Connect with us

Business and Economy

5 expert tips to protect yourself from financial fraud when the banks won’t

Published

on

By Erica JohnsonAna Komnenic, CBC News, RCI

Cybersecurity expert Claudiu Popa says financial institutions could do much more to protect customers from fraud. Until then, he urges customers to protect themselves. Photo: CBC / Alex Lupul

Canadians are being drained of their life savings by scammers — and many are shocked when their banks refuse to reimburse them.

Bank fraud is a significant concern in Canada, according to the Canadian Anti-Fraud Centre. Every week, Go Public hears from people whose accounts have been emptied by fraudsters using everything from phishing emails and fake banking apps to phone spoofing, hacked passwords and unauthorized e-transfers.

All too often, investigations by financial institutions end not with accountability, but with banks blaming the very customers who trusted them with protecting their money.

It’s very disappointing, said Claudiu Popa, a cybersecurity expert who’s spent decades investigating cybercrime and educating the public.

Banks appear to be protecting themselves and their own reputations, rather than trying to remedy a situation.

Popa says he’s seen firsthand how criminals exploit everyday habits and security gaps. To help, he’s sharing five tips that can reduce your risk of becoming the next victim of bank fraud.

WATCH | How to respond if you’ve been defrauded and your bank’s blaming you:

Début du widget Widget. Passer le widget ?
Fin du widget Widget. Retourner au début du widget ?

1. Use strong, unique passwords

The first tip is the most basic: change your password regularly — every three months is recommended — and make it unique.

According to password manager NordPass, the most common password used in Canada and dozens of other countries in 2025 is 123456. The second most common password? 123456789.

Popa says we should stop thinking of passwords as short codes, and instead think of them as memorable passphrases.

Choose your favourite line from a movie or poem or whatever, and sprinkle in some personal punctuation, he suggested. Something like, H@staLaV1staBaby!

Make sure it’s 15-20 characters, and never reuse passwords across different websites. Reused passwords are one of the most common ways criminals can gain access after a data breach.

He also recommends using a password manager to store passphrases, so you can just copy and paste them, instead of typing them out.

Viruses latch onto the keyboard and track the keys you’re typing, which it can’t do if you’re pasting it directly.

2. Enable two-factor authentication, account alerts

Even the strongest password isn’t enough if a hacker gains access through a data breach or phishing scam — which is why Popa says two-factor authentication (2FA) is so important.

It adds a second layer of security, typically through a code sent to your device or generated by an authentication app.

It needs to be a separate platform, so that’s why you should always try to have a different device that you’re getting your second factor on, said Popa.

Business signs of the 5 main banks in Canada: TD, BMO, RBC, CIBC and Scotiabank.

None of Canada’s big five banks allow users to set up two-factor authentication for all transactions. Photo: CBC

Enlarge image (new window)

He advises against using SMS text messages for 2FA when possible. Instead, opt for a secure authentication app like Google Authenticator or Microsoft Authenticator.

Also turn on every available account notification — for logins, password changes and transactions.

Time is of the essence when you get defrauded, said Popa. The sooner you find out, the more likely it is that your banking institution will work with you, rather than protect themselves against you.

Go Public asked the big five banks — BMO, CIBC, RBC, TD and Scotiabank — if they allow customers to set up two-factor authentication. All said they give users the option to get codes via text message, which the Canadian Anti-Fraud Centre says are vulnerable to being intercepted.

All the banks also offer a more secure option — push notifications sent through their mobile apps. But only TD offers an authenticator app, which Popa says should be standard in the industry.

Popa also thinks customers should have the option to set up two-factor authentication for all purchases where a physical card is not used — not just when they log in to their online banking.

Currently, none of Canada’s big five banks offer that. The banks do allow customers to set up alerts for every transaction, so they can know right away if there’s a fraudulent charge.

3. Guard personal information

Bank fraud doesn’t always involve hacking. Scammers often trick people into handing over information themselves.

Popa says social engineering scams, phishing emails and phone scams are becoming increasingly sophisticated.

One common tactic people have written to Go Public about is call spoofing.

A hand holding a smartphone receiving a call from "their bank", which is likely a scam.

Fraudsters often manipulate caller ID, a process known as ‘spoofing,’ to make it look like someone from your bank is calling you. Photo: CBC / L.J. Cake

Enlarge image (new window)

Fraudsters make it appear as though they’re calling from your bank, then ask you to confirm details like your login credentials or account number to prevent fraud.

