Cairitech IT Support and Services Logo

Leader in IT Support & Cybersecurity Across Ontario

Cairitech IT Support and Services Logo
CairiTech blog cover image

Half Your Team's on Vacation — That's When the Fake Invoice Arrives

Powered By CairiTech

Quick answer

Business email compromise (BEC) — where a scammer poses as a vendor or executive to push through a fake invoice or a "new" set of banking details — climbs every summer for one simple reason: fewer people are at their desks to double-check the request. Security vendor LevelBlue recorded its highest monthly BEC volume of 2025 in July, right as vacation season peaks. The average fraudulent wire request now runs about US $24,586, and paying one means paying twice — once to the criminal, once to the real supplier.

The fix isn't a bigger firewall; it's a simple out-of-band verification habit (confirm any new or changed payment detail by calling a number you already trust) plus multi-factor authentication on every email account. CairiTech, an Aurora, Ontario managed IT and cybersecurity provider, helps Greater Toronto Area businesses — including busy Architecture, Engineering, and Construction (AEC) firms running summer projects — put those guardrails in place.

3 min read posted on 08/02/26

What is business email compromise, and why does it spike in summer?

Business email compromise is a scam where a criminal impersonates someone you trust — a supplier, a partner, or your own CFO — to trick a staff member into sending money or changing payment details. Unlike spray-and-pray phishing, BEC is targeted: the attacker studies a real relationship, then slips a fraudulent request into it.

It spikes in summer because of staffing, not technology. When the people who normally approve payments are on vacation, verification gets delegated to whoever's available — often someone less familiar with the vendors involved. LevelBlue's 2025 telemetry shows BEC volume peaking in July, and its analysts tie the surge directly to the start of the vacation season, when fewer staff are around to process verification. Criminals know the calendar as well as you do.

How does the scam actually work?

The attacker either spoofs a familiar email address or compromises a real one, then inserts a believable money request into an existing thread. The most common version right now is vendor email compromise: a message claiming a supplier has "updated" its banking information, often with a fake "overdue invoice" attached. Sometimes the fraudster even calls your accounting team first to announce the change and build credibility. According to research from Hoxhunt, vendor email compromise attacks rose roughly 66% in the first half of 2024.

These aren't far-fetched schemes. In one widely reported case, Google and Facebook collectively lost over US $100 million to a scammer who simply sent invoices impersonating a real hardware supplier — the payments looked routine, so no one questioned them.

Why AEC and construction firms are especially exposed in summer

Summer is peak season for Architecture, Engineering, and Construction firms — and that's exactly the problem. Progress draws, subcontractor invoices, and large material orders are all moving at once, project managers are out in the field instead of at a desk, and sign-off authority gets handed around. High payment volume, delegated approval, and out-of-office decision-makers are the precise conditions BEC is built to exploit. A single fraudulent change to a subcontractor's "remittance details" can redirect a five- or six-figure draw before anyone notices.

How do you tell a legitimate payment request from a fraudulent one?

Most BEC attempts share the same handful of tells. Keep this quick reference near the approvals inbox:

Signal

Normal vendor request

Likely BEC / invoice fraud

Signal: Banking details

Normal vendor request: Unchanged, match prior invoices

Likely BEC / invoice fraud: "Updated" or "new" account, often a different bank

Signal: Urgency

Normal vendor request: Standard payment terms

Likely BEC / invoice fraud: Pressure to pay today / before a deadline

Signal: Channel

Normal vendor request: Expected email thread

Likely BEC / invoice fraud: New thread, reply-to a look-alike domain

Signal: Verification

Normal vendor request: Easy to confirm with your contact

Likely BEC / invoice fraud: Resists phone verification, or supplies a new number

Signal: Timing

Normal vendor request: Business hours, expected cadence

Likely BEC / invoice fraud: After-hours, or while approvers are away

Banking details

Unchanged, match prior invoices

"Updated" or "new" account, often a different bank

Urgency

Standard payment terms

Pressure to pay today / before a deadline

Channel

Expected email thread

New thread, reply-to a look-alike domain

Verification

Easy to confirm with your contact

Resists phone verification, or supplies a new number

Timing

Business hours, expected cadence

After-hours, or while approvers are away

What stops it?

