is that a scam?
← Back to all scams
CRITICAL phishing Last reported: Oct 3, 2026 Share

A text or email links to a fake Scotiabank, RBC, or TD login page that steals your banking credentials

A phishing SMS or email links to a fake Canadian bank site that looks real. You enter your credentials and OTP; the scammer logs in immediately and transfers funds. Over 14 Canadian banks have been impersonated this way.

Also known as: fake Scotiabank login page Canada, fake RBC phishing site Canada, Canadian bank smishing link, fake TD online banking login phishing, CIBC BMO Desjardins phishing page, bank account suspended text scam Canada, Canadian bank credential theft

What to do right now

  1. 1 Do not click links in unexpected banking texts or emails — go directly to your bank's site by typing the domain into your browser, or use the official app
  2. 2 Check the URL before entering any information: it must be exactly scotiabank.com, rbc.com, td.com, cibc.com, or bmo.com — no extra words or hyphens
  3. 3 If you already entered credentials: call your bank immediately using the number on the back of your card and ask them to flag for unauthorized access and lock your account
  4. 4 If a transfer occurred: your bank may be able to recall it if reported the same business day — call and also file with CAFC immediately
  5. 5 Enable push notifications for all banking transactions — immediate alerts give you the fastest window to recall any transfer
  6. 6 Report phishing texts by forwarding to 7726 (SPAM) and the suspicious URL to the Canadian Centre for Cyber Security at cccs.gc.ca
  7. 7 Report to the Canadian Anti-Fraud Centre at https://antifraudcentre-centreantifraude.ca or call 1-888-495-8501.

Red flags

  • ⚠ A text or email claims your account is suspended, a suspicious login was detected, or urgent verification is needed — then provides a link to 'sign in'
  • ⚠ The URL in the message or page is NOT the bank's real domain (scotiabank.com, rbc.com, td.com, cibc.com, bmo.com) — it contains extra words like 'auth,' 'webform,' 'authentication,' or 'secure-' around the bank name
  • ⚠ You are asked to enter your online banking username, password, AND a one-time passcode — providing all three allows real-time account takeover
  • ⚠ The message creates urgency — 'your account will be locked within 24 hours' — real banks send notices by mail or in-app, not with ultimatums by SMS
  • ⚠ The sender number looks like a real Canadian phone number or appears to come from a short code — SMS spoofing and SIM-based routing are trivial for criminals
  • ⚠ After entering your credentials the site shows a 'processing' or 'verification' page — it is relaying your details to the scammer in real time

Known variants

  • AITM (adversary-in-the-middle) proxy variant: the fake page relays credentials AND the OTP to the scammer in real time, defeating SMS-based 2FA. Victim sees a 'processing' screen while scammer logs in with the live session.

    Last seen: 9/22/2026

  • SMS blaster variant: a device impersonates a cell tower and delivers fake bank texts that appear in the same thread as genuine bank messages, bypassing sender-ID checks. Toronto Police arrested a three-person crew in April 2026 after 13M+ network disruptions — Canada's first known case.

    Last seen: 9/22/2026

  • Caller ID spoofing + OTP relay: scammer calls from a spoofed bank or fintech number (Wealthsimple, RBC, TD), reports a suspicious transaction, triggers an OTP SMS, and asks victim to read it back — completing live account takeover. Never read an OTP aloud to any caller.

    Last seen: 10/2/2026

Sources

Share this with someone who might need it