They might also ask you to share a one-time passcode sent to your phone.

Many of these scammers intentionally make these calls at dinnertime because you’re busy doing something else, because your bank branch might be closed, because it happens to be a weekend, said Popa. “They know exactly how to play with your emotions and your instincts.

Never share your passwords, PIN, one-time passcodes, or banking information with anyone who contacts you unexpectedly, either by phone, text or email.

Popa advises calling your bank directly using the number on their official website or your bank card. And don’t click links in unsolicited messages claiming to be from your bank, he warns. Many lead to fake websites designed to steal your credentials.

4. Avoid public wi-fi for banking

Checking your account while at a café might seem harmless — but public wi-fi is one of the riskiest ways to access financial information, Popa warns.

Hackers can use man-in-the-middle attacks to intercept your connection, steal your login credentials, or even install malware.

Instead of relying on wi-fi, use your cellphone data plan, which is more secure or connect through a trusted VPN (Virtual Private Network), which encrypts and protects your information.

WATCH | Do banks do enough to compensate customers who are victims of fraud?

Début du widget Widget. Passer le widget ?
Fin du widget Widget. Retourner au début du widget ?

5. Be careful with banking apps

Banking apps are convenient — but they can also pose risks, especially if downloaded from unofficial sources or used on devices with other background apps.

Many cybersecurity experts Go Public has spoken to — including Popa — decline to bank on their phone.

Many apps can run spyware or malware without your knowledge, Popa said. They can take screenshots, track your activity or steal your credentials.

Popa’s advice if you do use mobile banking: only download apps from the Apple App Store or Google Play Store.

Those are the only app stores that should ever be trusted with any apps at all, he said.

Better yet? Consider using your bank’s website on a secure browser at home.

Bonus tips

Also consider implementing these additional safety measures:

  • Monitor accounts regularly. Check your bank statements and transaction history frequently to catch suspicious activity early.
  • Shred financial documents. Don’t toss bank statements, cheques or credit card offers without shredding them first.
  • Secure devices. Install antivirus software, enable automatic updates and use screen locks on all devices that access your financial accounts.

A preventable crime

Bank fraud can feel overwhelming — but it isn’t inevitable. Popa says small changes in how you manage accounts and devices can make you a far less attractive target.

You can’t control what banks do, he said. But you can control how easy it is to scam you.


This article is republished from RCI.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Maria in Vancouver

Headline5 minutes ago

The Sobering Reality of Growing Old

Growing old brings a sobering reality: time is finite.  You watch your body slow down, see your parents age, and...

Lifestyle3 weeks ago

Dr. David Suzuki’s Legacy: A Celebration at 90

Celebrating Dr. David Suzuki’s 90th birthday on Friday, May 22  was a true privilege and a great pleasure! My husband,...

Lifestyle4 weeks ago

What I Know Now About Motherhood

Did you know that a mother’s cells can live in her child’s body for their entire lives? This fascinating phenomenon...

Headline2 months ago

Age with Audacity

At 25, I imagined life at 50 would mean I’d be past my prime and grumpy.  Little did I know,...

Lifestyle2 months ago

Spring Clean Your Body, Mind and Home

Spring has sprung! This season is perfect for spring cleaning, but why stop at our homes?  We can also rejuvenate...

Lifestyle3 months ago

Hear Us Roar

There is absolutely nothing wrong with a woman who wants her happily ever after. I certainly did. After 21 years...

Lifestyle3 months ago

The Real Rich

Margaret Atwood aptly captured this dynamic with the phrase, “Old money whispers, new money shouts.”  Let me elaborate on this...

Headline4 months ago

Love in the Afternoon of Life

Love in later life—the 50s, 60s, 70s, and beyond—is a thriving, fulfilling reality. It offers companionship, improved well-being, and joy,...

Headline4 months ago

Your Most Important Relationship is With Yourself

Valentine’s Day shouldn’t be celebrated only for one day. Love should be celebrated everyday. Valentine’s Day, when expanded beyond romance,...

Headline5 months ago

The 2016 Trend Made Me Reflect On My Past & Present

Like many others, I couldn’t resist joining the 2016 throwback trend.  It was all over social media, with everyone sharing...