Canada · Bank disputes · CAFC and OBSI · 25 min read

How to Try to Recover Money After a Scam in Canada

A Canadian scam loss can sometimes be stopped, reversed, reimbursed or compensated, but there is no single national rule that refunds every payment made under deception. The correct first move is to contact the financial institution that sent the money, identify whether the transaction was unauthorized or personally authorized, and use the procedure for the actual payment product. An unauthorized card purchase, an account-takeover e-Transfer, a voluntary e-Transfer to a fake seller, a pre-authorized debit and a credit-card purchase all raise different questions. Report the crime to local police and through the national Report Cybercrime and Fraud service, preserve the case number, and escalate a bank complaint to OBSI when the federal banking complaint process allows it. The dates below are product- and institution-specific; they are not a promise that reporting by a deadline guarantees recovery.

01Federal bank and OBSI stages separated
02Interac authorisation and account takeover treated differently
03Every deadline tied to the product it governs
Immediatelycontact the sending institutionask it to stop or recall funds where possible
30 dayscommon deposit-account notice periodusually from the statement date; the agreement may differ
56 daysfederal bank complaint stagemeasured from the bank’s receipt of the complaint
180 daysusual OBSI referral periodafter the institution’s final response
Sources for the introduction, figures and summary

The direct answer: start with the payment, not a recovery promise

Direct answer: Contact the institution that moved the money at once, report the precise transaction type and authorisation facts, preserve evidence, make the official reports, and use the bank-to-OBSI complaint route if the institution’s decision remains disputed.

The phrase ‘scammed money’ covers legally different events. A criminal may use stolen credentials to initiate a transfer without the customer’s approval. A customer may personally send an Interac e-Transfer because a fake seller promised concert tickets. A card may be used without permission, or the cardholder may knowingly pay a fake investment merchant that supplies nothing. A company may continue taking a pre-authorized debit after the authorization was cancelled. Each event can be fraudulent in everyday language, but a bank investigates it under a different agreement, network rule or federal consumer provision.

Create a payment inventory before making a long argument. For every loss, record the date, amount, sending product, recipient, reference, whether you pressed the final confirmation, and how the criminal obtained access or induced the payment. State plainly if you gave a one-time code, installed remote-access software or followed instructions while logged in. Those facts can be uncomfortable, but hiding them usually damages the claim when technical records emerge. The Financial Consumer Agency of Canada says an institution must investigate an unauthorized transaction and consider all relevant factors before finding a customer responsible; the technology used is not the whole test.

Recovery has several meanings. A bank may stop a pending transfer, obtain a voluntary return from the receiving institution, reverse an unauthorized debit, process a card chargeback, reimburse under a consumer-protection rule, or pay compensation after a complaint. Police may later restrain proceeds. These are separate outcomes. CAFC reporting helps connect intelligence but does not itself order a refund. OBSI can investigate eligible complaints about a participating firm, but it does not prosecute the criminal. A credible guide keeps those functions distinct.

Choose the first Canadian route by transaction
TransactionFirst requestCentral distinction
Interac e-Transfer you sentFraud report and urgent recipient-bank contactAuthorised under deception or account takeover
Card use you did not approveUnauthorised-transaction disputeNotice, authentication and customer conduct
Card purchase from a fake merchantMerchant contact and chargeback assessmentReason code and evidence of non-performance or fraud
Pre-authorized debitPAD refund requestNo authority, wrong amount/date or debit after cancellation
Wire or other transferStop/recall request and fraud escalationPayment status and receiving institution

The first hour: contain the loss and create a reliable record

Direct answer: Call the financial institution through a verified channel, stop further access, ask for a transaction recall or recipient-bank alert, and obtain a reference before moving on to the police and CAFC reports.

Use the number in the official app, on the card or on the institution’s independently located website. Do not continue through a number supplied in the scam conversation. Say whether money has left, is pending, or is merely scheduled. Ask the fraud team to note the receiving account and contact the receiving institution. A completed transfer may be difficult to reverse, yet quick notification can matter if funds remain in a controlled account. Do not wait to assemble a perfect dossier before making that first call.

Secure the channel that was compromised. Change online-banking and email passwords from a clean device, end active sessions, remove unrecognized devices and tell the institution if remote-access software was installed. If the criminal obtained identity documents, ask the institution to flag all affected accounts. CAFC also directs identity-fraud victims to contact both Equifax and TransUnion. Keep the original device and messages where safe; indiscriminate deletion can remove evidence needed to explain how access occurred.

