The New Face of BEC: How AI Voice Cloning and Deepfakes Are Hitting Canadian SMBs in 2026
Business email compromise has always relied on a simple premise: make a request look legitimate enough that someone acts on it before they think to verify. For more than a decade, that meant a well-crafted email from a spoofed domain, an impersonated executive, a plausible pretext, and a wire transfer instruction. Canadian businesses learned — slowly and expensively — to question unusual payment requests and verify senders.
In 2026, that learned caution is being systematically bypassed. The email still arrives, but now it is followed by a phone call from the CFO's voice. Or a Microsoft Teams meeting where every participant, including the CEO, appears on video. Or an urgent voicemail that sounds exactly like the person the employee has worked beside for three years. The fraud is the same. The verification methods your team learned are no longer sufficient.
The Canadian Fraud Picture in 2026
The scale of the problem in Canada is growing. The Canadian Anti-Fraud Centre's 2025 annual statistics, released in March 2026, recorded CA$704 million in reported fraud losses — the highest year on record, up from CA$638 million in 2024. Spear phishing and business email compromise accounted for CA$67.3 million in reported losses in 2024 alone, making it the second-largest category of cybercrime losses reported to the CAFC after investment fraud. The CAFC's own reporting acknowledges that only 5 to 10 per cent of victims report incidents, which puts the realistic national fraud loss in the range of CA$3.5 to CA$7 billion annually.
For Canadian SMBs, the stakes are sharpest because the per-incident exposure is highest. Coalition's 2026 Cyber Claims Report found that BEC attacks on Canadian organizations increased 171 per cent in 2025, with an average loss of CA$21,000 per incident — an amount that would take many small businesses months of net profit to absorb. Overall cyber claims in Canada rose 102 per cent in 2025. These are not large-enterprise numbers. They are the losses hitting the professional services firm, the construction company, the logistics operator, and the accounting practice.
How AI Has Changed the Attack
The traditional BEC playbook — email impersonation, domain spoofing, invoice fraud — still works because it is cheap and scalable. What has changed is the escalation layer available to attackers when the initial email generates hesitation.
A 2026 survey of 251 Canadian companies by KPMG Canada found that 81 per cent of businesses that had been defrauded said generative AI was used in the attack. The most common methods were AI-generated phishing emails and chats, identified by 60 per cent of victimized organizations, followed by deepfake documents at 39 per cent, and voice-clone calls impersonating executives at 24 per cent. Seventy-two per cent of companies reported losing as much as 5 per cent of annual profits to AI-enabled fraud. Only 26 per cent had implemented and tested a comprehensive fraud incident response plan that explicitly covered AI-powered attacks.
The attack anatomy in 2026 follows a consistent pattern. An employee in accounts payable, finance, or HR receives an email — sometimes from a spoofed external address, sometimes from a compromised internal account — requesting an urgent wire transfer, a change to direct deposit banking information, or access to credentials. The email creates urgency but also doubt. In the next step that doubt is resolved: a phone call arrives from the requestor's number, using their voice, confirming the request. Research by sqmagazine.co.uk found that 40 per cent of BEC attacks in 2026 now include AI-generated voice or video deepfakes, up from under 5 per cent in 2023. A convincing voice clone requires as little as three seconds of publicly available audio — a LinkedIn video, a company webinar recording, an investor call.
The Verizon 2026 Data Breach Investigations Report documents the broader social engineering trend: 62 per cent of breaches involve the human element, and pretexting — building false scenarios to establish trust before making a request — now accounts for more than 50 per cent of all social engineering incidents, overtaking simple phishing in frequency. Voice phishing simulations in the DBIR show a 40 per cent higher success rate than email phishing. The escalation to voice is not an accident. It is the most effective layer available.
The Email Authentication Gap
One of the conditions that makes BEC possible at scale is the continued failure to deploy basic email authentication controls. PowerDMARC's 2026 Canada DMARC Adoption Report found that only 9.4 per cent of Canadian domains have full DMARC protection with a reject policy at 100 per cent enforcement. A further 21.7 per cent have partial coverage, and 68.9 per cent remain entirely unprotected. That means more than two-thirds of Canadian domain owners are sending email that can be spoofed without technical friction.
SPF records — the foundational sender verification layer — are in place on 94.2 per cent of analyzed domains. The gap between SPF adoption (94 per cent) and DMARC enforcement (9.4 per cent) represents the practical exposure: organizations have the first layer of authentication but have not configured the policy that instructs receiving mail servers to reject or quarantine emails that fail it. Attackers know this. A domain without DMARC enforcement is a domain whose name can be freely borrowed for impersonation.
The Canadian Centre for Cyber Security's Email Security Best Practices guidance (ITSM.60.002) has long recommended DMARC enforcement alongside SPF and DKIM as baseline controls for Canadian organizations. The CCCS's April 2026 Alert AL26-010 specifically called out the shift toward social-engineering-driven initial access — voice phishing, brand impersonation, credential harvesting, and help-desk abuse — targeting enterprise SaaS environments. The gap between CCCS guidance and actual Canadian domain configuration is a practical attack surface.
Why the Federal Government Is Now Warning About AI Impersonation
In March 2026, the Competition Bureau of Canada issued a public consumer alert warning Canadians about AI-generated government impersonators — realistic fake audio and video impersonating the Prime Minister, senior officials, and government programs to extract money and credentials. The alert is framed for consumers but describes a threat architecture that is identical to the one targeting Canadian businesses: a convincing voice or face that the recipient has no technical means to verify, used to establish a pretext for a financial or credential transfer.
