← Back to CyberSpace

Every day, thousands of Canadians receive emails designed to trick them into handing over passwords, banking details, or personal information. These are called phishing emails — and they're the number one way people get hacked.

The good news? Once you know what to look for, they're not that hard to spot.

What Is Phishing?

Phishing is when a cybercriminal sends you an email pretending to be someone you trust — your bank, the Canada Revenue Agency, Amazon, Microsoft, or even a friend. The goal is always the same: get you to click a link, open an attachment, or hand over information you shouldn't.

The name comes from "fishing" — they cast a wide net and wait for someone to take the bait.

The Warning Signs

  1. The sender's email address looks off. The email might say it's from "RBC Royal Bank" but the actual address is something like service@rbc-secure-login.net. Always check the full email address, not just the display name. Legitimate organizations use their own domain — not a random variation of it.
  2. There's a sense of urgency. "Your account has been suspended." "Immediate action required." "You have 24 hours to respond." Phishing emails are designed to make you panic and act fast before you think it through. According to the Canadian Anti-Fraud Centre, watch out for urgent pleas that play on your emotions — legitimate companies rarely pressure you like this.
  3. The link doesn't go where it claims. Before you click anything, hover your mouse over the link and look at the bottom of your screen — it'll show you the actual URL. Fraudsters often create fake websites using similar domain names with minor spelling differences. If something looks off, don't click it.
  4. It asks for personal information. Your bank, the CRA, and any legitimate organization will never ask for your password, SIN, or banking details over email. The Canadian Anti-Fraud Centre is clear: if you didn't initiate the contact, you don't know who you're actually talking to.
  5. Poor spelling and grammar. Many phishing emails contain awkward phrasing, strange capitalization, or obvious spelling mistakes. The Government of Canada's Get Cyber Safe campaign flags this as a key warning sign — legitimate organizations proofread their communications.
  6. The greeting is generic. "Dear Customer" or "Dear User" instead of your actual name is a red flag. Real companies that have your account on file know your name.

What to Do If You Get One

Remember: No legitimate company — not your bank, not the CRA, not Microsoft — will ever ask for your password, SIN, or banking details over email or phone. If someone is asking for this, it's a scam.

Already Clicked Something?

Don't panic, but act quickly:

  1. Change your password immediately on the affected account
  2. Enable multi-factor authentication if you haven't already
  3. Check your account for any activity you don't recognize
  4. If banking or financial information was involved, call your bank right away
  5. Report it to the Canadian Anti-Fraud Centre at 1-888-495-8501

The Bottom Line

Phishing emails are getting more sophisticated every year — but so is awareness. Take an extra five seconds before clicking any link in an email. Ask yourself: was I expecting this? Does this make sense? When in doubt, don't click.

For more tips on staying safe online, the Government of Canada's Get Cyber Safe campaign at getcybersafe.gc.ca is an excellent Canadian resource covering everything from passwords to securing your home network.

Think your device has been compromised?

If you've clicked a suspicious link or think something isn't right with your machine, give us a call. We can help clean things up and make sure your device is secure.

Contact Us    902-247-2058

Sources

Canadian Anti-Fraud Centre — antifraudcentre-centreantifraude.ca

Get Cyber Safe, Government of Canada — getcybersafe.gc.ca