification process for payment requests and an independent check when supplier or employee payment details change.

6. Approve or isolate the event

Only fulfil the order, close the invoice, change payment details, or send money after the banking and identity checks agree. If they do not, keep the item in an exception queue. Do not delete it or quietly force it into the customer ledger.

Which e-Transfer Fraud Scenarios Need Different Checks?

Safe responses to common e-Transfer fraud scenarios
ScenarioSafe response
“Payment received” email but no bank depositDo not ship or mark paid; preserve and report the message
Unexpected Request Money noticeDo not fulfil it; confirm the requestor through a trusted channel
Customer appears to overpay and asks for money backVerify the settled deposit and customer; do not refund from the email alone
Supplier or employee changes payment details by emailPause the change and use known contact details and the approval process
Familiar email thread contains a new urgent instructionTreat it as possible thread hijacking and verify outside email
Autodeposit notification appears unexpectedlyCheck banking and identify the sender before allocating or returning funds
Message asks for a password, one-time code, or security answerDo not provide it; Interac will not ask for a banking password by email or text

For an unknown deposit that really reached the account, use the unknown sender workflow. Do not send money to a new address simply because someone claims the deposit was accidental.

What If You Already Clicked or Entered Information?

Close the page. If you entered banking credentials, a security answer, or a one-time code, contact the financial institution through a trusted number immediately. Change affected credentials from a trusted device, review account activity, and involve the business’s IT or security contact.

Preserve the message, URL, time, information entered, device, and alerts. The Cyber Centre advises organizations responding to suspected email compromise to change affected passwords, check devices, notify relevant contacts, and contact the financial institution when money or financial information may have been transferred.

What If Money or Goods Were Already Sent?

Contact the financial institution immediately with the amount, destination, time, reference, and fraudulent instruction. Ask what recovery steps are available, but do not promise that funds can be recovered.

Also:

  • notify the business’s security, finance, and insurer contacts as applicable;
  • preserve emails, texts, invoices, transfer records, approvals, access alerts, and communications;
  • report the incident to local police and keep the file number;
  • report fraud or attempted fraud to the Canadian Anti-Fraud Centre; and
  • forward a suspicious Interac notification to phishing@interac.ca.

If a customer or supplier inbox may be compromised, warn the real contact through a trusted channel and stop using that thread for payment details.

How Should the Incident Appear in Business Records?

Keep the accounting conclusion separate from the security event.

  • A fake notification with no deposit is not revenue and does not settle an invoice.
  • An unconfirmed transfer stays open; an unexplained bank deposit remains an exception until its owner and purpose are verified.
  • A fraudulent outgoing payment should retain its payee, date, amount, reference, approval trail, and recovery activity. Ask the accountant how to classify any loss or recovery.
  • A replacement payment needs a new record linked to the rejected or fraudulent attempt.

Do not erase the original row, replace the payee, or backdate the correction. Preserve what was believed, verified, approved, and reconciled.

How Can a Business Reduce the Next e-Transfer Email Risk?

Require independent verification for new recipients, changed payment details, unusual refunds, and urgent requests. Use dual approval above an internal threshold, limit payee changes, enable multi-factor authentication, review mailbox forwarding rules, and reconcile banking regularly.

Autodeposit reduces the need to click deposit links, but it does not explain an unexpected payment. Keep matching deposits to customers, invoices, and banking.

How TransferLog Fits Into a Fraud-Resistant Record Workflow

TransferLog organizes supported incoming and outgoing Interac e-Transfer notification emails from connected Gmail, Outlook, and iCloud inboxes. You can search, filter, categorize, and export CSV or PDF on the Pro plan.

TransferLog does not authenticate email, detect fraud, access banking, block or recover payments, or replace professional advice. Verify suspicious events independently.

For payment evidence, see what an e-Transfer confirmation can prove. For possible duplicate refunds, use the customer refund workflow.

Official Sources

  • Interac: Protecting your payments
  • Interac: How to receive money with e-Transfer
  • Interac e-Transfer FAQ and phishing reporting
  • Canadian Anti-Fraud Centre: What to do if you are a victim of fraud
  • Canadian Centre for Cyber Security: Managing email securely
  • RCMP: Business email compromise

Organize supported e-Transfer notifications with TransferLog. Start free, then verify suspicious events against the bank and your business records.

Make your next e-Transfer reconciliation easier

Connect Gmail, Outlook, or iCloud and turn supported Interac notification details into one searchable, filterable list.

Start organizing freeSee how it works

Free plan available · No credit card required

Keep reading

Small Business

How to Reconcile Autodeposit e-Transfers for a Business

A Canadian workflow for matching Interac e-Transfer Autodeposit receipts to customers, invoices, bank deposits, and bookkeeping records.

8 min read
Bookkeeping

How to Reimburse Employee Expenses by e-Transfer in Canada

Approve the claim, separate reimbursements from allowances, handle GST/HST support, and match the completed e-Transfer to receipts and the bank.

8 min read

Stop tracking e-Transfers by hand.

Connect your inbox and organize supported e-Transfer notifications in one dashboard.

Try TransferLog free
© 2026 TransferLog. All rights reserved.
PrivacyTermsRSS