- According to Verizon's 2026 Data Breach Investigations Report, the human element is present in 62% of breaches and ransomware is involved in 48% of them.
- According to Statistics Canada, 16% of Canadian businesses were impacted by a cybersecurity incident in 2023 and recovery spending doubled to $1.2 billion.
- According to the Canadian Anti-Fraud Centre, reported losses exceeded $704 million in 2025, including $67.9 million from spear phishing alone.
- A large wire transfer requested by email always requires voice confirmation through a separate channel (PlanAxion, 2026).
On a Monday morning, the accounting technician of a Laval distributor receives an email from her president: “Urgent, I am in a meeting, wire $48,000 to the attached supplier before noon.” The tone is right, so is the signature. One detail: the president never wrote that email. That is a cyberattack, and it looks nothing like a hacker movie.
Figures cited here come from public reports (Verizon, Statistics Canada, Canadian Anti-Fraud Centre) and describe trends, not your specific exposure.
According to Verizon's 2026 Data Breach Investigations Report, which analyzes more than 22,000 confirmed breaches across 145 countries, the human element is present in 62% of breaches, and ransomware is involved in 48% of them.
What is a cyberattack and why does it target your business?
A cyberattack is an action carried out by hackers to damage a system, access confidential information or extract money, and it targets businesses for two reasons: their data and their bank accounts. It takes many forms, often subtle ones, and the victim sometimes needs weeks to notice.
Modern hacking rarely exploits a spectacular technical flaw. It exploits a rushed employee, a reused password or a payment procedure with no second check. That is why a secure work environment, including cybersecurity for remote businesses, starts with employee habits.
The benchmarks worth remembering:
- According to Statistics Canada, 16% of Canadian businesses were impacted by a cybersecurity incident in 2023, and 30% of large businesses.
- Also according to Statistics Canada, recovery spending after incidents doubled from $600 million in 2021 to $1.2 billion in 2023, and 13% of impacted businesses experienced ransomware.
- According to Verizon (2026), the median ransom paid was US$139,875, and 69% of victims did not pay.
- According to the Canadian Anti-Fraud Centre, more than 112,000 reports and $704 million in losses were recorded in 2025, including $67.9 million from spear phishing.
How do you recognize malware hidden in a document?
Macro malware is a small program embedded in a document, sent to the victim, that activates when the victim clicks a button to “enable content”. The attack relies on curiosity or worry: an unpaid invoice, a delivery notice, an “unreadable” document that supposedly needs unlocking.
Two simple rules. You do not know the sender? Do not open the document. The document is unreadable and the only way to read it is to press a button? Do not press it. A legitimate supplier will find another way to reach you.
How do you spot email phishing and business email compromise (BEC)?
Email phishing comes in two forms: the mass fraudulent email (password reset, parcel tracking) and business email compromise (BEC), a patient attack that targets people authorized to make payments. The first can be recognized in seconds. The second can mature for months.
For mass emails, check the greeting: a company you bought from knows your name, a fraudster rarely does. Be wary of an unknown sender who seems to know you. Hover over the link to see the real destination, often hidden behind a URL shortener. Spelling mistakes remain a clue, but Verizon notes that generative AI has made fraudulent emails much cleaner.
For BEC, the script is well rehearsed. Hackers target accounting or finance, plant software that watches exchanges for weeks (who talks to whom, in what words, who approves what), then wait for the right moment: the boss travelling, in a meeting, unreachable. The fake email then arrives, marked “Urgent”, requesting a large international wire.
The defence fits in one sentence: every large transfer requires voice confirmation, by phone, at the number you already know. Most of the time, your boss will have no idea what you are talking about. You will have foiled the attack, and that is the moment to review the company's internal controls and application risks.
What is the difference between smishing and vishing?
Smishing is phishing by text message and vishing is phishing by phone call; both aim to obtain your personal and banking data, one through a link to click, the other through the pressure of a human voice. They work because the phone is always in our pocket and its small screen invites us to tap to “see it larger”.
