Being aware of online scams and knowing what to look for is the key to protecting against cyber criminals. Here are some cyber scams currently affecting RBC clients.
Scammers are targeting students by impersonating law enforcement, immigration or other government officials, falsely claiming that the victim is involved in criminal activity. Victims may be told that their identity or banking information has been linked to crimes, such as money laundering, and that they must cooperate with an investigation by completing a wire transfer to a South-East Asian country to avoid arrest, fines or other legal consequences.
Red flags to look out for:
Reminder: Legitimate law enforcement agencies will not ask you to transfer money or ask you to communicate through messaging applications.
Scammers are sending emails posing as RBC Investor Relations, claiming to include a trade confirmation. The email contains a "View Confirmation" button that directs victims to a fraudulent RBC Direct Investing login page. Once victims enter their login credentials, the scammers gain access to their accounts to steal funds or securities.
Scammers are impersonating RBC and other service providers by calling victims and claiming their account has been compromised. To resolve the issue, the victim is directed to dial an âextensionâ or âactivation codeâ followed by the scammerâs phone number (i.e. dial *21 followed by 123-123-1234). This unknowingly activates call forwarding on the victimâs device, allowing the scammer to intercept all incoming calls and text messages. This may lead to unauthorized account activity (i.e. financial transactions, changes to personal information), as the bad actor can now intercept multi-factor authentication codes required for signing into the victimâs account.
Reminder: RBC will never ask you to provide one-time codes or PINs to verify your identity over the phone, share your password or create a new password with an âAdvisor.â
Scammers are sending fake text messages that impersonate RBC and Avion Rewards, claiming clientsâ Avion Rewards points are about to expire and urging them to click a link. This is a phishing scam aiming to steal sensitive data. Avion points do not expire and any message claiming they do is fraudulent. You can check your points balance and redeem safely through the Avion Rewards app or website.
As excitement builds for the FIFA World Cup, scammers may exploit the event to target unsuspecting fans with common scams.
Scams to look out for:
Follow these best practices to help avoid these common scams:
If you believe your financial information has been compromised, contact RBC and law enforcement.
Additional resource: Cyber threat bulletin: FIFA World Cup 2026⢠- Canadian Centre for Cyber Security
Scammers are using fake news articles to obtain victimsâ contact information and lure them into investing on fraudulent trading platforms. The objective is to steal financial information and funds.
1. Details of the scam:
Social media ads promoting fake news articles redirect victims to malicious websites, prompting them to enter personal contact details (phone number and email address) to access the full story. Using the gathered personal information, scammers then contact the victims â posing as investment advisors and pressuring them to deposit funds into a fraudulent trading platform.
2. Red flags to look out for:
3. What should you do?
Bad actors are sending fraudulent emails that claim a client's W-8BEN tax form has expired and requires immediate renewal. The objective is to steal login credentials, personal information and tax/financial data to commit fraud.
By impersonating RBC Direct Investing, scammers claim victimsâ tax forms (W-8BEN) require urgent updating, warning them of compliance issues and service disruptions if they do not act quickly. Advised to submit the renewed tax form using the link in the email, victims are directed to a fake online portal, where they are then prompted to disclose sensitive tax and personal information.
2. What you should know:
3. Red flags to look out for:
4. What should you do?
Bad actors are creating fake RBC payment processing and e-Transfer portals to steal clientsâ login credentials, personal information, and funds.
Scammers design convincing phishing websites that mimic legitimate RBC payment portals, e-Transfer pages, and Interac services. They distribute links via unsolicited emails, text messages (SMS), or fraudulent ads directing clients to these fake sites. Once victims land on the malicious portal, they're prompted to enter their online banking credentials, personal information, or payment details under the guise of "verifying your account," "confirming a transaction," or "updating your payment method." Scammers then use this stolen information to access client accounts, transfer funds or sell the credentials on the dark web.
RBC will never ask you to:
Bad actors are impersonating legitimate RBC investment advisors to steal funds, personal information, or login credentials.
Scammers create fake social media profiles or websites using real advisorsâ names, photos, and credentials â these pages typically link to official regulatory pages as validation. They initiate contact through unsolicited messages on social media, email, or online ads, urging you to communicate via non-RBC channels. Often, they promote high-risk, high-reward investment opportunities, such as stocks or cryptocurrencies, through exclusive groups. Victims are then pressured to send funds via cryptocurrency transfers or wire payments to individual accounts, circumventing secure banking channels.
Scammers are using legitimate short codes to carry out smishing campaigns, impersonating banks and other businesses. Their objective is to gain your trust by posing as a trusted entity and ultimately steal your financial information.
You receive an unsolicited text message (SMS) from an RBC-specific short code. The message creates a sense of urgency, for instance, claiming your account is at risk and immediate action is required. You may be asked for sensitive information upfront, or be prompted to click on a link, which will redirect you to a phony login portal or another malicious website. Either approach is designed to gain access to your bank account or credit card.
