
Powered By CairiTech
Quick answer
Business email compromise (BEC) — where a scammer poses as a vendor or executive to push through a fake invoice or a "new" set of banking details — climbs every summer for one simple reason: fewer people are at their desks to double-check the request. Security vendor LevelBlue recorded its highest monthly BEC volume of 2025 in July, right as vacation season peaks. The average fraudulent wire request now runs about US $24,586, and paying one means paying twice — once to the criminal, once to the real supplier.
The fix isn't a bigger firewall; it's a simple out-of-band verification habit (confirm any new or changed payment detail by calling a number you already trust) plus multi-factor authentication on every email account. CairiTech, an Aurora, Ontario managed IT and cybersecurity provider, helps Greater Toronto Area businesses — including busy Architecture, Engineering, and Construction (AEC) firms running summer projects — put those guardrails in place.
3 min read posted on 08/02/26
Business email compromise is a scam where a criminal impersonates someone you trust — a supplier, a partner, or your own CFO — to trick a staff member into sending money or changing payment details. Unlike spray-and-pray phishing, BEC is targeted: the attacker studies a real relationship, then slips a fraudulent request into it.
It spikes in summer because of staffing, not technology. When the people who normally approve payments are on vacation, verification gets delegated to whoever's available — often someone less familiar with the vendors involved. LevelBlue's 2025 telemetry shows BEC volume peaking in July, and its analysts tie the surge directly to the start of the vacation season, when fewer staff are around to process verification. Criminals know the calendar as well as you do.
The attacker either spoofs a familiar email address or compromises a real one, then inserts a believable money request into an existing thread. The most common version right now is vendor email compromise: a message claiming a supplier has "updated" its banking information, often with a fake "overdue invoice" attached. Sometimes the fraudster even calls your accounting team first to announce the change and build credibility. According to research from Hoxhunt, vendor email compromise attacks rose roughly 66% in the first half of 2024.
These aren't far-fetched schemes. In one widely reported case, Google and Facebook collectively lost over US $100 million to a scammer who simply sent invoices impersonating a real hardware supplier — the payments looked routine, so no one questioned them.
Summer is peak season for Architecture, Engineering, and Construction firms — and that's exactly the problem. Progress draws, subcontractor invoices, and large material orders are all moving at once, project managers are out in the field instead of at a desk, and sign-off authority gets handed around. High payment volume, delegated approval, and out-of-office decision-makers are the precise conditions BEC is built to exploit. A single fraudulent change to a subcontractor's "remittance details" can redirect a five- or six-figure draw before anyone notices.
Most BEC attempts share the same handful of tells. Keep this quick reference near the approvals inbox:
Signal
Normal vendor request
Likely BEC / invoice fraud
Signal: Banking details
Normal vendor request: Unchanged, match prior invoices
Likely BEC / invoice fraud: "Updated" or "new" account, often a different bank
Signal: Urgency
Normal vendor request: Standard payment terms
Likely BEC / invoice fraud: Pressure to pay today / before a deadline
Signal: Channel
Normal vendor request: Expected email thread
Likely BEC / invoice fraud: New thread, reply-to a look-alike domain
Signal: Verification
Normal vendor request: Easy to confirm with your contact
Likely BEC / invoice fraud: Resists phone verification, or supplies a new number
Signal: Timing
Normal vendor request: Business hours, expected cadence
Likely BEC / invoice fraud: After-hours, or while approvers are away
Banking details
Unchanged, match prior invoices
"Updated" or "new" account, often a different bank
Urgency
Standard payment terms
Pressure to pay today / before a deadline
Channel
Expected email thread
New thread, reply-to a look-alike domain
Verification
Easy to confirm with your contact
Resists phone verification, or supplies a new number
Timing
Business hours, expected cadence
After-hours, or while approvers are away
The single most effective control costs nothing: out-of-band verification. Before paying any new or changed banking detail, confirm it by phone using a number you already have on file — never the number in the suspicious email. The FBI's Internet Crime Complaint Center (IC3) names this as a primary defence, alongside two-factor authentication on financial-change requests.
Layer these on top:
Multi-factor authentication (MFA) on every email account. Microsoft estimates MFA blocks 99% of automated account-takeover attempts — and account takeover is how the most convincing BEC messages get sent.
Email authentication (SPF, DKIM, DMARC) so spoofed look-alike domains get rejected before they reach an inbox.
Dual approval for any payment or banking change above a set dollar threshold.
Brief, targeted training — especially for new hires, who attackers single out because they don't yet know who's who.
Dark web monitoring so you find out when a staff credential has leaked, before it's used.
Handled together, these turn a "looks fine, pay it" moment into a two-minute check that saves a five-figure mistake.
That's where CairiTech comes in. We help Greater Toronto Area businesses lock down email, set up the verification habits that actually stop invoice fraud, and monitor for the leaked credentials that make BEC possible — so a quiet August doesn't become an expensive one. Book your free discovery call with CairiTech today
And if you know another business owner heading into a short-staffed summer, send this their way — they're a target too.

What You Should Expect To Pay For I.T. Support For Your Business (And How To Get Exactly What You Need Without Unnecessary Extras, Hidden Fees And Bloated Contracts)
It's a scam where a criminal pretends to be a trusted vendor, partner, or executive — usually over email — to trick someone into sending a payment or changing banking details. It works by abusing a relationship you already have, which is why it slips past staff who are simply trying to keep things moving.
Because verification breaks down when people are away. With approvers on vacation and sign-off delegated to whoever's available, fraudulent "updated invoice" and "new banking details" requests are more likely to be paid without a second look. Security vendor LevelBlue recorded its highest BEC volume of 2025 in July, at the start of vacation season.
Usually yes — you can end up paying twice, once to the criminal and once to the legitimate supplier whose invoice still needs to be settled. Whether insurance helps often hinges on whether you took "reasonable care," such as verifying payment changes through a separate, trusted channel.
The strongest tells are changed banking details, unusual urgency, a slightly altered email domain, and resistance to phone verification. Any new or changed payment instruction should be confirmed by calling a number you already have for that vendor — never the number provided in the email.
Sometimes, but coverage varies and may sit under a separate "social engineering fraud" provision rather than a standard policy. Insurers commonly expect documented controls like MFA and out-of-band verification, and recovery rates on stolen funds are low — which is why prevention matters far more than relying on a claim.
Written by the CairiTech team — Greater Toronto Area managed IT and cybersecurity specialists, serving Ontario businesses (including AEC firms) since 1990. Head office: 1-2 Vata Court, Aurora, ON. Phone: +1 (416) 361-1441.

March 29, 2026
Cyber resilience is no longer optional for Ontario manufacturers and builders. Learn how downtime, cyber risk, and outdated IT can quietly threaten your operations—and what smart business leaders are doing in 2026 to stay secure, compliant, and competitive. [Read more]

January 17, 2025
If you think hackers are only targeting Fortune 500 companies, think again. Thanks to artificial intelligence, cybercriminals now have the power to scale their attacks like never before - and small business owners are at the top of their hit list. Here’s how hackers are weaponizing AI... [Read more]

Canada
1-2 Vata Court, Aurora, ON
United States
39288 Calle Tonala, Indio, CA
Copyright 2026. Cairitech. All rights reserved.