Laurentian Bank: Laurentian Bank of Canada.

Business and corporate fraud.
Business and corporate fraud.
Fraudsters target business systems, suppliers or employees.
Inadequate accounting processes.
Without regular controls on outgoing payments, (including transfers, wires and cheques) errors, misappropriations, or unauthorized payments can go unnoticed. Regular audits help quickly detect anomalies and ensure every dollar relates to a legitimate, approved expense.
What to watch out for:
Excessive or uncontrolled access to payment systems
Unusual or unjustified payments
Duplicate invoices or invoices that appear suspicious because they’ve been altered or are inaccurate
How to protect yourself:
Split up roles and responsibilities
A single person shouldn’t prepare, approve and execute a payment
Divide up tasks to reduce the risk of internal fraud
Control access to financial systems
Immediately deactivate access for departing employees
Grant access to accounting systems only to employees who need it
Implement alerts and approval thresholds
Require additional approval for large amounts
Conduct regular audits
Review outgoing payments monthly or quarterly, for example
Ransomware.
Ransomware is malicious software that blocks access to company files, data and systems by encrypting them. Cybercriminals then demand a ransom to unlock them. Selecting an infected link or opening a suspicious attachment can be enough to paralyze operations, interrupt services, and cause major financial and reputational damage.
What to watch out for:
Unexpected attachments or emails from unknown senders
Links directing to suspicious websites
Messages creating a sense of urgency. For example, “Immediate action required”
How to protect yourself:
Train employees to recognize suspicious emails
Keep IT systems up to date and use antivirus protection
Regularly back up data
Limit employee access privileges and immediately deactivate access for departing employees
Warning: Paying the ransom does not guarantee data recovery, nor does it ensure the data hasn’t already been leaked or sold, including on the dark web.
Phishing and smishing.
Phishing, sent by email, and smishing, sent by text message, are fraud techniques designed to trick someone into selecting a link, opening an attachment, or sharing sensitive information. These attacks often impersonate a colleague, supplier (refer to supplier fraud), or well-known organization and can lead to financial losses, malware installation, and system or data compromise.
What to watch out for.
Phishing and smishing messages will often:
create a sense of urgency
ask you to select a link
request sensitive personal or financial information
How to protect yourself:
Train employees to recognize suspicious emails and text messages
Verify the sender first by contacting them through a known, legitimate source, for example from the official website
Never select a suspicious link
Supplier fraud.
What’s supplier fraud? Supplier fraud occurs when attackers impersonate a legitimate vendor to divert payments or gain access to systems.
Common supplier fraud scenarios include:
Vendor emails claiming new bank account details.
Fraudulent invoices for goods and services never delivered.
Attackers infiltrating a real vendor’s email to send legitimate‑looking requests.
Supplier fraud is especially dangerous because it exploits trusted relationships and often bypasses normal suspicion.
How to spot supplier fraud.
Red flags to look out for:
Vendor suddenly changes payment instructions.
Requests for early or duplicate payments.
Inconsistencies with usual behavior.
Our tip: Always take a step back and verify who’s actually contacting you. Verify with a colleague through a trusted channel, not the contact information provided in the suspicious communication. This helps ensure you’re not responding to supplier fraud.
How do you avoid becoming a victim of scams or fraud in the workplace? Strengthen your internal defences:
Train employees on BEC and supplier fraud red flags.
Use strict verification protocols for requests involving money or sensitive data.
Confirm vendor banking changes via a known phone number, not the information provided in the suspicious email.
What to do if you think you’ve been scammed:
Stop engaging with the scammer.
Contact your immediate superior to advise of the situation.
If your banking information was provided, contact your bank immediately.
Change passwords for any affected accounts where sensitive information was given.
Report the scam to your local police and the Canadian Anti-Fraud Centre.
Weak procurement processes.
Risks associated with awarding contracts can take several forms: made-up suppliers, abnormally high prices, favouritism based on personal relationships, or a lack of competitive bidding. Without strong ways to verify suppliers, a company may award a contract to an inadequate or illegitimate supplier, opening the door to financial losses, lower-quality services and internal misconduct.
What to watch out for:
Suppliers whose contact information is inconsistent, such as addresses, emails or phone numbers
New suppliers whose reputation appears manipulated or fake. For example, they have inconsistent public reviews
Prices that are abnormally high compared to the market
Invoices that don’t match the goods and services provided
An employee who regularly recommends the same supplier or doesn’t disclose personal or family ties with a supplier
Internal pressure to bypass standard procedures
How to protect yourself:
Split up roles and responsibilities
A single person shouldn’t choose a supplier, approve an invoice and make a payment
Divide up tasks to reduce the risk of internal fraud
Verify that the supplier exists
Confirm address, business number, references and online presence
Check that the company has real, verifiable business activity
Request multiple bids
Compare prices, timelines and conditions
Document the reasons for the final selection
Implement a clear procedure for conflicts of interest
Require employees to disclose any personal or financial ties to a supplier
Perform regular audits
Standardize the contract award process
Email account takeover.
Taking control of an email account is one of the most used entry points for criminals. Your email address often acts as the key that unlocks access to many of your other accounts, banking services and more. That’s why protecting your email is one of the most effective ways to safeguard your business.
Why it’s important to use a dedicated professional email domain.
Using a personal email address or one provided by an internet provider makes you more vulnerable. A professional email domain offers better protection against unauthorized access, stronger security settings, and more control over your accounts.
To strengthen email security even further, always enable 2-step verification (2SV) or multi-factor authentication (MFA). With 2SV, logging in requires an additional step, typically a one-time code sent to your phone. Even if someone gets your password, they can’t access your email without this code.
Signs your email may be compromised:
Emails marked as read when you didn’t open them
Missing emails
Clients or partners receiving emails you didn’t send
Password reset emails you didn’t request
Login alerts or unknown devices associated with your account
What to do if you think you’ve been compromised:
Change your password immediately
Enable MFA
Inform clients and partners, including financial institutions
Contact your email service provider
We recommend that you:
Choose strong passwords and change them regularly
Implement mandatory periodic password changes for all employees. For example, every 3 months
Enable MFA
Never share your one-time codes with anyone
Business Email Compromise (BEC).
What’s Business Email Compromise (BEC)? It’s a targeted attack where criminals impersonate executives, employees or partners to trick an organization into sending money or sensitive information.
Common BEC scenarios involve a fraudster who impersonates an employee or executive to:
request a money transfer urgently and discretely; or
request sensitive information.
BEC takes advantage of an employee’s desire to be helpful and play a role in important decisions.
How to spot BEC. Red flags to look out for:
Unusual urgency from someone claiming to be an executive.
Requests to bypass standard procedures, such as payments, credentials, or approvals.
Request to keep the situation discrete or a secret.
Our tip: Always take a step back and verify who’s actually contacting you. Verify with a colleague through a trusted channel, not the contact information provided in the suspicious communication. This helps ensure you’re not responding to a BEC.
How do you avoid becoming a victim of scams or fraud in the workplace? Strengthen your internal defences:
Train employees on BEC and supplier fraud red flags.
Use strict verification protocols for requests involving money or sensitive data.
What to do if you think you’ve been scammed:
Stop engaging with the scammer.
Contact your immediate superior to advise of the situation.
If your banking information was provided, contact your bank immediately.
Change passwords for any affected accounts where sensitive information was given.
Report the scam to your local police and the Canadian Anti-Fraud Centre.