Scammers are sending text messages (SMS) promising attractive, yet illegitimate, job opportunities to lure victims into clicking harmful links or sharing sensitive information, ultimately aiming to steal personal and/or financial information, or gain device access.
You receive an unsolicited SMS from someone claiming to be a recruiter from a company, or employment agency, despite not having applied for a job. The sender promotes flexible positions with minimal work and/or guaranteed salary. The message may prompt you to click a link or reply âYES,â further engaging you to provide confidential information or download malware* onto your device.
* Malware is any malicious software designed to harm or gain unauthorized access to computer systems, networks, or data. It is used by cyber criminals to steal information, disrupt operations, or extort money.
Scammers are using fake human verification prompts to install malware* onto peopleâs computers when visiting compromised websites. This deceptive technique is known as a ClickFix attack.
You are directed to a compromised website where a fake security pop-up (called a CAPTCHA) prompts you to verify theyâre human. When you interact with the fake CAPTCHA (ie. clicks on the âIâm not a robotâ checkbox) a harmful command is silently copied to your clipboard. The pop-up then provides step-by-step instructions for âverificationâ that prompts you to paste and execute the dangerous command, which can lead to malware infections and/or stolen information.
Website addresses (URL) can expire unbeknownst to the owner/organization and then registered by someone else to redirect online traffic to high-risk content. This exposes visitors to cyber threats and causes reputational damage to the organization being impersonated.
Scammers took over an expired URL belonging to an annual Toronto Christmas Market, redirecting online traffic to gambling advertisements. The scammers were able to manipulate search engine results, ensuring their fake website appeared before that of the legitimate organization, encouraging market goers to visit their site.
Malware is any malicious software designed to harm or gain unauthorized access to computer systems, networks, or data. It is used by cyber criminals to steal information, disrupt operations, or extort money.
Caller ID spoofing is when a scammer falsifies the phone number on the caller ID to appear as if the call is coming from a legitimate source, such as a bank or government agency. There have been reports of suspicious calls falsely claiming to be from RBC.
Scammers are using caller ID spoofing to make their phone number appear as if itâs coming from RBC. They often create a sense of urgency, claiming your account is at risk or immediate action is required. With AI voice replication tools, these calls can be highly convincing and may reference recent transactions or personal details. The scammerâs objective is to gain your trust by impersonating a trusted entity and ultimately steal your financial and personal information.
Screenshot of an RBC caller ID from a non-RBC phone number. This number has been reported online as a scam.
What to look out for:
Scammers are contacting Canadians impersonating bank employees, law enforcement or government representatives.
The scam may begin with an unexpected call from someone impersonating a bank employee, law enforcement or government representative where the caller explains that their account and/or identity has been compromised.
Alternatively, it may also begin by encountering a pop-up on a computer advising of a detected virus or an error requiring resolution. The individual is asked to call a number and speak to someone posing as a bank representative, a federal agent or law enforcement. In a returned phone call, the individual will be advised that their accounts and assets will be frozen if they donât cooperate.
Regardless of the initial contact, the caller will insist that the individual must urgently withdraw their funds â either once or over a period of several withdrawals â to purchase gold in order to secure their funds. Once the individual purchases the gold, the caller will then proceed to make courier arrangements to have the gold picked up advising them that it will be sent to a ââsecure locationââ â this includes pick up at home or meeting up at a public location such as a shopping center or parking lot.
These calls may involve but are not limited to the following:
What you should know:
A Royal Bank of Canada representative, law enforcement or government employee will NEVER:
In addition, RBC will never ask you to assist in creating a new Online Banking password or ask you to share it. Online Banking passwords should only be created by the client, and never shared with anyone.
Scammers are using social media platforms to create fake ads impersonating known financial institutions. RBC has been the target of these fake ads, where a photoshopped image of RBC CEO David McKay is used to promote cryptocurrency training scams. To maximize their reach, these ads are often sponsored (paid) on the platform.
1. Details of the scams:
Social media users in Canada may see ads that appear to be from reputable financial institutions, promoting courses on cryptocurrency investment. These ads can redirect users to malicious websites where they will be asked to purchase a course promising to teach cryptocurrency investment strategies. In other scenarios, users are directed to a malicious website designed by the scammer to install viruses onto their devices.
Scammers are increasingly targeting reputable government platforms, such as the CRA website, through malvertising campaigns designed to steal victimsâ banking information. Malvertising occurs when threat actors purchase ad space on search engines and display deceptive ads that appear legitimate. Since search engines prioritize ads based on payment, bid amounts, and relevance, malicious ads can appear at the top of search results, increasing the likelihood that users will click on them. This prioritization creates a dangerous opportunity for scammers to exploit trust in search engines and redirect users to fraudulent sites.
