Practical cybersecurity insights for Canadian small and mid-sized businesses.
This Month’s Focus: Human Risk - Phishing & Social Engineering
Cybersecurity discussions often focus on technology: firewalls, antivirus platforms, monitoring systems, and detection tools. But attackers frequently avoid those controls entirely. Instead, they target people.
Phishing emails, fraudulent invoices, impersonation attempts, and social engineering tactics continue to evolve, becoming more personalized and harder to recognize. For Canadian SMBs, a single click from a trusted employee can create access to sensitive systems, customer data, and financial information.
This month, we’re looking at human risk, not because employees are the problem, but because attackers increasingly see them as the easiest point of entry.
From the Contego Blog: How to Train Your Employees to Recognize Phishing Emails
Phishing remains one of the most common and damaging cyber threats for small and medium-sized businesses in Canada and the USA. Attackers use fake emails to trick employees into clicking on malicious links or giving up sensitive information. Even the best security tools cannot stop every phishing attempt. This is why employee training is one of the most effective defences against phishing.
Halton Hills Chamber Warns of Phishing Email Seeking Unpaid Invoices
The Halton Hills Chamber of Commerce is cautioning local businesses of a fraudulent email circulating in the community that asks for private information. The local chamber says the phishing email falsely claims to be from the Halton Hills Chamber of Commerce requesting copies of unpaid or outstanding invoices.
"The email references a “New Lead Accountant” and asks recipients to send statements or unpaid invoices. This message did not originate from the Chamber and should be treated as a scam/phishing attempt," said the Chamber in a statement about the incident.
Microsoft Details Phishing Campaign Targeting 35,000 Users Across 26 Countries
Microsoft has disclosed details of a large-scale credential theft campaign that has leveraged a combination of code of conduct-themed lures and legitimate email services to direct users to attacker-controlled domains and steal authentication tokens.
The multi-stage campaign, observed between April 14 and 16, 2026, targeted more than 35,000 users across over 13,000 organizations in 26 countries, with 92% of the targets located in the U.S. The majority of phishing emails were directed against healthcare and life sciences (19%), financial services (18%), professional services (11%), and technology and software (11%) sectors.