There are two Interac e-Transfer scams, and they mirror each other. The one you receive: a fake "you've received money" email copies the Interac logo and gold "Deposit your money" button, then sends you to a counterfeit bank login that steals your password — the sender and link use a look-alike domain, not interac.ca. The one that hits when you send: if the recipient isn't on Autodeposit, the money waits behind a security question, and a fraudster who guessed or read the answer can answer first and divert it — CIBC describes this exactly. One setting closes both: Autodeposit, which Interac says "bypasses the email and security question and answer steps." Below is the real email beside the fake, then a beat-by-beat decode.
For most people the scam arrives as a single email: an Interac e-Transfer notification saying money is waiting, with a gold "Deposit your money" button. The trouble is that a genuine notice and a fake one look almost identical — same logo, same button. Here is the real email beside the scam, and the three details that separate them.
![Side-by-side comparison of two Interac e-Transfer emails. Both show the Interac logo, the heading 'You've received money', '$250.00 CAD', and an identical gold 'Deposit your money' button. The genuine email on the left is from notify@payments.interac.ca and its link goes to etransfer.interac.ca then your own bank. The fake on the right is from a look-alike address, notify@interac-secure-deposit[.]ca, its link goes to the same look-alike domain — a fake bank login that steals your password — and it adds 'Expires June 18, deposit before it's gone' to rush you. A footer notes the real fix: turn on Autodeposit so a genuine transfer just lands in your account with no email to judge.](/anatomy/interac-real-vs-fake.png)
Was Interac "hacked," "compromised," or "exploited"? No — and the distinction tells you where the fix is
If you searched whether Interac was hacked, your e-Transfer was compromised, or there's an Interac e-Transfer "exploit" going around, here is the plain answer: Interac's systems have not been breached. The website wasn't hacked, and there is no software exploit letting strangers reach into accounts. What is surging in 2026 is ordinary phishing and interception — fraudsters tricking people, or quietly winning the security-question race described below — not breaking Interac's code. That distinction is the whole point, because it tells you where the fix lives: not in waiting for Interac to "patch" something, but in switching off the one step a fraudster can actually exploit. That step is the security question, and Autodeposit removes it.
"Did my e-Transfer get doxxed?" Almost certainly not in the way it sounds. Getting a fake "you've received an e-Transfer" email does not mean your details were leaked or doxxed — scammers blast these to millions of addresses at random, the way spam works, and landing in your inbox doesn't mean they know anything about you. The real exposure is narrower, and worth checking: if a fraudster has gotten into your email inbox, they can read the genuine transfer notice and, often, the security question and answer sitting inside it — and that is what lets a transfer be intercepted. So the move isn't to panic about being doxxed; it's to secure the inbox — change the password, turn on two-factor authentication, and check for mail-forwarding rules you never set up.
"Interac Verified," "Interac Debit," "blacklisted" — the exact words, decoded
The 2026 wave is worded a dozen different ways, and the wording is the weapon — each phrasing is picked to make you react before you check. A few you may have searched, and the plain answer to each:
"Interac Verified" / "verify your account." Interac's published rule is blunt: it will never ask for your banking password, PIN, or full card number by email or text, and a real e-Transfer never sends you a link to "verify," "confirm," or "reactivate." However a message is branded — "Interac," "Interac Verified," "verification required" — a verify-through-this-link demand is phishing. Forward it to phishing@interac.ca and, if you want to check, open your bank's app yourself.
"Interac Debit" fraud. That's your tap-or-insert card — a different product from e-Transfer, and it isn't "hacked" by a text either. A "your card is blocked, verify now" message is the same scam wearing a card instead of a transfer. Call the number on the back of your card, watch your statement, and never unblock or "verify" a card through a texted link.
"Breached," "leaked," "blacklisted." These words describe a system compromise that didn't happen. Interac wasn't breached and your address wasn't put on a "blacklist" — a scam text reaching your inbox is random spam blasted to millions, not evidence anyone leaked your data. The only "leak" worth checking is your own email account, because that's what makes an interception possible.
Why the security question is the weak point
An e-Transfer to someone not on Autodeposit is protected by a single shared secret: the security question and its answer. The system assumes only the right recipient can answer it. But that assumption breaks in ordinary ways. People pick answers that are easy to guess or already public — a pet's name, a street, a favourite team. They reuse the same answer across many transfers. And if a fraudster has gotten into the recipient's email, the notification and, often, the answer are sitting right there to read. CIBC spells it out: fraudsters "guess the correct security answer, use previous answers, or check for emails containing the security question and answer to redirect the funds." Answer first, and the money is theirs.
Anatomy of an interception — decoded
Interception isn't a hack of Interac or your bank. It's a quiet exploitation of the one step where the money pauses. Naming each move makes the gap visible.
What to do
An e-Transfer or "deposit" message you're unsure about? Send it to us first.
Paste the message or the link. A real expert reviews every case and replies within 24 hours. Free, confidential, no pressure — before you tap anything.
Common questions about Interac e-Transfer interception
What is an Interac e-Transfer interception scam?