In June 2025, a woman in London, Ontario searched âCanada Revenue Agencyâ intending to open a business account. Following expected CRA procedures, she provided her Social Insurance Number, banking details, and other personal information. However, she soon suspected she had unknowingly entered her information on a spoofed CRA website. Shortly afterward, her bank account was emptied.
Scammers are increasingly leveraging emerging AI technologies to target individuals planning a vacation. There has been a 900% increase in travel scams since 2023, with AI-enabled scams resulting in losses of an estimated $265,000 USD. Scammers use AI to easily generate fake emails, fraudulent booking websites, and, more recently, voice cloning to impersonate travel agents. A single submission of payment information through a fraudulent site or vishing call can result in immediate financial loss.
This emerging technology makes scams more believable and harder to detect, significantly increasing the risk for travelers.
Here are two of the most common tactics to be aware of:
Fake emails and fraudulent booking websites: Clients receive fake emails or stumble upon fraudulent booking websites that appear legitimate, often with AI-generated content and fake reviews to build credibility.
Vishing (voice phishing) calls: Sourcing voices from legitimate ads or social media content, scammers use AI voice cloning to impersonate travel agents, making phone calls to clients and tricking them into revealing payment information or making fake bookings.
Social Engineering is the use of expert manipulation via email, text message, phone call or even in-person encounters. It is the most common and most effective technique used by cybercriminals.
Cybercriminals often use psychological manipulation to trick individuals into revealing personal information or taking harmful actions.
Here are three of the most common tactics to be aware of:
Fear based manipulation. Scammers often try to create a sense of fear or anxiety to influence your decision. You might receive threatening messages that appear to come from trusted authorities such as law enforcement, government agencies or financial institutions. Warning of legal action, frozen accounts or other serious consequences. These tactics are designed to make you panic and hand over sensitive information or money.
Urgency and time pressure. Fraudsters often create a false sense of urgency to rush you into making quick decisions. For example, a message may claim your bank account is about to be closed, or that you must act immediately to claim a time sensitive offer. The goal is to prevent you from verifying the information or thinking it through.
Irresistible opportunities. If something sounds too good to be true, it probably is. Scams may promise free access to premium apps, exclusive deals, unexpected prize winnings or high paying job opportunities. In exchange, you might be asked to provide login credentials, download malicious software, or share personal details.
Scammers are using the recent tariffs and concerns regarding rising cost of living to trick Canadians into investing in fake investment opportunities. The deepfake investment scam is an AI-generated video that mimics legitimate organizations and uses the likeness and voice of a well-known political figure to promote an offer or partnership with an organization or business promising high returns on investment. These videos are often circulated on social media platforms and websites.
RBC has recently become aware of a deepfake investment ad impersonating a high-profile political figure promoting an inexistent program claiming to be supported by and backed by RBC. The ad promises high rates of return encouraging individuals to sign-up online by filling out their information and sending money to get started.
Be wary of investment scams â fraudulent deepfake ads will promote an opportunity to invest or make money, and will often utilize well-known political figures, CEO of large companies, actors, singers, or influencers to spread misinformation to ultimately obtain your funds.
Scammers are targeting Canadians during tax season with fake messages claiming to be from the Canada Revenue Agency (CRA) offering "unclaimed tax refunds" or stating that "the CRA owes you money." These scams trick people into sharing personal information or receiving fraudulent Interac e-Transfers.
Canadians receive emails, text messages, or phone calls claiming to be from the CRA. The messages typically state that the recipient is eligible for a tax refund that hasn't been claimed or that the CRA has discovered they're owed money. The scammer offers to send the refund via Interac e-Transfer for "faster processing." To receive this supposed refund, victims are asked to provide personal information (like SIN numbers, banking details) or click on fraudulent e-Transfer links that either steal information or request a "processing fee" before releasing the non-existent funds. The scammers use the CRA logo and official-looking documents to appear legitimate.
2. What should you know:
4. What should you do:
Scammers are targeting Canadians by pretending to be representatives from the Canadian Radio-television and Telecommunications Commission (CRTC) or the National Do Not Call List (DNCL) offering to register phone numbers to block unwanted telemarketing calls. These scams trick people into sharing personal information or paying fake "registration fees."
Canadians receive unsolicited phone calls or emails claiming to be from the CRTC or DNCL administrators. The scammers offer to add their phone number to the Do Not Call List to stop telemarketing calls. While the legitimate service is completely free and only requires a phone number, these scammers request extensive personal information (like full name, address, date of birth, SIN) and sometimes even demand payment for "processing fees" or "administration charges." Some variations include fake renewal notices claiming registrations are expiring and need immediate renewal (the real registration lasts for 5 years).
Scammers are sending emails to trick people into sharing their financial information over the phone. Instead of including suspicious links or attachments, they now put a phone number in the email and encourage recipients to call them.
