Authored by: Bryan Lachapelle, President & CEO

Could You Actually Spot a Scam Right Now? Here's Why It's Getting HarderOnce upon a time scams used to be easy (ok maybe not easy but easiER) to catch. It would like havbe bad spelling, maybe send you to a sketchy website or there would be a pop-up warning that you'd won a prize you never entered. Most of us learned to spot those signs years ago but AI has changed the game. Scammers can now produce polished writing, realistic images, phony endorsements, and even fake audio and video that look and sound completely legitimate. The problem is that scam can now come wrapped in familiar branding, real public figures, and a dramatic story that feels too detailed to be fake. They have overcome a good portion of the triggers our minds would look for and pairing that with social engineering that tells them exactly which button to press in order to make someone overlook the areas that would usually send up a red flag. This can make even savvy users of the internet blow past their common checks in order to click on the link that will bring them to something they want to read out.

Here's a real-world example that illustrates just how convincing these scams have become, and what to actually look for...

A recent Tiktok video circulating online used a paid ad to lead people in to a scam - it had a photo and title that was wild enough - clickbait really - to pull you in, and once clicked, it took you to a CBC web page which had a familiar logo, familiar layout, a breaking news headline. So, on the surface, it looked real but underneath, it wasn’t.

The article claimed a prominent Canadian politician had revealed a secret AI-powered investment platform live on television, personally tested it, and successfully cashed out. It went on to claim an unnamed politician tried to physically stop the broadcast and that police made an arrest because this was basically a cheat code to getting rich quick. It also claimed over 47,000 Canadians had already signed up, warning that unnamed authorities could shut the platform down at any moment.

None of it happened. It was a fabricated news story built entirely to funnel readers into an investment scam. This appealed to a subsect of people that believe that the government is actively trying to keep them oppressed and the language fit all of the emotional points that would trigger them to believe they would learn something to get one up on the “enemy”. This example is a useful demonstration of social engineering because every part of it maps to a tactic scammers use again and again which is to exploit your emotions and create urgency. Once you know what to look for both in the behaviour and the technical these scams get a lot easier to spot.

The Red Flags to Watch For

1. Check the URL, not the logo

A logo, colour scheme, and layout can all be copied in minutes. What can't be faked as easily is the actual domain so before trusting a page, especially one involving money, look at the web address itself. If you're unsure, don't click through links on the suspicious page. Open a new tab and go to the organization's official site directly. (This webpage definitely had a fake URL that would have been easy to spot).

2. Big claims need big coverage

Ask yourself: if this really happened, would only one website be reporting it? A major political scandal, an on-air arrest, a viral secret platform. These are the kinds of stories that would appear across multiple reputable outlets, not just one page linked from an ad. If you can't find it anywhere else, that's a strong signal something's off. In an age where AI can make a lot look real - developing these questions to be able to discern real from fake is going to become more necessary than before.

3. Pay attention to how it makes you feel

Scam content is often written to provoke a reaction, not to inform. It leans on financial stress, fear, anger, or excitement because strong emotion makes people act before they think it through. If something online suddenly makes you anxious, angry, or afraid of missing out, treat that as a cue to slow down rather than speed up.

4. Watch for "they don't want you to know"

Scammers love to frame their pitch as suppressed or insider information. It creates urgency, and it conveniently explains why you've never heard about this "opportunity" from a legitimate source. Any claim of secret or exclusive access should raise your guard immediately.

5. Notice the pivot

Many of these scams start as one thing (a news story, a warning, a giveaway) and suddenly shift into a pitch to invest, register, or share personal information. That shift is the whole point. The setup builds trust, then hands you off to the ask. Whenever content unexpectedly pivots toward money or personal data, stop and investigate before going further.

6. Be skeptical of "everyone else is doing it"

Big numbers, testimonials, and screenshots of supposed earnings are designed to create social proof, not evidence. A claim that thousands of people are already profiting isn't something you can verify just by reading it. Treat these claims the same way you'd treat any other unverified statistic: confirm it independently or assume it's inflated.

7. Recognize artificial urgency

"Limited spots." "Capacity is filling up." "Act before this gets taken down." These pressure tactics exist for one reason: the longer you have to think something over, research it, or talk to someone else, the more likely you are to catch the scam. Legitimate opportunities rarely require you to decide in the next five minutes.

It's Not Just Investment Scams

The same techniques show up in scams that target businesses directly:

  • A voicemail or email that sounds exactly like your CEO, requesting an urgent payment.
  • A video call that appears to show someone you know but saying things you don’t expect.
  • An email from a supplier claiming their banking details have changed, written in a tone that matches their usual communication perfectly.

The Canadian Anti-Fraud Centre reported roughly $57.7 million in spear phishing losses in just the first six months of 2026, with businesses frequently targeted through impersonation of executives, suppliers, and contractors.

The reality is that technology keeps evolving, but the defence is actually simple and really hasn't changed: stop, verify, then act.

What to Do If This Happens at Your Business

If you or a coworker come across something like this, whether it's a suspicious ad, a strange email from a "supplier," or a voicemail that doesn't sit right:

  • Don't forward it internally before checking. Even sharing a suspicious link with a coworker to ask "is this real?" can spread it further. Send a screenshot instead, or describe what you saw.
  • Report it to your IT team right away. Don't wait until you're sure it's a scam. If it turns out to be nothing, that costs a few minutes. If it turns out to be real, early reporting can stop it from spreading through your organization. This is a case of where urgency is required and its not sensationalizing things to say so.
  • If you clicked or entered information, say so immediately. There's no benefit to staying quiet, and every benefit to acting fast. The sooner your IT team knows, the sooner they can lock things down and limit the eventual impact.
  • Flag it for your team. If one person received it, others likely will too. A quick heads-up can stop a colleague from falling for the same thing.

Your IT provider would rather field ten "is this legitimate?" questions than deal with one successful breach after the fact. Often times in targeted attacks they will pick more than one target and roll it out. The same automation we are using to make our businesses better is also being used by scammers.

Your Quick-Reference Checklist

Before you click, register, send money, or share sensitive information:

  • Stop before reacting. Urgency is usually intentional.
  • Check the URL. Confirm you're actually on the organization's real website.
  • Verify independently. Don't rely on links inside the suspicious content itself.
  • Search elsewhere. Legitimate major stories will have multiple credible sources.
  • Question endorsements. A familiar face doesn't confirm someone actually said or did what's being claimed.
  • Distrust guaranteed or unusually high returns. If it sounds too good to be true, it is.
  • Verify financial companies independently. In Canada, you can check registration through the Canadian Securities Administrators.
  • Use a second channel to confirm. If a coworker, executive, vendor, or family member suddenly requests money or sensitive information, contact them a different way before acting.

The Bottom Line

Being tech-savvy doesn't make you immune. These scams aren't built to fool careless people, they're built to look legitimate long enough for anyone to take the next step without thinking. As AI makes fraudulent content faster and easier to produce, spotting it will rely less on noticing a typo or a strange font, and more on slowing down, questioning what you're seeing, and independently verifying before you act.

When something online asks for your trust, your information, or your money, take the extra minute and if you're ever unsure whether something is legitimate, whether it's an email, a link, a call, or a video, reach out to your IT team before you click, reply, or send anything. Call us at 905-228-4809 (Niagara) or 705-885-0993 (Barrie), that's exactly what we're here for.