A voice that sounds exactly like your CFO calls your bookkeeper and asks for an urgent wire transfer. An invoice from a supplier you've used for years arrives looking completely normal, except the banking details have changed. Neither of these needs a skilled hacker anymore — just a few minutes of publicly available audio or a document template and free AI tools.

That shift is no longer theoretical. In 2026, KPMG Canada found that most businesses hit by fraud were hit by an AI-enabled version of it, and most of them weren't ready. Here's what the numbers actually say, and what an Ontario small business can do about it without hiring a security team.

Key Takeaways

  • In 2026, 72% of Canadian businesses lost between 1% and 5% of annual profit to AI-powered fraud in the past 12 months (KPMG Canada, February 2026).
  • Among businesses that experienced fraud at all, 81% say it was AI-enabled, and 72% of those were targeted more than once.
  • The three leading attack types are AI-generated phishing (60%), deepfake documents (39%), and voice-clone executive impersonation (24%).
  • Only 26% of businesses have a tested, formal fraud response plan that explicitly covers AI-powered attacks — while 94% say they're concerned about future attacks.
  • KPMG's sample skews toward mid-size and larger firms, so these figures describe the broader Canadian business population, not small businesses specifically — a caveat worth keeping in mind.
72% Profit Lost Canadian businesses that lost 1-5% of annual profit to AI-powered fraud in the past 12 months (KPMG)
81% AI-Enabled Share of fraud victims where the attack involved AI-generated content or tools
26% Have a Plan Businesses with a tested, formal response plan covering AI-powered fraud

What Does "AI-Powered Fraud" Actually Look Like in 2026?

In 2026, KPMG Canada's fraud survey found that AI-generated phishing emails and chat messages are the leading attack type, hitting 60% of businesses that experienced fraud (KPMG Canada, March 2026). It isn't the clumsy, typo-riddled scam email of five years ago. It reads like a real colleague wrote it, because an AI model trained on scraped writing samples did.

Deepfake or manipulated documents come next at 39%, followed by voice-clone calls impersonating an executive at 24%. Isn't it worth asking which of your own vendor or payroll processes would actually catch a perfectly-worded fake invoice or a familiar-sounding voice on the phone? For most small teams, the honest answer is: not reliably.

AI Fraud Attack Types Among Affected Canadian Businesses, 2026 AI Fraud Attack Types Among Affected Businesses AI-generated phishing 60% Deepfake documents 39% Voice-clone impersonation 24% Source: KPMG Canada, "Fraud in the Age of AI," survey of 251 Canadian business leaders, Feb 4-13, 2026
Percentages are shares of businesses that experienced AI-powered fraud; a single business can report more than one attack type.
Computer screen displaying a virus warning, representing AI-generated phishing and malware threats facing Canadian businesses

How Much Is AI Fraud Actually Costing Canadian Businesses?

In 2026, 72% of Canadian businesses lost between 1% and 5% of annual profit to AI-powered fraud over the previous 12 months, and 94% expect the risk to grow (KPMG Canada, March 2026). Among the 81% of fraud victims where the attack was AI-enabled, 72% were targeted more than once — this isn't a single bad month, it's a repeat cost line.

Here's the detail that gets lost in the headline numbers: KPMG's 251 respondents skew toward mid-size and large companies, with 55 firms in the $300M–$1B range and nearly a quarter over $1B in revenue. Only 50% were Ontario-based, and none of the published breakdown isolates businesses under, say, $10M in revenue. So the 72% figure describes the broader Canadian business population that KPMG surveyed — not small businesses specifically. It would be misleading to claim this data proves small Ontario businesses are losing exactly this much. What KPMG's own commentary does say is that smaller companies tend to be more exposed, precisely because they lack the dedicated fraud-detection budgets larger firms are starting to build.

Reading this data honestly: KPMG's survey (n=251) is weighted toward companies with $50M+ in revenue, so treat the 72%/81% figures as directional evidence that AI fraud is widespread and costly across the Canadian business landscape — not as a small-business-specific statistic. The underlying risk (phishing, deepfakes, voice cloning) applies regardless of company size; the exposure may simply differ.
Businessman looking annoyed and stressed while on a phone call, representing the pressure tactics used in voice-clone executive impersonation scams

Why Are So Few Businesses Prepared for AI Fraud?

Only 26% of Canadian businesses have implemented and tested a formal fraud response plan that explicitly covers AI-powered attacks, even though 94% say they're concerned about facing one in the next year (KPMG Canada, February 2026). That's a wide gap between worry and readiness, and it's exactly the gap fraud relies on.

Concern alone doesn't stop a wire transfer. A written, tested plan does — because it tells whoever picks up the phone exactly what to check before moving money, rather than leaving them to make a judgment call under pressure from someone who sounds like their boss.

The Concern-vs-Preparedness Gap in AI Fraud Response, 2026 Concerned, But Not Ready 26% have a tested plan 26% — tested AI fraud response plan 74% — no tested plan in place 94% are concerned about future attacks Source: KPMG Canada, "Fraud in the Age of AI," February 2026
Nearly all businesses see AI fraud coming; fewer than 3 in 10 have actually written and tested a plan for it.