Recipients receive emails that look like they're from popular software or online services claiming there's a strange charge on their account. The email tells them to call a phone number if they want to dispute the charge. This phone number doesn't belong to the real company - it belongs to the scammers. When someone calls to dispute the charges, the scammers ask for payment information to "verify the account" and "reverse the charges," but they actually use this information to steal money.
These scams work because they create worry about unexpected charges. When people are scared about money, they might act quickly without thinking. Even though it feels bad when someone thinks they've been charged for something they didn't buy, it's important to slow down and think carefully before responding to these emails.
Scammers are using fake security verification pages to trick people into running harmful code on their computers, leading to virus infections and stolen information. This is a trick that takes advantage of people's trust and unfamiliarity with computer commands.
People visit a website and see a fake security check page (called a "CAPTCHA") that claims to verify they're human. Instead of the normal picture puzzles, the page tells them to copy and paste a string of code into a special program on their computer (called "PowerShell"). This harmful code then installs viruses on the computer. The scammers use website addresses that look legitimate but aren't.
During the holiday season, scammers are taking advantage of the high volume of deliveries to steal information from clients. We have observed fake text messages and emails pretending to be from Package Delivery/Courier Services, or RBC regarding a pending delivery.
Scammers are sending fake shipping notices from popular courier services. They are sending phishing SMS and emails claiming that the recipient has a parcel waiting but must pay a customs or rescheduling fee, which needs to be done online via the attached link. This link directs the recipient to a genuine-looking phishing site for the courier service, where they will be tricked into either entering their credit card or banking information.
Scammers are also impersonating Delivery Agencies and RBC by calling clients, claiming to be assisting with a package delivery for which they require access to your online banking and personal and banking information.
With the overwhelming popularity and accessibility of online sports betting, fraudsters have adapted their tactics to target unsuspecting sports bettors. These scams often fraudulent offers, fake betting platforms, or manipulated odds to trick individuals into revealing personal information or sending money to accounts impersonating sports betting sites.
One common tactic is offering "guaranteed wins" or "insider tips" in exchange for upfront payment or deposit into a fake account. Once the payment is made, the fraudsters either disappear or request further funds, claiming there is an issue with the initial deposit.
Fraudsters may also pretend to be legitimate sports betting platforms and ask for sensitive banking and/or personal information, claiming it is required to process winnings or refund an "overpayment".
Details of the scam:
The taxi scam involves a card swap and a stolen PIN. In recent situations, an individual will be approached by a scammer claiming that they are attempting to pay their taxi fare, but they only have cash, and the taxi driver will only accept a card payment. The scammer will ask the individual if they can give them the cash and, in return, borrow and use the individualâs card to pay for the taxi fare.
The taxi driver, who is also a scammer, will ask the individual to complete the payment by inserting their card into a device and entering their PIN. The device is rigged to capture the entered PIN; meanwhile the taxi driver will secretly swap cards and hand back a different, but similar looking card to the individual.
With the card and PIN in hand, the fraudsters will then utilize it aggressively in a short period of time for in-store purchases or ATM withdrawals until fraud is detected or reported and card is blocked.
There has also been reports of scammers working alone, posing as a taxi driver and completing a card swap when the individual is paying for their ride
Individuals, especially seniors, are receiving phone calls from fraudsters pretending to be a bank employee. The caller will create an urgent scenario; in most cases, they will inform you that theyâve identified fraudulent activity on your account(s), and the card(s) needs to be cancelled immediately.
The fraudster will then instruct you to put your card(s) and PIN in an envelope, and hand it over to someone who will come to your door to pick up. Within a few minutes, the other fraudster will come to the door dressed as a courier service staff, while you are on the phone with the caller. You are then instructed to hand over the envelope to the person at the door.
The fraudster proceeds to deplete funds quickly through various means. This includes ATM withdraw, Point-of-sale purchases, and online purchase for credit cards.
To gain your trust, the caller will usually provide some details regarding your personal information (e.g. name, address). Or they sometimes will ask you to cut the card into pieces but leave the chip on the card intact before you put the pieces in the envelop. However, once they receive the card pieces they can tape it back and will still be able to use it for POS purchases since the chip is still functioning.
Fraudsters are targeting commercial clients using counterfeit cheque that are couriered to RBC branches. These cheques come with instructions to deposit funds into the commercial clientâs account.
After the deposit is made, the fraudster contacts the commercial client pretending to be a legitimate customer who has accidentally made a payment in excess of an agreed upon price or quote (âoverpaymentâ). The victim is asked to wire the difference to an overseas account to correct the error.
When the counterfeit cheque is inevitably returned, the account is at a loss for the funds that were sent to the bad actors.