Smishing borrows familiar names: iCloud, your bank, Canada Post, a fake Interac transfer to “accept”. The right response is to do nothing: no click, no reply, no conversation. Block the number, but stay alert, fraudsters have others. Verizon (2026) also observes that click rates on mobile vectors (text, voice) are 40% higher than by email in phishing simulations.
Vishing is the fake fraud accusation from Revenu Québec or the Canada Revenue Agency, the cruise you win every month, the fake Microsoft technician. Hang up. Then call the organization at its official number to warn it: less wary people will get the same call.
An urgent wire transfer requested by email is not an emergency: it is an alarm signal.
What is ransomware and how do you protect against it?
Ransomware is malware that blocks access to the system and encrypts the data, then demands a ransom, often in cryptocurrency, in exchange for a promise to unlock everything. It arrives through a downloaded attachment or an infected website, and it plays on anxiety, sometimes by accusing the victim of illegal acts.
Paying guarantees nothing. The software often stays in place, which announces the next attack. Statistics Canada reports that 88% of Canadian businesses hit by ransomware did not pay in 2023. Verizon notes that the median ransom is falling, but that the share of breaches involving ransomware has climbed to 48%.
Protection is unglamorous and very effective: update everything (operating system, software, antivirus, firewall), and make periodic backups stored offline or in the cloud, tested at least once a year. A backup you have never restored is only a hypothesis. If personal information is affected, Law 25 imposes notification obligations you should know before the incident.
How do you reduce the risk of a cyberattack day to day?
Reducing the risk of a cyberattack rests on three reflexes: never click an unsolicited link or attachment, confirm any unusual payment through a second channel, and keep updates and backups current. Technology protects the work environment; vigilance protects everything else. Learning to detect an attack remains the cheapest way to avoid it.
Frequently asked questions
What are the most common types of cyberattacks on businesses?
The five most common forms are malware hidden in a document, email phishing (including business email compromise or BEC), text message phishing (smishing), phone phishing (vishing) and ransomware. According to Verizon (2026), the human element is present in 62% of breaches, which explains why these attacks target employees first rather than infrastructure.
How can you tell if an email is fraudulent?
Check four things: a generic greeting when the sender should know your name, an unknown sender who seems to know you, a link whose real destination (visible on hover) does not match the text, and a sense of urgency. Spelling mistakes are a less and less reliable clue, since generative AI has made fraudulent emails far more polished.
What is business email compromise (BEC)?
Business email compromise is a patient attack: hackers watch the exchanges of someone authorized to pay, then send a fake email from the unreachable boss demanding an urgent international wire. In Canada, spear phishing caused $67.9 million in reported losses in 2025 according to the Anti-Fraud Centre. The defence: confirm by voice, at a known number.
Should you pay the ransom in a ransomware attack?
No, in the vast majority of cases. Paying guarantees neither data recovery nor removal of the malware, which often prepares the next attack. According to Statistics Canada, 88% of Canadian business victims did not pay in 2023. The real defence is a recent, offline backup whose restoration has actually been tested.
What should you do immediately after a cyberattack?
Isolate the affected devices from the network, change compromised passwords and enable multifactor authentication, then notify your IT team or service provider. Document what happened and report the incident to the police and the Canadian Anti-Fraud Centre. If personal information is involved, Law 25 requires notifying the Commission d’accès à l’information du Québec.
- Verizon, 2026 Data Breach Investigations Report: more than 22,000 breaches analyzed across 145 countries, human element present in 62% of breaches, ransomware in 48%, median ransom of US$139,875, 69% of victims not paying, mobile click rate 40% higher.
- Statistics Canada, Impact of cybercrime on Canadian businesses, 2023: 16% of businesses impacted, recovery spending doubled to $1.2 billion, 13% hit by ransomware, 88% not paying a ransom.
- Canadian Anti-Fraud Centre, Top 10 frauds in 2025: more than 112,000 reports, $704 million in losses, $67.9 million attributable to spear phishing.

