|
When you work for a multi-channel news outlet and receive an email placing an order for air compressors, welding equipment or restaurant refrigerators, it’s pretty easy to figure out it’s spam.
What if you work for a company that supplies air compressors, welding equipment or restaurant refrigerators? It’s pretty easy to get hooked, especially since a request email seems so innocuous.
According to multiple internet-security experts, they’re far from innocent.
Advertisement

“The ‘I’d like to place an order…’ email is commonly seen as a first cast in a low-effort phishing campaign or business email compromise,” says Randy Purse, senior adviser, cybersecurity training and education at Toronto Metropolitan University.
“On its own, this initial message does not constitute fraud; rather, it serves as a probe to identify companies that respond quickly and without verification,” he says.
“Keeping with the fishing analogy, once the cast has been made and the cybercriminals receive a reply, they have hooked the victim and begin reeling them in through follow-up messages designed to prompt action,” he says.
Those actions include requests for quotes or additional details, fake invoices or purchase orders, malicious attachments or links, payment routing or unusual payment requests, or, in an odd twist to the scam, capturing the victim’s email identity and using it to find other victims, which the cybersecurity industry calls business email compromise, he says.

Email scams often end with fraudulent financial transactions. In this example, the claim that a business transfer disables autodeposit doesn’t pass the smell test — and the sender’s email address isn’t as one would expect. (Supplied)
Smaller businesses are especially vulnerable, as they often don’t have the internal structure to keep one person from being able to both receive an order and approve payment or shipment, says Calgary-based Marike Kuyper, content marketing and education manager at TrendLife, a firm focused on protecting families from scams.
“The fact it asks for nothing up front is part of what makes it effective,” she says. “It is often the opening step in a longer script, intended to lower the target’s guard before the scam escalates.”
Prevention can often be as simple as identifying the underlying email address. It’s pretty easy to create an email address with the outward-facing name looking legitimate, such as “CEO Precision Parts LLC” but often a look at the actual email address — hover over the email avatar — shows something such as “johnnylikesjazz@gmail.co.uk”.
That’s your first red flag. It’s not absolute, however, as it can be easy to commandeer legitimate email addresses, or create an email address with substitute characters that look normal with a casual glance (such as replacing an O with a zero, or an l with a 1).
If the email address looks legitimate, check for other red flags, Purse says, such as:
Unusual spelling, grammar or formatting — although generative AI has made polished scam messages easier to produce:
- a signature that differs from the email address
- awkward phrasing or language you don’t typically see in business correspondence,
- prompts to download attachments or click unfamiliar links
- an unusual sense of urgency, or
- requests for business details or to provide additional information.
Most worrisome are requests for unusual payment schemes such as gift cards, multiple credit cards or wire transfers.
A scam borrowed from online consumer classified advertising sites is the overpayment, where the victim is requested to refund an overpayment. The goal is to receive the refund before the victim discovers the original payment bounced.
“Spear-phishing, which includes (business email compromise), continues to be one of the top reported scams recorded by the Canadian Anti-Fraud Centre,” Kuyper says.
In 2025, the centre received more than 112,000 fraud reports involving losses of over $704 million.
“The CAFC also notes that only an estimated five to 10 per cent of fraud victims ever report to the centre, so the actual losses are likely several times higher.”
|