CANADA · INTERACJune 16, 2026Updated June 27, 20268 min read

An Interac e-Transfer isn't really sent to a person. It's released to whoever answers the security question first — and that's the gap every version of the scam slips through.

Most warnings just tell you to spot the fake "you've received money" email. True — but it misses the deeper flaw. Until the recipient turns on Autodeposit, an e-Transfer doesn't move to a person at all; it waits for an answer, and a stranger who can guess or read that answer gets paid instead. Once you see money this way — as something claimed, not sent — both the fake email and the intercepted transfer stop looking like bad luck and start looking like the same gap. Here is how it really works, and the one setting that removes it.

$704M
Lost to fraud in Canada in 2025, a record (CAFC)
5–10%
Share of fraud actually reported (CAFC) — real losses are far higher
No law
Canada has no rule forcing banks to refund an authorised transfer
Autodeposit
The one setting that removes the security-question step a fraudster exploits
The short answer

There are two Interac e-Transfer scams, and they mirror each other. The one you receive: a fake "you've received money" email copies the Interac logo and gold "Deposit your money" button, then sends you to a counterfeit bank login that steals your password — the sender and link use a look-alike domain, not interac.ca. The one that hits when you send: if the recipient isn't on Autodeposit, the money waits behind a security question, and a fraudster who guessed or read the answer can answer first and divert it — CIBC describes this exactly. One setting closes both: Autodeposit, which Interac says "bypasses the email and security question and answer steps." Below is the real email beside the fake, then a beat-by-beat decode.

This is live right now. As of mid-2026, Canadian authorities are warning of a fresh surge: New Brunswick's Financial and Consumer Services Commission (FCNB) has an active alert on phishing disguised as Interac e-Transfer notices, and says the same templates are circulating nationwide; Manitoba RCMP warns the e-Transfer scams are "becoming more common." FCNB also gives one tell worth memorising: a genuine Interac e-Transfer notification never carries an attachment — not a PDF, not an HTML file. Any "e-Transfer" message with a file attached is a scam, full stop (the attachment is usually a fake login page that harvests your banking credentials). To be clear about what this surge is and isn't: Interac itself hasn't been hacked — interac.ca wasn't breached and there's no system "exploit." This is a wave of phishing and interception, which is exactly why the fix is a setting on your side, not a patch on theirs.

For most people the scam arrives as a single email: an Interac e-Transfer notification saying money is waiting, with a gold "Deposit your money" button. The trouble is that a genuine notice and a fake one look almost identical — same logo, same button. Here is the real email beside the scam, and the three details that separate them.

Side-by-side comparison of two Interac e-Transfer emails. Both show the Interac logo, the heading 'You've received money', '$250.00 CAD', and an identical gold 'Deposit your money' button. The genuine email on the left is from notify@payments.interac.ca and its link goes to etransfer.interac.ca then your own bank. The fake on the right is from a look-alike address, notify@interac-secure-deposit[.]ca, its link goes to the same look-alike domain — a fake bank login that steals your password — and it adds 'Expires June 18, deposit before it's gone' to rush you. A footer notes the real fix: turn on Autodeposit so a genuine transfer just lands in your account with no email to judge.
Real vs. fake. The scam copies the logo and the gold button — the giveaways are the look-alike sender and link domain, and the panic clock. Recreated examples; illustrative, links disabled.

Was Interac "hacked," "compromised," or "exploited"? No — and the distinction tells you where the fix is

If you searched whether Interac was hacked, your e-Transfer was compromised, or there's an Interac e-Transfer "exploit" going around, here is the plain answer: Interac's systems have not been breached. The website wasn't hacked, and there is no software exploit letting strangers reach into accounts. What is surging in 2026 is ordinary phishing and interception — fraudsters tricking people, or quietly winning the security-question race described below — not breaking Interac's code. That distinction is the whole point, because it tells you where the fix lives: not in waiting for Interac to "patch" something, but in switching off the one step a fraudster can actually exploit. That step is the security question, and Autodeposit removes it.

"Did my e-Transfer get doxxed?" Almost certainly not in the way it sounds. Getting a fake "you've received an e-Transfer" email does not mean your details were leaked or doxxed — scammers blast these to millions of addresses at random, the way spam works, and landing in your inbox doesn't mean they know anything about you. The real exposure is narrower, and worth checking: if a fraudster has gotten into your email inbox, they can read the genuine transfer notice and, often, the security question and answer sitting inside it — and that is what lets a transfer be intercepted. So the move isn't to panic about being doxxed; it's to secure the inbox — change the password, turn on two-factor authentication, and check for mail-forwarding rules you never set up.

"Interac Verified," "Interac Debit," "blacklisted" — the exact words, decoded

The 2026 wave is worded a dozen different ways, and the wording is the weapon — each phrasing is picked to make you react before you check. A few you may have searched, and the plain answer to each:

"Interac Verified" / "verify your account." Interac's published rule is blunt: it will never ask for your banking password, PIN, or full card number by email or text, and a real e-Transfer never sends you a link to "verify," "confirm," or "reactivate." However a message is branded — "Interac," "Interac Verified," "verification required" — a verify-through-this-link demand is phishing. Forward it to phishing@interac.ca and, if you want to check, open your bank's app yourself.

"Interac Debit" fraud. That's your tap-or-insert card — a different product from e-Transfer, and it isn't "hacked" by a text either. A "your card is blocked, verify now" message is the same scam wearing a card instead of a transfer. Call the number on the back of your card, watch your statement, and never unblock or "verify" a card through a texted link.

"Breached," "leaked," "blacklisted." These words describe a system compromise that didn't happen. Interac wasn't breached and your address wasn't put on a "blacklist" — a scam text reaching your inbox is random spam blasted to millions, not evidence anyone leaked your data. The only "leak" worth checking is your own email account, because that's what makes an interception possible.

Why the security question is the weak point

An e-Transfer to someone not on Autodeposit is protected by a single shared secret: the security question and its answer. The system assumes only the right recipient can answer it. But that assumption breaks in ordinary ways. People pick answers that are easy to guess or already public — a pet's name, a street, a favourite team. They reuse the same answer across many transfers. And if a fraudster has gotten into the recipient's email, the notification and, often, the answer are sitting right there to read. CIBC spells it out: fraudsters "guess the correct security answer, use previous answers, or check for emails containing the security question and answer to redirect the funds." Answer first, and the money is theirs.

This is the mirror image of the fake bank-text scam: there, you're tricked into handing over a login code; here, the secret that protects your money is something a stranger can simply guess or read. Either way, the safeguard is only as strong as a piece of information someone else can get hold of — which is why removing the secret entirely, with Autodeposit, is the real fix.

Anatomy of an interception — decoded

Interception isn't a hack of Interac or your bank. It's a quiet exploitation of the one step where the money pauses. Naming each move makes the gap visible.

1The transfer waits behind a question
You send an e-Transfer to someone who isn't on Autodeposit. Interac holds the funds and protects them with a security question only the recipient should be able to answer.
The lever — A shared secret. The whole security model rests on that answer being known only to the right person. But answers are often guessable, reused, or written down in an email — and a held transfer is a target sitting still, waiting for anyone who can answer.
The counter — If the recipient uses Autodeposit, there is no question and no pause — the money lands directly in their account and this step doesn't exist.
2The deposit link goes out by email or text
A notification — 'you've received an Interac e-Transfer, deposit your money' — is sent to the recipient's email or phone, the same channels a fraudster may already be watching.
The lever — Exposure of the notice. If the recipient's inbox is compromised, the fraudster sees the transfer arrive in real time. In a related phishing variant, the 'click to deposit' link itself is fake and leads to a counterfeit bank login page that steals credentials — RBC warns about exactly this.
The counter — A genuine Autodeposit transfer simply appears in your account with nothing to click. Never log in through a deposit link — open your bank's app yourself.
3Whoever answers first gets paid
The fraudster answers the security question before the real recipient does, and the funds are redirected into the scammer's account. Your intended recipient never receives them.
The lever — First-to-answer wins. Interac releases the money to whoever satisfies the question. There's no second check on identity at that moment, so the race goes to whoever has the answer — and a determined fraudster has often arranged to have it.
The counter — Remove the race: with Autodeposit there is no question to win. Failing that, use an answer no one can guess and share it through a separate channel, never in the transfer message.
If it happens, recovery is hard. Canada has no law forcing banks to reimburse money lost on a transfer you authorised, so it's decided case by case. CBC's Go Public has reported Canadians turned down after interception — including a woman who lost $7,000 through RBC after the system gave a fraudster repeated attempts at her security question — with banks frequently pointing to a weak or shared answer as the customer's responsibility. And beware the follow-up: anyone who then calls offering to "recover" your money is almost certainly running the second scam.

What to do

1Turn on Autodeposit in your banking app. Interac says it bypasses the security-question step, and TD states auto-deposited funds can't be intercepted by a third party. This is the single most effective fix.
2If you must send to someone not on Autodeposit, choose a security answer that can't be guessed or found online — never a pet, a street, a team, or anything public — and don't reuse the same answer across transfers.
3Never put the answer in the same email or text as the transfer notification. Share it a different way, like a quick phone call, so a compromised inbox can't reveal both at once.
4Never log in through a "click to deposit" link. A real Autodeposit transfer needs no link — open your bank's app yourself, and forward a suspicious Interac message to phishing@interac.ca.
5If a transfer was intercepted, tell your bank immediately and report to the Canadian Anti-Fraud Centre — then see the full Canada reporting directory and recovery odds. Unsure about an e-Transfer or "deposit" message? Run it through our Canadian scam-text checker or send it to our free case review first.
From the field. What makes interception work is that nothing about it feels like a scam. You send money to a real person; no one phones you, no one threatens you, no link gets clicked. The failure is structural — a few quiet minutes where the money sits behind a secret that turns out not to be secret enough. That's why the answer isn't vigilance, it's design: turn on Autodeposit and the vulnerable step simply stops existing. The cruelty is in the aftermath, where the same banks that built the security-question system can turn around and call a guessed answer your fault. So close the gap before you ever need to argue about it. Send money in a way that has no question for a stranger to answer.

An e-Transfer or "deposit" message you're unsure about? Send it to us first.

Paste the message or the link. A real expert reviews every case and replies within 24 hours. Free, confidential, no pressure — before you tap anything.

Submit a free case review →Where to report a scam in Canada

Common questions about Interac e-Transfer interception

What is an Interac e-Transfer interception scam?

It's when money you send by e-Transfer is diverted before it reaches the person you meant to pay. When a transfer isn't set to Autodeposit, Interac holds the funds behind a security question and sends the recipient a link to "deposit your money." Whoever answers the security question first gets paid — and a fraudster who has guessed the answer, reused an old answer, or read it inside a compromised email inbox can answer first and redirect the money to their own account. CIBC describes exactly this: fraudsters "guess the correct security answer, use previous answers, or check for emails containing the security question and answer to redirect the funds." The recipient simply never receives it.

How do I stop my e-Transfers from being intercepted?

Turn on Autodeposit. Interac says Autodeposit "bypasses the email and security question and answer steps" — the money lands directly in the registered account, and TD states auto-deposited funds "cannot be intercepted by a third party." With no security question in the chain, there is nothing for a fraudster to answer. If you ever do send to someone not on Autodeposit, use a security question whose answer can't be guessed or found online, and never send the answer in the same email or text as the transfer notification — share it a different way, like a phone call.

Will my bank refund an intercepted e-Transfer?

Be realistic: Canada has no law forcing banks to reimburse money lost to a transfer you authorised, so it's case-by-case and at the bank's discretion. CBC's Go Public has documented Canadians refused reimbursement after interception — in one case a woman lost $7,000 through RBC after the system gave a fraudster repeated chances at her security question, and banks often point to a weak or shared security answer as the customer's responsibility. Report it to your bank the moment you notice, but don't count on getting it back. See our Canada guide for the full reporting process and the honest odds.

I got an email saying I have an e-Transfer to "click to deposit" — is it safe?

Treat it with suspicion. A common variant is a phishing email or text — "you've received an Interac e-Transfer, click here to deposit" — whose link goes to a fake bank login page that harvests your online-banking credentials. RBC warns about exactly this. A real Autodeposit transfer just appears in your account with no link to click. If you have to act on a deposit link, never log in through it: open your bank's app yourself or type the bank's address directly. You can forward a suspicious Interac message to phishing@interac.ca.

Was Interac e-Transfer hacked or compromised in 2026?

No. Interac's systems were not breached, and there is no software "exploit" letting strangers drain accounts. The 2026 surge people are searching about is a rise in phishing emails and interception fraud — social engineering, and guessing or reading a transfer's security question — not a hack of Interac itself. New Brunswick's FCNB and Manitoba RCMP have both issued active alerts about the phishing wave. Because it isn't a system breach, the fix is on your side: turn on Autodeposit, which removes the security-question step entirely, and never log in through a "click to deposit" link.

I got a fake e-Transfer email — does that mean I was doxxed?

Almost certainly not. Scammers send fake "you've received an Interac e-Transfer" notices to millions of email addresses at random, the way spam works; receiving one doesn't mean your information was leaked or that they know anything about you. The genuine risk to watch is your email inbox itself: if a fraudster has access to it, they can read a real transfer notification and the security question and answer inside it, which is how interception happens. If you're worried, secure the inbox — change the password, turn on two-factor authentication, and check for mail-forwarding rules you didn't create.

I got a message from "Interac," "Interac Verified," or asking me to "verify" my account — is it real?

Treat any "verify," "confirm," or "reactivate your account" message as phishing, however it's branded. Interac's own security guidance is blunt: it will never ask for your banking password, PIN, or full card number by email or text. A genuine Interac e-Transfer never asks you to verify or confirm your details through a link — with Autodeposit the money simply appears in your account. So a text or email that pushes you to a link to "verify," whether it says "Interac," "Interac Verified," or "verification required," is fake. Don't tap the link; forward it to phishing@interac.ca and, if you want to check your account, open your bank's app yourself.

Is "Interac Debit" fraud the same as an e-Transfer scam?

They're two different Interac products, and neither is "hacked" by a text. Interac Debit is the card you tap or insert to pay; Interac e-Transfer is the email/text money-send this page is about. A phishing message about either — including a "your Interac Debit card is blocked/compromised, verify now" text — is social engineering, not a breach of Interac's network. Handle a card message the same way: Interac and your bank never text a link to unblock or verify a card. Call the number on the back of your card, watch your statement, and ask for a replacement if a charge you didn't make appears. On the e-Transfer side the weak point is the security question; on the debit side it's a lost or skimmed card or a phished PIN.

Was my Interac e-Transfer "breached," "leaked," or "blacklisted"?

No — those words describe a system compromise, and that isn't what happened. Interac's network wasn't breached, and there is no "blacklist" your address lands on. A scam e-Transfer text reaching you means a fraudster blasted it to millions of addresses at random, not that your data leaked. The one real "leak" worth checking is your own email inbox: if someone else can read your mail, they can see a genuine transfer's security question and intercept it — so secure the inbox (new password, two-factor authentication, and remove any mail-forwarding rule you didn't set). Turn on Autodeposit and there's no security question left to leak in the first place.

Sources & further reading

Claims here follow Interac's and the banks' own security pages (CIBC, TD, RBC), the Canadian Anti-Fraud Centre, and CBC's Go Public reporting on Canadian e-Transfer reimbursement. The diagram is illustrative, built from that guidance, not a captured real transfer.

Interac — AutodepositCIBC — e-Transfer fraudInterac — security & fraud guidanceRBC — Cyber Security alertsCanadian Anti-Fraud CentreCBC Go Public — e-Transfer fraudFCNB (New Brunswick) — Interac e-Transfer phishing alertManitoba RCMP — Interac e-Transfer scam warning

Keep reading