Recent scam campaigns involve bad actors contacting clients as fraud representatives within their financial institution, including RBC. These are not actual representatives of the bank but are impersonating them to take advantage of unsuspecting victims. These calls may involve but are not limited to the following:
Other red flags of a scam to look out for on any call, not just those purporting to be from RBC:
A Royal Bank of Canada representative or employee will NEVER:
As the tax filing deadline approaches in Canada, we are once again observing a spike in phishing attacks targeting Canadians via SMS, emails, and phone calls. These scams may claim to be notifications and links regarding the following (but are not limited to):
These scams may also contain the following keywords if there is a linked URL (but again, are not limited to):
The CRA will not ask you by text message or email for personal information, bank information, payments by e-transfers or gift cards. While the CRA may notify you of new tax-related communications via email, these messages must be read by signing in to your CRA account at Canada.ca .
In addition, the CRA will never issue refunds via Interac e-Transfer. Should you click any link directing you to an Interac page, close the page immediately. All CRA payments are sent through Direct Deposit or mailed to you by cheque.
For more information about protecting yourself against CRA Scams, please visit https://www.canada.ca/en/revenue-agency/corporate/security/protect-yourself-against-fraud/scam-alerts.html .
In previous Scam Alerts, weâve discussed some tricky text-related methods that Fraudsters use to lure clicks, such as:
However, sometimes all it takes is the use of a familiar, âtrustedâ image (like the RBC logo) to get a victim to fall for the scam. Malicious messages may utilize bank logos or include image previews from their phishing websites to appear trustworthy, and the use of familiar logos can create a false sense of security â making it easier for unsuspecting individuals to fall victims to these scams.
Social media platforms are being increasingly leveraged by cyber criminals to spread malicious software (malware). Fake job postings or business opportunities might be used to lure users to download the malware.
Victims will receive direct messages from false recruiters with very attractive job opportunities, via LinkedIn or Facebook. The message contains a link to what is supposed to be the job description. When clicking the link, the malware will be downloaded.
Note: The job description could be hosted in a legitimate website (e.g. Dropbox, Google Drive, iCloud etc.)
Before clicking any links or downloading any attachments:
If you received a fake job posting:
Good afternoon, sorry to disturb you. We are looking for 1,000 online media workers. The only condition: must have a Canadian SIN or (foreigner who has worked here for more than one year) Job Description: Requires review of product web pages to increase product awareness and sales.
If you are interested, please answer 1 and click on the Whats App link to learn more! https://
You may have noticed that QR codes gained popularity during the pandemic - especially at restaurants as an alternative to printed menus. QR codes also continue to be a popular way to link to a website while attending an in-person event. Although convenient, QR codes can be used to trick you! Hackers are taking advantage of their popularity and sending phishing e-mails with malicious QR codes.
You receive an unexpected message with a QR code attached, requesting you to scan it.
Like other methods discussed in previous posts (Package Delivery scams â May 2023, Interac e-Transfer scams â March 2023) another common tactic targeting Canadians is the use of fake Telecom company refunds by masquerading as companies like Rogers, Bell, or Telus.
Victims will receive smishing and phishing messages stating that they are eligible for a refund due to a variety of reasons, such as outages, goodwill, or account corrections. These messages include a link directing them to a realistic-looking Telecom company phishing page and will appear to offer a refund via Credit Card or Debit. If Debit is selected, the victim will be directed to a fake Interac e-Transfer page where they will proceed to select their bank.
Keep in mind that Telecom companies will never send SMS messages regarding refunds, or issue refunds via e-Transfer or Credit Card. Any messages received should be deleted immediately.
An investment scam is when a fraudster offers an individual the opportunity to invest, often using cryptocurrency, and promises a high rate of return in a short amount of time. These offers can be solicited through online ads where the victim is redirected to a website, but may also be unsolicited; in either case, there is time pressure to ensure the individual commits before they have time to complete their research on the investment opportunity.
Scammers will create fake accounts on websites or on social media that appears to be legitimate. They will reach out to individuals to invest in cryptocurrencies and promise them massive profits, even sharing âscreen capturesâ or live âtrend graphsâ showcasing the progress of their investment. Note that these types of returns cannot be guaranteed, and anyone who promises a no-risk investment is most likely a scammer.
Cryptocurrency, along with other forms of payment such as gift cards, are often preferred by scammers because they are untraceable once they have left your account.
In most cases, victims of an investment scam will lose not only their investment but also their personal and financial information, leaving them vulnerable to identity theft.
3. What should you do to prevent becoming a victim of an investment scam?
With the increase in scam SMS messages (âsmishingâ messages) sent to Canadians targeting their bank accounts, clients must exercise caution when clicking on URLs sent to them. However, even the most eagle-eyed recipient may fall for the use of Punycode to disguise phishing URLs, making them look like legitimate domains.
In this scam method, punycode is what Fraudsters can use to replace âregularâ characters in a URL with a different, similar character, directing clients to a phishing site. This can make it very tricky to differentiate between a legitimate and fake URL, since these links may look almost exactly like the real thing at first glance.