Write a same-day chronology while memory is fresh. Include the caller’s claimed identity, numbers and handles, links, names shown on transfers, security warnings, one-time codes requested, and each conversation with the bank. Note the case number and the employee or department, not private information about staff. Save receipts, email headers, exported chats and statement records. A chronological file lets the bank, police and later ombudsman see the same facts instead of three inconsistent summaries created weeks apart.

  1. 01
    Notify the institution

    Report the scam, identify the transactions and ask for immediate containment and recipient-bank contact.

  2. 02
    Lock down access

    Change credentials, end sessions and disclose remote access or stolen identity information.

  3. 03
    Preserve evidence

    Export messages, statements, receipts, adverts, websites and the warnings displayed during payment.

  4. 04
    Report to police

    Contact local police and keep the file number.

  5. 05
    Report nationally

    Use Report Cybercrime and Fraud and update the report if material facts change.

Authorized and unauthorized transactions are not interchangeable

Direct answer: An unauthorized transaction is one the customer did not make or approve; a payment personally confirmed because of a lie may still be a scam, but it is not automatically covered by unauthorized-transaction protections.

FCAC defines an unauthorized transaction as one that the account holder did not make or approve, while noting that definitions can vary by institution. Account takeover, stolen card credentials and a forged debit can fit that route. In contrast, a person who enters a recipient, amount and confirmation code after speaking to an impostor has usually participated in the instruction. The deception remains relevant to police, recovery efforts and complaints about the bank’s conduct, but it does not erase the technical authorisation step.

Describe control of the device and credentials in detail. Did the criminal operate the screen through remote software? Did the customer read out a code, or did the criminal receive it on a changed phone number? Was a new payee added? Did the institution send a notification? Did the customer contact the bank before later transactions? A bank cannot fairly decide a complex takeover solely by saying the correct password was used. Conversely, the customer should not claim never to have approved a transfer if they knowingly pressed confirm.

The distinction also controls deadlines. FCAC says deposit-account agreements usually require an unauthorized transaction to be disputed within 30 days after the statement date, although the agreement may set a different period. A credit-card dispute and a PAD refund have their own rules. Report immediately even if you think an outer period remains. The notice deadline preserves a route; it does not keep recipient funds stationary or guarantee that the institution will classify the payment as unauthorized.

Interac e-Transfer: account takeover and purchase scam routes

Direct answer: An Interac e-Transfer initiated through account takeover should be disputed as unauthorized, while a transfer the customer deliberately sent to a fraudster usually requires urgent recovery action and a conduct-based complaint rather than assumed buyer protection.

Interac e-Transfer is often experienced as instant and informal, which can hide the legal importance of authorisation. If credentials were phished and the criminal initiated transfers, tell the bank exactly which actions you did not perform. Preserve the fake notification or login page and the legitimate security alerts. If you sent money to a fake marketplace seller, ticket seller, landlord or investment contact, say that the recipient and bargain were fraudulent, but acknowledge that you initiated the payment. OBSI has warned in its educational material that an authorised e-Transfer does not carry purchaser protection simply because the underlying transaction was fraudulent.

Ask the sending bank to contact the receiving institution promptly, mark the recipient details and attempt recovery. Provide the recipient email or mobile number, displayed name, reference, security-question details if used, and confirmation number. Do not contact the recipient to negotiate through a new channel if doing so risks further payment or evidence loss. If the fraudster says a refund is pending but needs a fee, stop. A real return does not require the victim to increase a transfer limit or send another e-Transfer.

If the bank refuses reimbursement, separate two questions. First, could it recover money remaining in the recipient account? Second, did it handle the sending account, warnings, authentication, report and investigation fairly and according to the agreement? OBSI reviews the conduct of the participating financial firm, not the criminal or the marketplace. Frame the complaint around a provable bank act or omission rather than asserting that Interac gives a universal right to reverse a completed authorised transfer.

  • Give the bank the exact e-Transfer confirmation and recipient identifier.
  • State who operated the account and who pressed confirm.
  • Ask for receiving-institution contact and a recovery attempt.
  • Request a written investigation outcome and the agreement terms applied.
  • Escalate eligible bank-conduct issues, not a dispute with the scammer, to OBSI.

Unauthorized debit and account transactions

Direct answer: Report an unauthorized debit or account transaction immediately; the institution must investigate relevant facts, and debit-card losses outside the customer’s control should not be assigned to the customer under the applicable protections.

FCAC instructs customers to change the affected PIN or password, notify the institution or card issuer, dispute the transaction, review their credit report and monitor accounts. The institution should look at the circumstances before finding the customer at fault, regardless of the authentication technology used. Relevant facts can include how credentials were obtained, normal account activity, device information, the timing of alerts, the customer’s report and whether the bank followed its own security process.

