Avoiding fraud in today's digital world
From William McCloundy—known as I.O.U. O’Brien—who “sold” the Brooklyn Bridge to a tourist in 1901, to Charles Ponzi and today’s elusive cybercriminals, fraudsters have always looked for ways to exploit trust.
As more of daily life moves online, fraudsters increasingly use the digital tools we rely on to gather information, communicate and make payments. It’s easy to think fraud could never happen to you, but anyone can be targeted—including people you know and trust.
The good news is that knowing the warning signs, pausing before you act and verifying unexpected requests can make fraud much easier to spot and avoid.
Know the common types of fraud
Spoofing: Fraudsters disguise a website, email address, phone number or other identifier so it appears to come from a legitimate organization or person. Their goal is often to steal passwords, credit card numbers, banking details or other sensitive information.
Phishing: A fraudulent email or other electronic message that appears legitimate and pressures you to share information, open an attachment, scan a QR code or follow a link.
Smishing: Phishing conducted through SMS or other text messages.
Vishing: Voice phishing conducted by phone. A caller may impersonate a trusted organization or use a prize, refund, threat or urgent problem to pressure you into sharing information or sending money.
Search engine phishing: Fraudsters create convincing websites or paid ads that appear in search results. The pages may promote unusually low prices or imitate a trusted organization to capture your information or payment.
Angler phishing: Fraud carried out through social media. Criminals may use fake profiles, posts, direct messages, URLs or customer-support accounts to persuade you to share sensitive information, send money or download malware.
Online advertising fraud has been relatively easy and lucrative for fraudsters, difficult for online ad platforms to control, and a financial burden for victims and legitimate advertisers. It’s important to use the internet safely and be skeptical.
No matter the decade, if it seems too good to be true, then it probably is.
Tips to spot fraud and protect yourself
1. Don't reply to emails asking for personal information to stop the sudden closure on an account. Do not click on the links within the email. Instead, open a new browser window and type in a web addresss you can confirm to reach the company in the email, or call the company instead.2. Be skeptical. Legitimate businesses don't send unsolicited requests for personal, sensitive, or financial information through email, texts, or phone.
3. Don't open attachments, follow links, or reply to spam messages — even to unsubscribe.
4. Check the full website address before entering personal or financial information. “https” means the connection is encrypted, but it does not prove that the site itself is legitimate. Confirm the spelling and domain, and when in doubt, navigate to the organization’s website yourself.
5. Verify links before clicking on them by hovering your mouse over the link and carefully checking that it's the website that you expect. The difference may be as simple as a .net address versus a .com address, or a slight difference in spelling, so pay close attention.
6. Watch for warning signs such as unusual spelling or formatting, unexpected requests, urgent deadlines, threats, secrecy, or offers that seem too good to be true. Keep in mind that polished writing alone does not prove a message is legitimate
7. Google Ads show the destination website address near the ad headline. Confirm this link is what you expect before clicking, and if unsure, don't click the link.
8. When possible, go to the source directly, and type in the company website yourself to verify and use the information from the website.
9. Let unknown calls go to voicemail when possible. If you answer, don’t let urgency, threats or emotional pressure rush you. Hang up and contact the organization using a trusted number from its official website, your statement, or the back of your card.
10. Keep your devices, apps, browsers, and security software up to date. Turn on automatic updates when available, and back up important files regularly.
11. Turn on multi-factor authentication. Enable it wherever possible—especially for email, banking, and social media. It adds another barrier if a fraudster obtains your password.
12. Pause before sending money. Be cautious when someone demands immediate payment or asks for gift cards, cryptocurrency, wire transfers, or other hard-to-reverse methods. Verify the request through a separate, trusted channel.
13. Treat QR codes like links. Before scanning, confirm who provided the code and where it should lead. If the source is unclear or the request is unexpected, don’t proceed.
14. Review your accounts regularly. Turn on transaction alerts when available and report unfamiliar activity to your financial institution right away.
15. If you think you’ve been targeted: Stop communicating with the sender, save relevant messages or receipts, contact SCU if money or account information may be at risk, change affected credentials, and report the incident to local police and the Canadian Anti-Fraud Centre.
Visit our fraud prevention centre to learn how to protect yourself: