Fraud

How to spot phishing emails and protect yourself from online scams

Written by Matt Lukas | Jul 24, 2026, 2:45:00 PM

Phishing scams continue to be one of the most common forms of fraud in Canada. Criminals send emails, text messages, or fake websites that appear to come from trusted organizations—such as your financial institution, the Canada Revenue Agency (CRA), courier companies, or popular online retailers—with the goal of stealing your passwords, banking information, or personal details.

The good news? Most phishing attempts share common warning signs. Knowing what to look for can help you protect your identity, your accounts, and your money.

What is a phishing email?

A phishing email is a fraudulent message designed to trick you into:

  • Revealing usernames, passwords, or online banking credentials
  • Sharing personal information such as your Social Insurance Number (SIN)
  • Clicking malicious links that install malware
  • Downloading infected attachments
  • Sending money to a scammer

These scams often create a sense of urgency, making you feel you need to act immediately before your account is suspended or a payment is missed.

How to identify a phishing email

Before clicking a link or opening an attachment, look for these common warning signs.

Check the sender's email address

Scammers often use email addresses that closely resemble legitimate organizations but contain small spelling changes or unusual domains.

For example:

  • support@yourbank-secure.com
  • cra-refunds.net
  • amazon-orders-help.co

Always verify the sender before responding.

Watch for generic greetings

Legitimate organizations often personalize emails using your name.

Be cautious if an email begins with:

  • Dear Customer
  • Dear Member
  • Dear User

Generic greetings can be a sign of phishing.

Be cautious of urgent or threatening language

Many phishing scams try to create panic by claiming:

  • Your account has been locked.
  • Suspicious activity has been detected.
  • Your payment has failed.
  • You must verify your identity immediately.

Take a moment to pause and verify the request before taking action.

Hover over links before clicking

Before selecting a hyperlink, hover your mouse over it (or press and hold on mobile devices) to preview the destination.

If the website address doesn't match the organization it claims to represent, don't click it.

When in doubt, type the company's website directly into your browser instead of following the email link.

Look for spelling and grammar mistakes

Many phishing emails contain:

  • Poor grammar
  • Awkward wording
  • Inconsistent formatting
  • Low-quality logos or branding

While some scams are becoming more sophisticated, errors can still be a major warning sign.

What should you do if you receive a phishing email?

If you think an email may be fraudulent:

  • Do not click any links or download attachments.
  • Do not reply to the sender.
  • Mark the email as phishing or spam in your email program.
  • Delete the email from both your inbox and deleted folder.
  • If the message claims to be from your financial institution, contact them using the phone number listed on their official website or the back of your debit or credit card.

What if you already clicked the link?

If you accidentally interacted with a phishing email, act quickly.

Change your passwords immediately

Update the password for the affected account, along with any other accounts using the same password.

If possible, create a unique password for every account.

Enable multi-factor authentication (MFA)

Multi-factor authentication adds an extra layer of security by requiring a second verification step before someone can access your account.

Monitor your financial accounts

Review your:

  • Bank accounts
  • Credit cards
  • Online banking activity
  • Credit report

Report any unauthorized transactions immediately.

Contact your financial institution

If you shared banking information or believe your account has been compromised, contact your financial institution as soon as possible. Acting quickly can help reduce financial losses and protect your accounts.

Tips to protect yourself from phishing scams

Good cybersecurity habits can significantly reduce your risk of becoming a victim.

Here are a few best practices:

  • Never share passwords or one-time verification codes by email or text.
  • Use strong, unique passwords for every account.
  • Enable multi-factor authentication whenever it's available.
  • Keep your devices and software up to date.
  • Verify unexpected requests using official contact information—not the details provided in the suspicious message.
  • Stay informed about the latest scams targeting Canadians.

The bottom line

Phishing scams continue to evolve, but awareness remains your strongest defence. Taking a few extra seconds to verify an email before clicking a link can protect your identity, your finances, and your peace of mind.

At YNCU, protecting our members from fraud is a top priority. If you believe you've responded to a phishing email or think your banking information may have been compromised, contact our Service Excellence Centre immediately at 1-800-413-YNCU (9628). You can also report scams to the Canadian Anti-Fraud Centre.

Looking for more practical financial tips? Browse our magazine for free financial education, fraud prevention resources, budgeting advice, and Honest Money Talk designed to help you build financial confidence.