For debit-card losses, FCAC states that a customer should not be responsible for losses resulting from circumstances beyond their control. Where liability is assigned, the maximum is typically linked to withdrawal limits, although linked overdraft or credit facilities can change exposure. Do not convert that summary into a blanket promise. The institution’s agreement and the exact events still matter. A customer who voluntarily disclosed credentials may face a disputed finding, but the institution must assess the full record rather than cite one fact in isolation.

Put the dispute in writing after the urgent telephone report. Identify each transaction, state that it was not made or approved, describe the compromise, and ask for provisional or final treatment available under the account terms. Keep the date the statement became available because the common 30-day deposit-account notice period runs from the statement, not necessarily the transaction. If the institution uses a different contractual period, ask it to quote the clause.

Unauthorized-transaction file
QuestionUseful recordWhy it matters
Who controlled the account?Device and session history, remote-access factsDistinguishes takeover from customer instruction
When was notice given?Call reference, secure message, branch receiptTests prompt reporting
What authentication occurred?Alerts, code delivery, payee creationPrevents a password-only conclusion
What did the bank do?Investigation letter and agreement clausesCreates a reviewable complaint record

Credit-card fraud, chargeback and merchant disputes

Direct answer: Use an unauthorized-use dispute when you did not approve the card transaction, and ask for a chargeback assessment when you made the purchase but the merchant was fraudulent, did not deliver or materially misrepresented the service.

FCAC states that maximum liability for an unauthorized credit-card transaction is generally $50 unless the cardholder was grossly negligent. It also notes public zero-liability commitments from major card networks. Those protections concern unauthorized use; they do not automatically cover a purchase the cardholder made after believing a false investment, seller or service. Tell the issuer whether the card itself was used without consent or whether the dispute concerns what the merchant promised and supplied.

OBSI’s chargeback approach lists unauthorized use, billing errors, undelivered or not-as-described goods and merchant fraud among possible dispute reasons. It says consumers should first try the merchant where appropriate and then provide the issuer with the statement, receipt, contract or invoice, correspondence and reasons for alleging fraud. OBSI describes a general 30-to-45-day period from the statement for raising disputes, while stressing that agreements and card-network rules control. There is no safe universal deadline for every reason, so report immediately and ask the issuer for the exact deadline applied.

A fake investment platform can create an additional complication: the statement merchant may be a genuine crypto exchange or payment processor that supplied exactly what the cardholder ordered, even though the purchased asset was later sent to a criminal. A chargeback against that intermediary is not automatically valid. Map the card purchase and the onward transfer as separate legs. Ask the issuer to assess the correct reason rather than presenting the intermediary as the scammer without evidence.

  1. 01
    Classify the card event

    State whether use was unauthorized or the authorised purchase was not delivered or was misrepresented.

  2. 02
    Contact the merchant where safe

    Request cancellation or refund and retain the answer or non-response.

  3. 03
    Notify the issuer promptly

    Give the transaction, dispute reason and supporting documents.

  4. 04
    Ask for the rule used

    Request the deadline, reason code and written result if the claim is declined.

Pre-authorized debit has a distinct 90-day refund route

Direct answer: A customer can generally report an unauthorized, incorrectly dated, incorrectly valued or post-cancellation pre-authorized debit and request reimbursement within 90 calendar days of the withdrawal.

A PAD is not the same as a card payment or an e-Transfer. It is a debit made under an authorization given to a biller or merchant. FCAC says a customer usually has 90 calendar days from the withdrawal to report a PAD that was unauthorized, made on the wrong date, taken for the wrong amount or continued after the underlying agreement was cancelled. The financial institution can require a signed declaration. After 90 days, it does not have to reimburse under that process.

Preserve the PAD agreement, cancellation notice, account statement and any merchant response. Identify the exact defect. ‘The company is a scam’ is less operationally useful than ‘I never signed a PAD agreement’, ‘the authorized amount was $80 and $800 was withdrawn’, or ‘the merchant received cancellation on this date and debited again later’. Ask the institution to reverse related fees caused by the incorrect debit; FCAC suggests raising those incidental charges as part of the request.

Do not quote the PAD 90-day period for an ordinary transfer between accounts, a card purchase or an Interac payment. Product names in online banking can be confusing, so ask the institution how the transaction was coded. If a supposed subscription used a card-on-file rather than a PAD, the card dispute rules apply. Correct classification is often the difference between reaching the right operations team and receiving a generic refusal.

Police, CAFC and identity-recovery reports have different jobs

Direct answer: Report the crime to local police for a police file, submit the national cybercrime and fraud report for intelligence coordination, and separately secure identity and credit records where personal information was exposed.