When the federal government's competition regulator is issuing public warnings about a fraud technique, the technique has crossed from proof-of-concept into operational deployment at scale. The same tools and workflows being used to impersonate government officials are being used to impersonate your CFO, your IT administrator, your payroll processor, and your largest vendor.
The Verification Problem at the Core of AI-Enhanced BEC
The defences Canadian SMBs built for traditional BEC — suspicious email checklists, payment approval workflows, callback verification — were designed for a threat that relied on one-channel impersonation. Email alone. A single plausible message that the recipient evaluates in isolation.
AI-enhanced BEC attacks are multi-channel by design. The email creates the request and the urgency. The voice call provides corroboration. The deepfake video meeting eliminates the residual doubt. Each channel reinforces the others, and each additional channel requires a different verification method to defeat. Organizations that trained their staff to be skeptical of emails but did not update that training to include skepticism of voice calls and video have a gap that attackers are now exploiting systematically.
The FBI IC3 2025 report recorded USD$3.04 billion in BEC losses from 24,768 complaints — 86 per cent transmitted via wire transfer or ACH, which are fast-moving and frequently unrecoverable. The FBI also noted over USD$30 million in losses from BEC scams with a confirmed AI nexus, a figure expected to grow significantly as AI fraud tooling becomes cheaper and more accessible to less sophisticated threat actors.
Building a Defence That Works Against AI-Enhanced BEC
The practical defences against AI-enhanced BEC are not primarily technical — though the technical controls matter. They are procedural and organizational, built around the recognition that verification through the same channel as the original request is no longer sufficient.
Establish out-of-band verification as a mandatory policy for high-risk transactions. Any payment instruction, banking information change, wire transfer, or credential access request that arrives via email or messaging — regardless of who it appears to come from — requires verification through a separate, pre-established channel. Not a callback to the number in the email. Not a reply to the request. A call to the phone number already on file, or a meeting booked through the calendar system, using contact information established before the request arrived.
Deploy DMARC enforcement on all organizational domains. A DMARC reject policy prevents your domain from being spoofed in BEC emails targeting your customers, partners, and employees. Combined with SPF and DKIM, it closes the authentication gap that 68.9 per cent of Canadian domains currently leave open. This is one of the controls the CCCS has consistently recommended and one of the easiest to implement with the right technical support.
Update security awareness training to explicitly address voice cloning and deepfake scenarios. Employees who can identify a suspicious email but have not been trained to question an unexpected phone call from a familiar voice are only half-protected. Training programs need to include realistic scenarios involving AI-cloned voice calls and explain the technical reality: a caller who sounds exactly like the CEO may not be the CEO, and that alone does not mean the call is legitimate.
Implement payment controls that do not rely on identity verification alone. Dual-approval requirements for payments above a defined threshold, automated holds on same-day wire transfers, and mandatory email-plus-phone confirmation for changes to banking information all add procedural friction that AI impersonation cannot bypass. These controls are not about doubting employees — they are about removing the structural vulnerability that BEC attacks exploit regardless of how convincing the impersonation is.
Build an AI fraud response plan before you need it. The KPMG Canada survey found that only 26 per cent of organizations have tested a formal fraud incident response plan covering AI-powered attacks. The CCCS guidance on incident response (ITSAP.40.003) outlines the components a functional plan requires. For BEC specifically, that plan needs to include immediate steps for potentially stopping an in-flight wire transfer — contacting your bank's fraud team within hours of discovering the fraud is the difference between recovery and a permanent loss.
The average Canadian data breach now costs CA$7.11 million, according to IBM's 2026 report. For an SMB, a single successful BEC incident — a fraudulent wire transfer in the CA$50,000 to CA$500,000 range — can represent a material percentage of annual revenue. The fraud does not have to be at enterprise scale to be business-ending.
Sources
- Canadian Anti-Fraud Centre. *Annual Reports.* antifraudcentre-centreantifraude.ca
- KPMG Canada. *Fraud in the Age of AI.* kpmg.com (March 2026)
- KPMG Canada. *AI Fraud Hits Canadian Companies' Bottom Lines.* kpmg.com (March 2026)
- Coalition. *2026 Cyber Claims Report.* coalitioninc.com
- FBI Internet Crime Complaint Center. *2025 Internet Crime Report.* ic3.gov
- Verizon. *2026 Data Breach Investigations Report.* verizon.com
- PowerDMARC. *Canada DMARC & MTA-STS Adoption Report 2026.* powerdmarc.com
- Competition Bureau of Canada. *Watch Out for AI-Generated Government Impersonators.* canada.ca (March 2026)
- Canadian Centre for Cyber Security. *AL26-010 — Cyber Criminals Social-Engineering-Enabled Compromise of Enterprise SaaS Environments.* cyber.gc.ca
- Canadian Centre for Cyber Security. *Email Security Best Practices — ITSM.60.002.* cyber.gc.ca
- Canadian Centre for Cyber Security. *National Cyber Threat Assessment 2025-2026.* cyber.gc.ca
- IBM Canada. *IBM Report: Canada's Data Breach Costs Hit Record High.* canada.newsroom.ibm.com (July 2026)
- SQ Magazine. *AI Voice Cloning Fraud Statistics 2026.* sqmagazine.co.uk
AI-powered BEC is not a future threat — it is the threat landing in Canadian SMB inboxes today. Cloud Forces works with Canadian small and mid-sized businesses to close the technical gaps that make BEC possible: DMARC enforcement, email security architecture, endpoint protection, and the security awareness training that prepares your team for attacks that arrive by voice, not just by email. Our Cybersecurity team can assess your current email authentication posture and build a practical BEC defence framework calibrated to your risk profile. Book a free consultation to get started.
Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.
Ready to bring AI to your business?
Book a free AI Readiness Consultation — no commitment required.
Book Free Consultation