The single most effective control costs nothing: out-of-band verification. Before paying any new or changed banking detail, confirm it by phone using a number you already have on file — never the number in the suspicious email. The FBI's Internet Crime Complaint Center (IC3) names this as a primary defence, alongside two-factor authentication on financial-change requests.

Layer these on top:

  • Multi-factor authentication (MFA) on every email account. Microsoft estimates MFA blocks 99% of automated account-takeover attempts — and account takeover is how the most convincing BEC messages get sent.

  • Email authentication (SPF, DKIM, DMARC) so spoofed look-alike domains get rejected before they reach an inbox.

  • Dual approval for any payment or banking change above a set dollar threshold.

  • Brief, targeted training — especially for new hires, who attackers single out because they don't yet know who's who.

  • Dark web monitoring so you find out when a staff credential has leaked, before it's used.

Handled together, these turn a "looks fine, pay it" moment into a two-minute check that saves a five-figure mistake.

That's where CairiTech comes in. We help Greater Toronto Area businesses lock down email, set up the verification habits that actually stop invoice fraud, and monitor for the leaked credentials that make BEC possible — so a quiet August doesn't become an expensive one. Book your free discovery call with CairiTech today

And if you know another business owner heading into a short-staffed summer, send this their way — they're a target too.

FREE REPORT: IT Buyers Guide

What You Should Expect To Pay For I.T. Support For Your Business (And How To Get Exactly What You Need Without Unnecessary Extras, Hidden Fees And Bloated Contracts)

Frequently asked questions

What is business email compromise in simple terms?

It's a scam where a criminal pretends to be a trusted vendor, partner, or executive — usually over email — to trick someone into sending a payment or changing banking details. It works by abusing a relationship you already have, which is why it slips past staff who are simply trying to keep things moving.

Why do invoice scams increase in the summer?

Because verification breaks down when people are away. With approvers on vacation and sign-off delegated to whoever's available, fraudulent "updated invoice" and "new banking details" requests are more likely to be paid without a second look. Security vendor LevelBlue recorded its highest BEC volume of 2025 in July, at the start of vacation season.

If my business pays a fraudulent invoice, are we liable for the real one too?

Usually yes — you can end up paying twice, once to the criminal and once to the legitimate supplier whose invoice still needs to be settled. Whether insurance helps often hinges on whether you took "reasonable care," such as verifying payment changes through a separate, trusted channel.

How can I tell a fake invoice from a real one?

The strongest tells are changed banking details, unusual urgency, a slightly altered email domain, and resistance to phone verification. Any new or changed payment instruction should be confirmed by calling a number you already have for that vendor — never the number provided in the email.

Does cyber insurance cover BEC losses?

Sometimes, but coverage varies and may sit under a separate "social engineering fraud" provision rather than a standard policy. Insurers commonly expect documented controls like MFA and out-of-band verification, and recovery rates on stolen funds are low — which is why prevention matters far more than relying on a claim.

Written by the CairiTech team — Greater Toronto Area managed IT and cybersecurity specialists, serving Ontario businesses (including AEC firms) since 1990. Head office: 1-2 Vata Court, Aurora, ON. Phone: +1 (416) 361-1441.

Popular Reads You Don’t Want to Miss

Blog Cover Image: Cyber Resilience Is Now a Business Requirement for Ontario Manufacturers & Builders

March 29, 2026

Cyber resilience is no longer optional for Ontario manufacturers and builders. Learn how downtime, cyber risk, and outdated IT can quietly threaten your operations—and what smart business leaders are doing in 2026 to stay secure, compliant, and competitive. [Read more]

Blog Cover Image: Inside Look: How Hackers Use AI To Attack Your Business

January 17, 2025

If you think hackers are only targeting Fortune 500 companies, think again. Thanks to artificial intelligence, cybercriminals now have the power to scale their attacks like never before - and small business owners are at the top of their hit list. Here’s how hackers are weaponizing AI... [Read more]

LOCATIONS

Canada

1-2 Vata Court, Aurora, ON

United States

39288 Calle Tonala, Indio, CA

Copyright 2026. Cairitech. All rights reserved.