Your bookkeeper gets an email that looks exactly like it came from a supplier you have paid for years, with new banking details attached. Nobody thinks to call and check before the wire goes out. In Nova Scotia, most standard commercial policies do not automatically pay for that kind of loss. Cyber fraud and payment scams usually fall under a separate crime or cyber endorsement, one that has to be added on purpose and often carries its own low limit. Here is what a typical commercial policy actually covers, and where the gap usually sits.

What Just Happened Should Get Your Attention
In April 2026, a Quebec business authorized two wire transfers after criminals impersonated a legitimate contact and sent fake payment instructions. Banks caught it fast enough that the Canadian Anti-Fraud Centre and its partners recovered roughly $3.5 million. That case is one recovery among many losses that are not caught in time. The Centre reported spear phishing fraud losses of more than $68 million across Canada in 2025, and nearly $31 million more in the first three months of 2026 alone. Spear phishing is a scam email built to look like it came from someone you actually know or do business with, unlike the generic ones that land in a spam folder. The Centre also named small and medium businesses in construction, contracting, and real estate as common targets, which lines up with how those businesses operate: multiple suppliers and large one-off payments moving through email every week.
Cyber Fraud and What Your Standard Policy Actually Covers
General liability insurance, the policy most businesses carry as a baseline, responds when someone outside your business is hurt or their property is damaged because of your operations. Commercial property insurance repairs or replaces your building and equipment after a covered loss like fire or storm damage. Neither one was built to respond when money leaves your bank account because an employee believed a fake email. That is a different kind of loss, and it needs a different kind of coverage to answer it.
Is Ransomware a Different Problem From Wire Fraud?
Yes, and it is worth knowing both exist. The Canadian Centre for Cyber Security reported that ransomware, malicious software that locks up your files until you pay to get them back, was identified in 13 percent of Canadian businesses that reported a cybersecurity incident, and that recovery costs for cyber incidents nationally climbed to an estimated $1.2 billion. Wire fraud steals money directly through a fake instruction. Ransomware locks up your systems and demands payment to unlock them. A policy built to respond to one does not automatically respond to the other.
Where the Coverage Gap Usually Sits
Two separate coverages are worth asking about. Cyber liability insurance responds to a network security incident: a data breach, a ransomware attack, the cost of notifying customers and rebuilding your systems. Crime insurance, sometimes sold as a fidelity or social engineering endorsement, responds when someone tricks an employee into sending money or changing payment details. A lot of owners assume one covers the other. It usually does not, and even where a policy includes social engineering coverage, it often carries a sublimit, a lower cap built into the policy for that one type of loss, well below what the same policy pays for a physical loss. Ask your broker for the actual sublimit in writing rather than assuming a number.
Does General Liability Cover a Wire Fraud Loss?
No, in almost every case. General liability responds to third-party injury or property damage claims, not to money your own business sent out the door on a fake instruction. That gap is exactly why crime and cyber coverage exist as separate lines rather than being bundled automatically into a standard policy.

Why Contractors and Property Owners See This the Most
A contractor running jobs out of Burnside is paying subcontractors and suppliers constantly, often on timelines too tight to double check every request. A property manager closing on a downtown building or collecting a large deposit is moving exactly the kind of one-off, high-value payment a scammer is hoping to intercept. Restaurants and trucking companies are not exempt either. A restaurant processing supplier invoices or a trucking company paying a factoring company both move money through the same inboxes criminals are targeting. If you run a contracting business or hold commercial property, it is worth a direct conversation about where your coverage actually stands on this, rather than assuming it is bundled in.

What to Actually Do This Week
- Confirm any change to a supplier’s banking details by phone, using a number you already have on file, not one in the email.
- Ask your broker in writing whether payment fraud and social engineering coverage are included in your current policy, and what the sublimit is.
- Require a second person to sign off on any wire transfer above a set dollar amount before it goes out.
- Turn on multi-factor authentication for email and online banking, a login step that requires a second code beyond your password.
- Report a suspected fraud immediately to your bank and to the Canadian Anti-Fraud Centre, since faster action improves the odds of recovery.
- Pull your policy this week and read the crime and cyber section yourself instead of waiting for renewal.
Most standard commercial policies cap payment redirection fraud at a low sublimit, or leave it out completely, and you will not know which one applies to you until someone actually reads the wording in plain English. That is the job I do for business owners here: no jargon, just a straight answer about what your policy would pay if a fake invoice got through. Giving Halifax business owners the best service I can means catching that gap before a claim does, not after.
Don’t Wait for the Claim to Find the Gap
None of this means every email is a scam or every wire needs three signatures. It means the businesses that come through a fraud attempt without losing money are usually the ones who already knew what their policy would do before they needed it to. A phone call to confirm a banking change costs a few minutes. Finding out after the money is gone that your policy caps the loss at a fraction of it costs a lot more. Rayanur Rahman places commercial insurance for businesses across the Halifax Regional Municipality, and this is one of the more common gaps he finds once he actually reads a client’s existing wording.
Worried a Fake Invoice Could Get Through?
Send me your current policy and I will tell you plainly whether payment fraud and cyber crime are covered, and what it would cost to add if they are not.
About the author. Rayanur Rahman is a commercial insurance broker with Western Financial Group in Bedford, Nova Scotia. He places commercial policies for restaurants, contractors, trucking and transportation companies and commercial property owners across the Halifax Regional Municipality, with access to the standard Canadian insurers and to specialty and MGA markets. He works around a business owner’s schedule rather than standard office hours, including evenings for owners who cannot take a call mid-shift. Reach him at 902-321-1712 or book a 30 minute call.
Sources: Canadian Anti-Fraud Centre, payment redirection fraud recovery. Canadian Centre for Cyber Security, Ransomware Threat Outlook 2025-2027. Photo by Mikhail Nilov on Pexels. Photo by Pixabay on Pexels. Photo by Karola G on Pexels. General information only, not advice on your specific policy. Check your own wording.

Leave a Reply