This may look like the legitimate domain belonging to RBC. Pause and look carefully, you may notice that the ârâ in ârbc.comâ is underlined and is the character: âá¹ â. By clicking this link, the scam victim would be directed to a phishing website using the domain âá¹bcâ, which is not the same as ârbc.comâ.
In this second sample, it seems like the legitimate ârbconlinebanking.comâ domain at first. Assess closely and you will notice the dot under the âkâ, replacing it with a âḳâ (a âkâ with a small dot underneath):
2. What should you do?
RBC clients are seeing an increased number of sophisticated phishing emails impersonating RBC and requesting that the client resets their password due to suspected fraud on their account. When the link is clicked, the client will be redirected to a fraudulent RBC Online Banking site that steals client credentials.
At first glance, these emails may appear very legitimate due to the messageâs urgency and formality. Some of the information (like phone numbers and instructions) may even be real, in attempt to further increase the chances of luring a victim. Additionally, legitimate-looking links in the message will hide the true URL behind it, which directs the client to a phishing site.
2. Fraudsters may attempt to use some of the following fake reasons to lure clients into their scams:
RBC would never request a password reset for any of the above reasons! If RBC detects fraudulent activity on your account, we will contact you directly via the phone number associated on your account.
A Rental Scam is when a fraudster creates a fake advertisement for a room or property rental to steal money from interested renters. In this scam, would-be tenants are tricked into paying an upfront fee or deposit to secure the rental, when the property does not exist, has already been rented out, or has been rented to multiple people at the same time.
On the flip side, Fraudulent Renters target legitimate landlords. There are several ways that fraudulent renters commit scams:
With rapidly evolving technology, events, and social trends, scammers continue to develop creative methods of luring victims into phishing attacks. However, many of these attacks often have commonalities that we can use to easily identify scams.
One easy method of identifying a phishing scam is by paying attention to the website address (URLs) that the Banking site is hosted on and checking if it is an IP Address . You will never be asked by RBC or any other Financial Institution to conduct transactions or enter banking information on websites hosted on IP Addresses .
2. What is an IP Address?
To put it simply, an IP address is a string of numbers (such as 192.168.1.1) that the internet uses to translate the human-readable website addresses we use into computer language. Since words and characters are easier for us to remember, legitimate website owners will use a web address to direct users to their websites (e.g., www.rbcroyalbank.com , www.royalbank.ca , www.rbc.com , etc.)
RBC (or any legitimate organization) will never ask their customers to access their websites via an IP address. However, this is a common practice by scammers as it prevents them from needing to purchase a new phishing web address each time one is identified as a scam.
A call is received from what is displayed on a caller ID as a toll-free number. A recorded message states the call is from RBC and pertains to a fraud issue however no client name is mentioned.
After a moment which may include hold music, the caller may be transferred to a voicemail and asked to leave their contact information. A scam perpetrator will subsequently call the victim back and attempt to obtain Personal Identifiable Information (PII) and banking information while impersonating a VISA credit card security department representative. The goal being to conduct financial fraud.
Always remember that RBC Fraud Prevention representative will never ask a client to divulge banking or personal information on an outbound call. RBC relies on various methods to authenticate transactions and we may send you a SMS with One-Time Passcodes under various circumstances. RBC employee will never ask you to share this code by reading it back to us or by entering it on your phone keypad.
If you believe your confidential information may have been stolen or obtained by a fraudulent party either online, by telephone or through any other means, please call us immediately.
Report the unsolicited fraudulent phone call to:
Thank you for calling RBC fraud prevention center. One of our fraud specialists will be with you shortly. Please hold while I try to connect you.
Download recorded message
No one is available to take your call. At the tone, please record your message, when you finish recording you may hang up or press the pound key for more options.
Use Caution When Opening Links from Package Delivery/Courier Services
The drastic rise of e-commerce has resulted in an increase of scammers sending fake shipping notices from popular courier services. Scammers are taking advantage of this by sending phishing SMS and emails to trick unsuspecting Canadians into submitting their banking information.
The messages claim that the recipient has a parcel waiting but must pay a customs or rescheduling fee, which needs to be done online via the attached link. This link directs the recipient to a genuine-looking phishing site for the courier service, where they will be tricked into either entering their credit card or banking information.
The scam messages sent can range from being good imitations, to primitive or very off-brand:
Exercise Care when Interacting on Social Media
Fraudsters continue to impersonate RBC by creating fake RBC Facebook pages. Unsuspecting clients may interact with the fake pages and provide personal information, assuming that it is a RBC legitimate Facebook page.
These fake Facebook pages may look deceivingly close to the legitimate RBC Facebook page ( https://www.facebook.com/rbc ) as they often copy images, posts, and reactions from the RBC page.
Use Caution When Accepting Interac e-Transfers
Scammers are using fake Interac e-Transfer pages to direct clients to phishing sites resembling their bankâs login page, where they will be tricked into entering their login credentials. Once the credentials are entered, the scammers use them to steal money from the clientâs bank account.