It's when money you send by e-Transfer is diverted before it reaches the person you meant to pay. When a transfer isn't set to Autodeposit, Interac holds the funds behind a security question and sends the recipient a link to "deposit your money." Whoever answers the security question first gets paid — and a fraudster who has guessed the answer, reused an old answer, or read it inside a compromised email inbox can answer first and redirect the money to their own account. CIBC describes exactly this: fraudsters "guess the correct security answer, use previous answers, or check for emails containing the security question and answer to redirect the funds." The recipient simply never receives it.
How do I stop my e-Transfers from being intercepted?
Turn on Autodeposit. Interac says Autodeposit "bypasses the email and security question and answer steps" — the money lands directly in the registered account, and TD states auto-deposited funds "cannot be intercepted by a third party." With no security question in the chain, there is nothing for a fraudster to answer. If you ever do send to someone not on Autodeposit, use a security question whose answer can't be guessed or found online, and never send the answer in the same email or text as the transfer notification — share it a different way, like a phone call.
Will my bank refund an intercepted e-Transfer?
Be realistic: Canada has no law forcing banks to reimburse money lost to a transfer you authorised, so it's case-by-case and at the bank's discretion. CBC's Go Public has documented Canadians refused reimbursement after interception — in one case a woman lost $7,000 through RBC after the system gave a fraudster repeated chances at her security question, and banks often point to a weak or shared security answer as the customer's responsibility. Report it to your bank the moment you notice, but don't count on getting it back. See our Canada guide for the full reporting process and the honest odds.
I got an email saying I have an e-Transfer to "click to deposit" — is it safe?
Treat it with suspicion. A common variant is a phishing email or text — "you've received an Interac e-Transfer, click here to deposit" — whose link goes to a fake bank login page that harvests your online-banking credentials. RBC warns about exactly this. A real Autodeposit transfer just appears in your account with no link to click. If you have to act on a deposit link, never log in through it: open your bank's app yourself or type the bank's address directly. You can forward a suspicious Interac message to phishing@interac.ca.
Was Interac e-Transfer hacked or compromised in 2026?
No. Interac's systems were not breached, and there is no software "exploit" letting strangers drain accounts. The 2026 surge people are searching about is a rise in phishing emails and interception fraud — social engineering, and guessing or reading a transfer's security question — not a hack of Interac itself. New Brunswick's FCNB and Manitoba RCMP have both issued active alerts about the phishing wave. Because it isn't a system breach, the fix is on your side: turn on Autodeposit, which removes the security-question step entirely, and never log in through a "click to deposit" link.
I got a fake e-Transfer email — does that mean I was doxxed?
Almost certainly not. Scammers send fake "you've received an Interac e-Transfer" notices to millions of email addresses at random, the way spam works; receiving one doesn't mean your information was leaked or that they know anything about you. The genuine risk to watch is your email inbox itself: if a fraudster has access to it, they can read a real transfer notification and the security question and answer inside it, which is how interception happens. If you're worried, secure the inbox — change the password, turn on two-factor authentication, and check for mail-forwarding rules you didn't create.
I got a message from "Interac," "Interac Verified," or asking me to "verify" my account — is it real?
Treat any "verify," "confirm," or "reactivate your account" message as phishing, however it's branded. Interac's own security guidance is blunt: it will never ask for your banking password, PIN, or full card number by email or text. A genuine Interac e-Transfer never asks you to verify or confirm your details through a link — with Autodeposit the money simply appears in your account. So a text or email that pushes you to a link to "verify," whether it says "Interac," "Interac Verified," or "verification required," is fake. Don't tap the link; forward it to phishing@interac.ca and, if you want to check your account, open your bank's app yourself.
Is "Interac Debit" fraud the same as an e-Transfer scam?
They're two different Interac products, and neither is "hacked" by a text. Interac Debit is the card you tap or insert to pay; Interac e-Transfer is the email/text money-send this page is about. A phishing message about either — including a "your Interac Debit card is blocked/compromised, verify now" text — is social engineering, not a breach of Interac's network. Handle a card message the same way: Interac and your bank never text a link to unblock or verify a card. Call the number on the back of your card, watch your statement, and ask for a replacement if a charge you didn't make appears. On the e-Transfer side the weak point is the security question; on the debit side it's a lost or skimmed card or a phished PIN.
Was my Interac e-Transfer "breached," "leaked," or "blacklisted"?
No — those words describe a system compromise, and that isn't what happened. Interac's network wasn't breached, and there is no "blacklist" your address lands on. A scam e-Transfer text reaching you means a fraudster blasted it to millions of addresses at random, not that your data leaked. The one real "leak" worth checking is your own email inbox: if someone else can read your mail, they can see a genuine transfer's security question and intercept it — so secure the inbox (new password, two-factor authentication, and remove any mail-forwarding rule you didn't set). Turn on Autodeposit and there's no security question left to leak in the first place.
Sources & further reading
Claims here follow Interac's and the banks' own security pages (CIBC, TD, RBC), the Canadian Anti-Fraud Centre, and CBC's Go Public reporting on Canadian e-Transfer reimbursement. The diagram is illustrative, built from that guidance, not a captured real transfer.