CAFC’s victim guidance tells victims to gather documents and receipts, contact the financial institution that transferred the money, contact local police and obtain a file number, and report through Report Cybercrime and Fraud. The national report can be useful to institutions and investigators, but it is not a substitute for the bank’s fraud notice or a guarantee that an officer will investigate an individual case. Give the bank both the police and national report references once available.

If identity information was taken, place flags on affected accounts, change passwords and contact both Canadian credit bureaus. Review the credit files for unfamiliar inquiries or accounts. Contact the relevant government issuer where an identity document or account was compromised. Avoid sending a full identity pack repeatedly by ordinary email. Ask each recipient which secure upload channel and minimum documentation it requires.

Update reports when the scam evolves. A recovery approach, new beneficiary, additional domain or attempted account access may connect cases. Keep a change log rather than submitting inconsistent fresh stories. Report abuse to the platform that hosted the profile or website, but preserve evidence first. A platform takedown can protect others while also removing material you need for the bank complaint.

  • Bank report: containment, investigation and payment dispute.
  • Local police report: criminal occurrence and police file number.
  • National report: CAFC and RCMP fraud intelligence.
  • Credit bureaus: fraud alert and credit-file monitoring.
  • Platform report: account or website abuse after evidence preservation.

The federal bank complaint clock is 56 calendar days

Direct answer: A federally regulated bank must deal with the complaint process and provide a detailed written response within 56 calendar days from the day it received the complaint.

A fraud investigation and a formal complaint are not always opened at the same moment. After the urgent report, say in writing that you are making a complaint about the institution’s decision or handling. Record the date of receipt, because FCAC’s 56-day clock runs from the initial complaint. Ask for the bank’s acknowledgement, complaint reference, internal stage and the employee or office responsible. The bank should explain its process and provide a detailed written response.

Define the bank issue. It may be an alleged failure to investigate an unauthorized transaction, a refusal to submit or properly pursue a chargeback, inadequate action after notice, an incorrect PAD decision, an unreasonable liability finding, or complaint delay. Attach the loss chronology but do not ask the bank to compensate merely because a criminal committed fraud. Identify the agreement, consumer protection or conduct standard you say the bank applied incorrectly and the financial consequence.

FCAC supervises federally regulated financial institutions and explains the complaint framework, but it does not decide an individual compensation dispute. A consumer can share information about a possible compliance issue with FCAC while taking the personal dispute to the bank and then OBSI. Presenting FCAC as a court or compensation scheme creates false expectations. Provincial credit unions and other provincially regulated providers may have different complaint bodies, so verify the regulator before relying on the federal 56-day route.

  1. 01
    Open the complaint

    State that it is a formal complaint and record when the bank received it.

  2. 02
    Name the bank error

    Separate dissatisfaction with the scammer from the act or decision attributed to the bank.

  3. 03
    Specify the remedy

    Request investigation, reversal, compensation, fee correction or a reasoned decision as appropriate.

  4. 04
    Preserve the 56-day record

    Keep acknowledgements, transfers between teams and the final response.

When and how to take an eligible bank complaint to OBSI

Direct answer: A federal bank customer can generally approach OBSI after the bank’s final written response or after 56 days have elapsed, and usually has 180 calendar days from the final response to submit the complaint.

OBSI is an independent, free external dispute-resolution service. It investigates complaints about participating banking and investment firms within its mandate. It is not a police agency, regulator or court, and it does not pursue the fraudster. Its question is whether the financial firm acted fairly, made an error or caused a compensable loss. Since 1 November 2024 it has been the single external complaints body for federally regulated banks, which makes the referral path clearer than it was under the earlier split system.

Send the bank’s final response, the original complaint, transaction schedule, key evidence and the remedy sought. Explain why the bank’s reasoning is wrong rather than restarting the entire scam story. OBSI’s published eligibility information says federal bank complaints can be brought after the final response or 56 days, and the consumer normally has 180 days after the final response. Its FAQ also describes a general six-year knowledge limit and other restrictions. Court proceedings, settlement or lateness can affect jurisdiction, so read the current criteria for the actual case.

OBSI can recommend compensation up to $350,000, but recommendations are not a guaranteed award. Its 2025 annual release reported more than 26,000 inquiries, more than 6,100 investigations and 1,815 fraud investigations, compared with 966 in 2024. More than 1,300 complaints across its work ended with monetary compensation totalling about $5.8 million. Those numbers show activity, not a scam-refund success rate: the compensation total covers more than one complaint category and says nothing about an unreviewed individual claim.

