When people picture a cyberattack, they picture a hacker in a hoodie locking up their computers and demanding a ransom. That happens, but it is not what is actually draining money from most businesses. The bigger, quieter threat is a convincing email. According to the Coalition 2026 Cyber Claims Report, business email compromise and funds transfer fraud made up 58 percent of cyber incidents. Most losses do not come from someone breaking in, they come from someone tricking you into sending money.
Let me make it concrete with a scene I could see happening to any general contractor in Alberta. You are mid-project. You have been emailing back and forth with a supplier or a subtrade you have paid a dozen times. One day an email comes in on that same thread, same name, same signature, saying their banking details have changed and to send the next payment to a new account. It looks completely normal. Your bookkeeper pays it. Except that email was not from your supplier. A criminal had been watching the thread and slipped in at the right moment. The money is gone, the real supplier still wants to be paid, and now you are out both.
This works because it does not feel like an attack. There is no alarm, no locked screen, just a routine-looking request during a busy week. Trades and contractors are a favorite target because you move real money between a lot of parties, deposits, progress draws, and supplier payments, and a change in banking details does not raise an eyebrow. And the losses are not small. Canadians reported a record 704 million dollars in fraud losses in 2025 to the Canadian Anti-Fraud Centre, and one 2026 Canadian report found that for small and medium businesses, business email compromise is the single most costly type of incident there is.
The good news is that the fixes are cheap and mostly about habits. A few that stop the majority of these cold:
• Verify by voice. Any time banking details change, call the vendor on a number you already have, not the number in the email, and confirm before you pay.
• Require dual approval. Make it a rule that any new or changed payment needs a second person to sign off.
• Slow down urgency. Fake requests almost always push you to hurry. Treat urgency plus a payment change as a reason to double check, not a reason to rush.
• Lock down email. Turn on multifactor authentication so a stolen password alone cannot get someone into your inbox.
This is also where insurance comes in, and where a lot of owners have a false sense of security. A standard cyber policy does not automatically cover social engineering fraud, which is the category this falls under. Coverage for tricked payments, sometimes called social engineering or funds transfer fraud coverage, is often a separate add-on with its own limit and conditional on you having verification steps in place. The time to find out whether you have it is now, not after a payment goes to the wrong account. This is also where the market you are placed with matters. At Velocity, one of the cyber markets I work with is Coalition, and I rate them among the strongest options available for this kind of protection.
If you are not sure whether your policy would respond to a fake-email payment, or you do not have cyber coverage at all, let's talk it through. It is one of the cheapest, most overlooked protections a small business can put in place, and the scenario above is a lot more common than most people think.
Mandy Stierman, Founder and Principal Broker