For a broader look at the risks and rules around AI adoption itself, see our guide to PIPEDA-compliant AI tools for Ontario small businesses — a related but distinct question, since that piece covers the privacy compliance of AI tools you choose to use, while this one covers AI being used against you by someone else.

Voice Clones and Deepfake Documents: How Business Email Compromise Evolved

Business email compromise used to rely on a spoofed email address and a plausible story. In 2026, it can rely on a cloned voice built from a few seconds of a real executive's public audio — a conference talk, a podcast interview, even a company video — and a script generated to match how that person actually talks.

The Setup

Fraudsters scrape public audio or video of a company's owner, CFO, or another decision-maker — often from LinkedIn, YouTube, or a company website — and feed it into a voice-cloning tool.

The Pressure Call

An employee, often in finance or accounts payable, gets a call that sounds exactly like their boss, requesting an urgent wire transfer or a change to vendor banking details before day's end.

The Supporting "Proof"

A deepfake document — an invoice, a signed authorization, or an email thread — often follows to make the request look procedurally normal, which is why 39% of AI fraud cases involve fabricated documents.

The Money Moves

Once a transfer clears, it's usually gone. Unlike a card chargeback, a wire fraud recovery depends on catching it within hours, which is why prevention matters more than response here.

None of this requires the fraudster to know your business well. It requires only that your process for verifying an unusual request is weaker than their script — which, for most small teams without a written policy, it currently is.

What Should an Ontario Small Business Actually Do About This?

The good news: the highest-leverage defenses here don't cost much. KPMG found that 74% of businesses plan to invest in AI-powered detection technology and 72% in employee training, but a small business doesn't need to wait for budget approval to fix the biggest gap — the missing verification step (KPMG Canada, March 2026).

Where Canadian Businesses Are Investing Fraud-Prevention Budget Planned Fraud-Prevention Investment Detection technology 74% Employee training 72% Transaction controls 60% Already using AI defenses 52% Source: KPMG Canada, "Fraud in the Age of AI," February 2026
Detection technology tops the investment list, but transaction controls and training are the two a small team can implement without new software.

Require Callback Verification for Money Movement

Never action a wire transfer, password reset, or vendor-banking change based on a voice or email request alone. Confirm it on a second, previously known channel — call the person back on the number already saved in your system, not one provided in the request.

Write Down Your Response Plan

Only 26% of businesses have a tested plan. A one-page document naming who approves unusual transfers, who to call if something looks off, and what to freeze first, costs nothing and closes most of that gap.

Train Whoever Touches Payments

Anyone who can move money or change vendor details should know what a voice-clone or deepfake-document attempt looks like. A 20-minute conversation with your accounts team is a start; formal training is the target 72% of businesses are already funding.

Add a Second Approver on Large Transfers

A simple dual-authorization rule above a set dollar threshold stops most single-point-of-failure scams, whether the request came from a real hacked email or a convincing fake.

Building an AI strategy for your business shouldn't skip the defensive side of the equation. If you haven't yet mapped out how your team uses AI day to day, our guide on building an AI strategy for a 10-person Canadian company is a useful starting point, and our piece on whether your business actually needs an AI agent covers the adjacent question of how much AI autonomy to hand your own operations.

Frequently Asked Questions: AI Fraud and Small Business

What percentage of Canadian businesses have been hit by AI-powered fraud?

72% of Canadian businesses lost between 1% and 5% of annual profit to AI-powered fraud in the past 12 months. Among businesses that experienced fraud at all, 81% say the attack involved AI-generated content or tools (KPMG Canada, survey of 251 business leaders, February 2026).

What is the most common type of AI-powered fraud businesses face?

AI-generated phishing emails and chat messages are the most common, hitting 60% of affected businesses. Deepfake or manipulated documents follow at 39%, and voice-clone calls impersonating executives affect 24% (KPMG Canada, February 2026).

Are small businesses in Ontario specifically at risk from AI fraud?

KPMG's survey skewed toward mid-size and large firms, with half its 251 respondents based in Ontario, so the 72% profit-loss figure isn't small-business-specific. But KPMG's own commentary flags smaller firms as more exposed, since they typically lack dedicated fraud-detection tools or a formal verification process.

What is a voice-clone or deepfake fraud attack?

A voice-clone attack uses AI to mimic a real executive's voice, often from short public audio clips, to call an employee and authorize an urgent wire transfer or credential reset. Deepfake document fraud fabricates invoices, contracts, or ID documents that appear legitimate.

How can a small business protect itself from AI-powered fraud without a big security budget?

The highest-leverage, lowest-cost step is a callback verification rule: never action a wire transfer, password reset, or vendor-banking change from a voice or email request alone. Only 26% of businesses have a tested, formal response plan covering AI-enabled fraud, so writing one down costs nothing but time.

AI fraud isn't a future risk for Canadian businesses — 72% have already paid for it in lost profit, and 94% expect it to keep coming. The businesses least prepared aren't the ones without a security budget; they're the ones without a written rule for verifying an unusual request before the money moves. That rule is free to write today.

Ritesh Watts

Founder & CEO, Watts Group

Ritesh Watts leads Watts Group's consulting and business-building work with immigrant and newcomer entrepreneurs across Ontario, from incorporation through day-to-day operations. He draws on 18 years of building businesses in Canada as an immigrant founder himself, across multiple verticals and economic cycles.