A voice that sounds exactly like your CFO calls your bookkeeper and asks for an urgent wire transfer. An invoice from a supplier you've used for years arrives looking completely normal, except the banking details have changed. Neither of these needs a skilled hacker anymore — just a few minutes of publicly available audio or a document template and free AI tools.
That shift is no longer theoretical. In 2026, KPMG Canada found that most businesses hit by fraud were hit by an AI-enabled version of it, and most of them weren't ready. Here's what the numbers actually say, and what an Ontario small business can do about it without hiring a security team.
Key Takeaways
- In 2026, 72% of Canadian businesses lost between 1% and 5% of annual profit to AI-powered fraud in the past 12 months (KPMG Canada, February 2026).
- Among businesses that experienced fraud at all, 81% say it was AI-enabled, and 72% of those were targeted more than once.
- The three leading attack types are AI-generated phishing (60%), deepfake documents (39%), and voice-clone executive impersonation (24%).
- Only 26% of businesses have a tested, formal fraud response plan that explicitly covers AI-powered attacks — while 94% say they're concerned about future attacks.
- KPMG's sample skews toward mid-size and larger firms, so these figures describe the broader Canadian business population, not small businesses specifically — a caveat worth keeping in mind.
What Does "AI-Powered Fraud" Actually Look Like in 2026?
In 2026, KPMG Canada's fraud survey found that AI-generated phishing emails and chat messages are the leading attack type, hitting 60% of businesses that experienced fraud (KPMG Canada, March 2026). It isn't the clumsy, typo-riddled scam email of five years ago. It reads like a real colleague wrote it, because an AI model trained on scraped writing samples did.
Deepfake or manipulated documents come next at 39%, followed by voice-clone calls impersonating an executive at 24%. Isn't it worth asking which of your own vendor or payroll processes would actually catch a perfectly-worded fake invoice or a familiar-sounding voice on the phone? For most small teams, the honest answer is: not reliably.
How Much Is AI Fraud Actually Costing Canadian Businesses?
In 2026, 72% of Canadian businesses lost between 1% and 5% of annual profit to AI-powered fraud over the previous 12 months, and 94% expect the risk to grow (KPMG Canada, March 2026). Among the 81% of fraud victims where the attack was AI-enabled, 72% were targeted more than once — this isn't a single bad month, it's a repeat cost line.
Here's the detail that gets lost in the headline numbers: KPMG's 251 respondents skew toward mid-size and large companies, with 55 firms in the $300M–$1B range and nearly a quarter over $1B in revenue. Only 50% were Ontario-based, and none of the published breakdown isolates businesses under, say, $10M in revenue. So the 72% figure describes the broader Canadian business population that KPMG surveyed — not small businesses specifically. It would be misleading to claim this data proves small Ontario businesses are losing exactly this much. What KPMG's own commentary does say is that smaller companies tend to be more exposed, precisely because they lack the dedicated fraud-detection budgets larger firms are starting to build.
Why Are So Few Businesses Prepared for AI Fraud?
Only 26% of Canadian businesses have implemented and tested a formal fraud response plan that explicitly covers AI-powered attacks, even though 94% say they're concerned about facing one in the next year (KPMG Canada, February 2026). That's a wide gap between worry and readiness, and it's exactly the gap fraud relies on.
Concern alone doesn't stop a wire transfer. A written, tested plan does — because it tells whoever picks up the phone exactly what to check before moving money, rather than leaving them to make a judgment call under pressure from someone who sounds like their boss.
For a broader look at the risks and rules around AI adoption itself, see our guide to PIPEDA-compliant AI tools for Ontario small businesses — a related but distinct question, since that piece covers the privacy compliance of AI tools you choose to use, while this one covers AI being used against you by someone else.
Voice Clones and Deepfake Documents: How Business Email Compromise Evolved
Business email compromise used to rely on a spoofed email address and a plausible story. In 2026, it can rely on a cloned voice built from a few seconds of a real executive's public audio — a conference talk, a podcast interview, even a company video — and a script generated to match how that person actually talks.
