What Happened?
The Anishinabek Police Service issued a second public warning on 9 September 2026 after five additional Business Email Compromise (BEC) cases were reported across the communities and organisations it serves in recent weeks.
In each case the targeted organisation had an established relationship with a supplier, wholesaler or contractor. Fraudsters used a spoofed or compromised supplier email account to advise that payment details had changed, supplying new bank account information that the organisation then paid into, believing the request was genuine.
The five recent cases combined for losses exceeding C$544,000, on top of more than C$350,000 lost across two similar cases investigated earlier in 2026 — bringing losses from the same pattern past C$894,000 for the year. Police say the attackers appear to understand the victim organisations' invoicing practices, accounts payable contacts and vendor details.
Where Was the Supplier Risk?
The risk here isn't a fabricated supplier — every targeted organisation already had a genuine, ongoing relationship with the supplier being impersonated. Familiarity with a supplier is not the same thing as a verified bank account.
The trigger event is a change to an existing, trusted supplier record, not the onboarding of a new one. A single sensitive field — the bank account — can be altered by an outside party without the organisation ever engaging a new or unfamiliar counterparty.
Police note the attackers appear to understand invoicing practices, accounts payable contacts and vendor details specific to each target — the attack is built on reconnaissance of a real business relationship, not a generic phishing attempt an alert employee might spot on sight.
What Went Wrong?
Email was treated as a sufficient channel for authorising a change to where payments are sent — a spoofed or compromised supplier mailbox can look, and read, exactly like the genuine one it's impersonating.
There was no independent, out-of-band step to confirm the new bank details before payment — organisations acted on the instruction as received, rather than verifying it through a channel the requester didn't control.
Supplier familiarity substituted for verification: because the supplier, invoicing pattern and business relationship were all genuine, the fraudulent bank details attached to that legitimate context went unquestioned.
What Should Businesses Do?
Verify every bank-detail change independently
Never action a change to supplier payment details on the strength of an email alone — confirm the new account by phone, using a number you already hold on file, not one supplied in the change request.
Treat existing-supplier changes as a distinct risk event
The highest-risk moment isn't onboarding a new supplier — it's a change to one you already trust. Build a mandatory, logged re-verification step around bank-detail changes specifically, however routine the request looks.
Assume the mailbox itself can be compromised
A spoofed domain isn't the only threat — a supplier's genuine email account can be compromised outright, so a message arriving inside a normal, ongoing thread is not proof of authenticity.
Separate the request channel from the verification channel
If the change request arrives by email, verify by phone or another channel the requester can't also control. Independent verification only works if the person asking for the change can't also confirm it.
The ArayaPRO Response
How ArayaPRO Helps
This is exactly the type of supplier risk ArayaPRO is built to control.
Further Reading