These fake Interac pages look just like the legitimate Interac e-Transfer page, and contain links for the most common Canadian banks, including RBC. Scammers may use reasons such as tax refunds, telecom refunds, and COVID-19 relief to lure clients, allowing fraudsters to target as many Canadians as possible.
E-Transfer(s) received via SMS: Legitimate SMS messages from Interac Corp. regarding e-Transfers will be sent from the number â10001â. However, this number can still be faked by scammers, so continue to be vigilant while clicking links received from â10001â.
E-Transfer(s) received via Email: Verify the origin of the interac e-transfer email before clicking on links. Legitimate interac emails are typically sent from the âpayments.interac.caâ domain and include a digital signature. See screenshot for more details on what to look for.
Exercise Care when Web Searching to Avoid Phishing Scams
Fraudsters continue to impersonate RBC by creating âgenuine lookingâ phishing websites and scheming new ways to lure clients into clicking malicious links.
Cybercriminals are purchasing advertising space to promote their phishing sites so that they appear at the top of search engine results. Unsuspecting clients may click the first or second link that appears to them, assuming that it is a trustworthy website.
These fake advertisement links often look deceivingly close to the legitimate RBC URLs (such as www.rbcroyalbank.com or www.rbc.com ). Clicking a malicious link will redirect the victim to a phishing website, which may possibly result in the victim disclosing sensitive information. Red Flags to look out for:
Fraudsters continue to trick victims into entering credentials onto fake RBC websites. It is now common for phishing sites to be hidden behind a âCAPTCHAâ, which is a test to differentiate between humans and robots, commonly known as "I'm not a robot" test.
RBC does not use any CAPTCHA services as we use many other tools to identify and authorize you to keep your accounts safe. If you find yourself clicking or tapping on an RBC-related link and are faced with a CAPTCHA, do not go any further, and immediately close the website.
To help you spot phishing emails and fake websites, visit our Cyber site .
Subject line: RBC GIC special introduction rates
An email arrives in your inbox indicating itâs from an RBC employee and it has an RBC logo, promising special GICs rates. However, the email address doesnât look right, and they are asking for your personal information.
Example: The first result in this search looks very convincing. The link associated with the ad was a realistic-looking phishing site.
Fraudsters continue to impersonate RBC through many channels, including genuine-looking phishing websites. Scammers lure clients through malicious links in emails, text messages and search engine results, aiming to trick users into sharing sensitive information.
Cybercriminals are actively targeting RBC clients by taking out fake online advertisements to drive traffic to malicious websites. Known as âmalvertisingâ, these attacks target the web search results of highly visited websites, including popular ecommerce sites and financial institutions like RBC. Fraudsters aim to trick users into divulging sensitive information before the search engines can remove fake ads. Be careful when clicking on any link and stay alert for fake websites.
If you think youâve spotted a fake website or online advertising masquerading as RBC, copy and paste the website address or search result and email to [email protected] . Online advertising scams can also be reported directly to the search engine using tools for submitting violations.
Note: We receive large volumes of reports and are unable to provide personalized responses to emails sent to this email address.
The fraudulent text messages can be very convincing. This one claims an âonline accountâ has been âtemporarily lockedâ.
Cyber criminals continue to send fraudulent SMS (text) messages masquerading as RBC. Known as Smishing, a form of phishing , these texts are sent by fraudsters trying to trick people into providing personal or financial information.
Be alert for any text messages claiming to be from RBC â particularly those asking you to log into your RBC accounts or appearing to require urgent attention.
If you receive one of these messages:
Cyber criminals are continuing to use COVID-19 themed messages to harvest personal information and commit fraud. Their tactics continue to evolve, with the latest phishing emails focused on emergency financial support, employment and benefits programs, including the Canada Emergency Response Benefit (CERB) program.
+ 1 (306) 261-0789 Text Message Sunday 19:04 2020CRA.Reimbursement of 147.99$ (CAD) at; Https://3za912.com
Scammers are sending text messages  impersonating government revenue/taxation authorities and agencies, such as the Canada Revenue Agency (CRA) and Internal Revenue Service (IRS). Although taxation scams may be more frequent around tax-filing deadlines, they also continue throughout the year.
How to Recognize the Scam Text messages that claim to provide a tax reimbursement with a website link. Scammers are attempting to steal your personal information, such as:
Government taxation agencies will never contact taxpayers by email, text message, or social media requesting personal or financial information
This current tax-related scam is similar to past ones, such as a refund deposit, claiming you owe taxes, offering free tax preparation, or that your government identification or bank account is being suspended. See the past RBC alert, âPhishing Scam: Payment Receipt Advise.â
Cyber criminals are currently taking advantage of the COVID-19 pandemic by sending emails, texts and social media messages that contain phishing links  or malicious attachments.