The Setup
Fraudsters scrape public audio or video of a company's owner, CFO, or another decision-maker — often from LinkedIn, YouTube, or a company website — and feed it into a voice-cloning tool.
The Pressure Call
An employee, often in finance or accounts payable, gets a call that sounds exactly like their boss, requesting an urgent wire transfer or a change to vendor banking details before day's end.
The Supporting "Proof"
A deepfake document — an invoice, a signed authorization, or an email thread — often follows to make the request look procedurally normal, which is why 39% of AI fraud cases involve fabricated documents.
The Money Moves
Once a transfer clears, it's usually gone. Unlike a card chargeback, a wire fraud recovery depends on catching it within hours, which is why prevention matters more than response here.
None of this requires the fraudster to know your business well. It requires only that your process for verifying an unusual request is weaker than their script — which, for most small teams without a written policy, it currently is.
What Should an Ontario Small Business Actually Do About This?
The good news: the highest-leverage defenses here don't cost much. KPMG found that 74% of businesses plan to invest in AI-powered detection technology and 72% in employee training, but a small business doesn't need to wait for budget approval to fix the biggest gap — the missing verification step (KPMG Canada, March 2026).
Require Callback Verification for Money Movement
Never action a wire transfer, password reset, or vendor-banking change based on a voice or email request alone. Confirm it on a second, previously known channel — call the person back on the number already saved in your system, not one provided in the request.
Write Down Your Response Plan
Only 26% of businesses have a tested plan. A one-page document naming who approves unusual transfers, who to call if something looks off, and what to freeze first, costs nothing and closes most of that gap.
Train Whoever Touches Payments
Anyone who can move money or change vendor details should know what a voice-clone or deepfake-document attempt looks like. A 20-minute conversation with your accounts team is a start; formal training is the target 72% of businesses are already funding.
Add a Second Approver on Large Transfers
A simple dual-authorization rule above a set dollar threshold stops most single-point-of-failure scams, whether the request came from a real hacked email or a convincing fake.
Building an AI strategy for your business shouldn't skip the defensive side of the equation. If you haven't yet mapped out how your team uses AI day to day, our guide on building an AI strategy for a 10-person Canadian company is a useful starting point, and our piece on whether your business actually needs an AI agent covers the adjacent question of how much AI autonomy to hand your own operations.
Frequently Asked Questions: AI Fraud and Small Business
What percentage of Canadian businesses have been hit by AI-powered fraud?
72% of Canadian businesses lost between 1% and 5% of annual profit to AI-powered fraud in the past 12 months. Among businesses that experienced fraud at all, 81% say the attack involved AI-generated content or tools (KPMG Canada, survey of 251 business leaders, February 2026).
What is the most common type of AI-powered fraud businesses face?
AI-generated phishing emails and chat messages are the most common, hitting 60% of affected businesses. Deepfake or manipulated documents follow at 39%, and voice-clone calls impersonating executives affect 24% (KPMG Canada, February 2026).
Are small businesses in Ontario specifically at risk from AI fraud?
KPMG's survey skewed toward mid-size and large firms, with half its 251 respondents based in Ontario, so the 72% profit-loss figure isn't small-business-specific. But KPMG's own commentary flags smaller firms as more exposed, since they typically lack dedicated fraud-detection tools or a formal verification process.
What is a voice-clone or deepfake fraud attack?
A voice-clone attack uses AI to mimic a real executive's voice, often from short public audio clips, to call an employee and authorize an urgent wire transfer or credential reset. Deepfake document fraud fabricates invoices, contracts, or ID documents that appear legitimate.
How can a small business protect itself from AI-powered fraud without a big security budget?
The highest-leverage, lowest-cost step is a callback verification rule: never action a wire transfer, password reset, or vendor-banking change from a voice or email request alone. Only 26% of businesses have a tested, formal response plan covering AI-enabled fraud, so writing one down costs nothing but time.
AI fraud isn't a future risk for Canadian businesses — 72% have already paid for it in lost profit, and 94% expect it to keep coming. The businesses least prepared aren't the ones without a security budget; they're the ones without a written rule for verifying an unusual request before the money moves. That rule is free to write today.