Four rules for money movement
Procedural controls that insert the pause fraud cannot survive.
Payment-detail changes confirmed by calling a number the firm already had.
Transfers above a set amount need two approvals; urgency is the tell.
Refunds only after the original payment genuinely clears.
Invoices approved against purchase orders by a named owner.
Source basis: Canadian Anti-Fraud Centre patterns
Payment fraud against small firms rarely looks like hacking. It looks like a supplier emailing new banking details, an urgent e-transfer request from the travelling owner, an overpayment with a refund request, or an invoice for services never ordered. Each works because it arrives during a busy week and imitates a routine the firm already runs.
The Canadian Anti-Fraud Centre catalogues these patterns continuously, and the defences are procedural: cheap, boring, and effective when they are written down.
The four patterns to drill
Supplier impersonation: an email, often from a lookalike or compromised account, changes payment details for a real vendor. Executive impersonation: an urgent transfer request appearing to come from the owner. Overpayment fraud: a cheque or transfer for too much, with a request to refund the difference before the original payment fails. False invoicing: directory listings, domain renewals, or services that were never ordered, priced low enough to slip through.
Every one of these defeats technology and loses to procedure, because the procedure inserts a pause the fraud cannot survive.
The controls that hold under pressure
Rule one: any change to payment details is verified by calling the supplier at a number the firm already had, never one in the email. Rule two: transfers above a set amount need a second person, with no exceptions for urgency, since urgency is the tell. Rule three: refunds are issued only after the original payment has genuinely cleared. Rule four: one person owns invoice approval against purchase orders.
Write the four rules on one page, train everyone who touches money, and rehearse the awkward part: staff must be explicitly authorized to slow down anything claiming to be urgent, including messages appearing to come from the owner.
When something gets through
Speed matters: call the bank immediately, as rapid recall attempts sometimes succeed. Report to the Canadian Anti-Fraud Centre and local police, and preserve the emails and records. Then close the specific gap the incident exposed rather than treating it as bad luck. Baseline cyber controls, MFA on email above all, cut off the account-compromise variants at the root.
Government links used for this briefing
These links point to federal, provincial, territorial, municipal, intergovernmental, or official data sources. Readers should confirm current eligibility and deadlines directly with the issuing government before applying.
Official source for current fraud patterns and reporting channels.
Federal / ComplianceBaseline cyber security controls for small and medium organizationsCanadian Centre for Cyber SecurityThe technical controls that cut off account-compromise fraud variants.
Municipal / ProgramResources for small businessesCity of WinnipegMunicipal small-business resources for Winnipeg operators.