Cyber criminals are impersonating governments, health authorities and other organizations to provide false information, steal information, sell fake medical products or tests and redirect to fake charity donations.
Visit known and reputable websites, like the official World Health Organizationâs Coronavirus disease (COVID-19) Pandemic page , or local health authorities like the Public Health Agency of Canada website  for correct up-to-date information on COVID-19.
For updated information on COVID-19 from RBC, please visit https://www.rbc.com/covid-19/index.html
Make sure you know how to protect your business .
Investors are being targeted by a scam using fake RBC Direct Investing branded websites. Cyber criminals are attempting to solicit members of the public to invest money in a questionable investment or one that doesn’t exist at all via websites that appear to be from RBC. Common tactics of the online investment scam include website spoofing (making a similar version of a trusted website), using social media to research and attract potential targets, and soliciting them through popular messaging platforms and/or email.
RBC Direct Investing has two legitimate websites:
If you are unsure whether a correspondence claiming to be from RBC is authentic, please contact us immediately.
If you have already invested in an offering you think may be fraudulent or you have been asked to pay additional money to get back money from an investment, we strongly recommend that you take steps to report the matter to your local law enforcement .
For secure ways to open an RBC Direct Investing account, Investors should contact RBC Direct Investing
Please visit the following links to seek guidance on how to protect yourself:
Recently, we sent an email to our valued RBC business clients asking them to update their email servers to a more secure encryption protocol. The Payment Card Industry Data Security Standard (PCI DSS) for safeguarding payment data now requires an encryption protocol which includes the Transport Layer Security (TLS) v1.1 or higher (TLS v1.2 is the RBC Standard). This update is needed to ensure our business clients have the right security measures in place to continue communicating safely and securely with RBC. The email was sent from RBC TLS Communication ( [email protected] ) on July 8. Below is what it looked like:
Get more details about this change on our TLS v1.2 FAQs page .
If you have any questions, please contact RBC's TLS Registration team at [email protected] .
A telephone scam targeting the Asian community has recently resurfaced. The fraudsters claim to be calling from RBC. The purpose of these calls is to trick clients into giving up personal information for fraudulent use. The caller may use social engineering tactics like threatening to close your account or insisting you update your account information to create a sense of urgency.
The calls appear to be coming from an RBC phone number: 1-888-769-2598. This is known as ‘call spoofing’ where a caller falsifies the number that appears on the recipient’s caller ID display. In this case, the fraudsters are trying to trick you into believing that RBC is calling.
If you accidentally share your banking information, contact us immediately.
Become your best defence against cyber criminals. Visit rbc.com/cyber for more tips on how to keep your personal information secure.
RBC clients are the target of new phishing scam. The suspicious email, appearing to come from RBC, is a direct deposit notice indicating that the Canada Revenue Agency has recently put money into your RBC account. The email includes an attachment.
Pay attention to the sender and their email address.
The email's contents can also offer clues.
If you receive a suspicious email, appearing to come from RBC, forward it to [email protected] and then delete it right away. Even if you didn’t click on the link or download any attachments, it’s important that our cyber security experts are aware of these types of scams.
RBC clients are the target of another text-messaging scam . The text messages warn clients that their cards have been disabled, and that they must click on a link or call a phone number in order to secure their account.
If you receive one of these text messages, we strongly urge you not to click on the link, and to contact us directly using the contact numbers on the back of your client card or on our site rather than the number provided in the text message.
Clients have also received text messages instructing them to call a phone number to receive an important message. These messages are also fraudulent. DO NOT call the number provided, instead use the contact numbers found on the back of your RBC client card or on our site .
The scam appears to be limited to Canadian clients, but US or Caribbean clients may be targeted too. If you have received a text message from a number you don’t recognize, delete the message right away. If you believe your confidential information may have been stolen or obtained by a fraudulent party either online, by telephone or through any other means, contact us immediately.
Several calls, designed to appear as though they are coming from RBC, have been made to RBC clients across Canada in order to retrieve personal or financial information. No RBC systems have been compromised, and we have escalated this issue to Canadian telephone carriers, who are working to remediate the situation.
What is Caller ID Spoofing?
Caller ID spoofing is when a caller deliberately falsifies the information transmitted to an individual’s caller ID display to disguise their identity.
Protect Yourself from Spoofing
Spoofing is often used as part of an attempt to trick someone into giving away valuable personal information so it can be used in fraudulent activity or sold.
Spoofing is a social engineering scam that relies on psychological manipulation tactics. Websites, phone numbers, email addresses, and various other communication methods can be spoofed.
As this is a Canada-wide scam that involves a wide range of corporate and personal phone numbers, here are some additional tips to protect yourself from caller ID spoofing:
If you believe your confidential information may have been stolen or obtained by a fraudulent party either online, by telephone or through any other means, call us immediately.
If you think you are a victim of identity fraud and you are an RBC client
If you have received a suspicious email or accessed a fraudulent RBC website