OBSI handoff checklist
RequirementRecord to keepCommon error
Bank stage complete or 56 days elapsedComplaint receipt and final responseCounting from the fraud report without opening a complaint
Referral within 180 daysFinal-response dateContinuing informal negotiation until the period expires
Complaint concerns the firmSpecific decision, act or omissionAsking OBSI to prosecute the scammer
Financial loss and requested outcomePayment schedule and calculationQuoting OBSI’s maximum as an entitlement

Provincial consumer rights may add a route for online purchases

Direct answer: A qualifying distance-sale dispute can carry provincial cancellation and credit-card reversal rights, but those rules do not turn every scam transfer into a chargeback claim.

Quebec’s consumer office describes a structured route for certain distance contracts. Where a consumer validly cancels an eligible online purchase and the merchant does not refund within 15 days, the consumer can request a credit-card chargeback during the next 60 days. The card issuer must acknowledge the request within 30 days and credit it by the earlier of 90 days after the request or two complete statement periods, subject to the provincial conditions. The page also sets cancellation triggers, including failures involving delivery dates.

That procedure is valuable because it is precise, but its precision is also its boundary. It concerns an eligible distance purchase and a credit-card payment under Quebec consumer law. It is not a rule for an Interac e-Transfer to an impersonator, a wire to an investment platform or a blockchain transfer. Other provinces have their own distance-sale regimes and consumer agencies. Identify the consumer’s province, merchant location, contract form and payment method before quoting a provincial deadline.

Use provincial rights alongside, not instead of, the issuer’s dispute process. Send the cancellation notice in a provable form, retain evidence of delivery, and calculate the merchant’s refund period. Then make the chargeback request with the documents specified by the provincial office and issuer. A consumer living elsewhere should use the relevant provincial source rather than copying Quebec’s 15/60/30/90 sequence into a complaint where it does not apply.

Prepare one evidence pack for the bank, police and ombudsman

Direct answer: A strong evidence pack has a short chronology, a payment schedule, original communications, provider contacts and separate sections for identity compromise, merchant evidence and claimed loss.

Lead with a one-page factual summary. State when contact began, what identity or proposition was presented, when the first payment occurred, when suspicion arose and when each institution was notified. Follow it with a payment table. Do not put every screenshot before the reader knows the transaction sequence. Give each attachment a stable name such as B03-chat-2026-04-12 or C02-statement-May. Consistent labels make later complaint citations possible.

Retain full communications. A cropped message saying ‘send now’ may omit the false bank identity established earlier in the thread. Email headers and domain spellings can show impersonation. Bank records show merchant descriptors and recipient names that may differ from the public-facing brand. For crypto-related losses, include the bank or card purchase separately from the wallet transaction hash. Never send a private key, seed phrase or online-banking password as evidence.

Build a decision log beside the fraud chronology. Record what the bank was asked to do, when it answered, the clause or reason it used, and the amount recovered, provisionally credited, reimbursed or still disputed. Those statuses are different. If a provisional credit can be reversed, label it as provisional. If police or a bank says funds are frozen, do not call them returned until they are actually credited or a final compensation decision is documented.

  • One-page narrative with discovery and reporting dates.
  • Transaction schedule separating payment products.
  • Original messages, emails, adverts and domain records.
  • Bank warnings, call references and written decisions.
  • Police and CAFC report references.
  • Loss calculation that separates recovered, credited and disputed amounts.

Recovery scams target people who have already reported a loss

Direct answer: Treat an unsolicited promise to recover funds for an advance payment as a new fraud risk, especially when the caller impersonates CAFC, police, a regulator, a lawyer or a blockchain investigator.

CAFC describes recovery fraud as a repeat attack on previous victims. The approach may claim that a refund, bankruptcy distribution, government seizure or secret investigation has located the money. The criminal then asks for an administrative fee, tax, legal cost, security deposit, crypto payment, wire or remote access. CAFC and police do not ask victims to transfer money in order to receive recovered funds. Verify any claimed official through a contact found independently, not through the message or document provided.

The risk is material. CAFC’s finalized 2025 table recorded 933 recovery-pitch reports, 569 identified victims and about $25.9 million in reported losses. These are reported figures, not the total incidence. The same annual page recorded more than 112,000 fraud reports overall and more than $704 million in reported loss. A previous report can expose enough detail for an impostor to sound informed, so a case number, logo or knowledge of the original scam is not proof.

A legitimate regulated professional may charge disclosed fees under a written agreement, but cannot guarantee that a bank, police service, court or exchange will return funds. Check the entity, named professionals, regulator and complaints route. Ask what specific deliverable the fee buys: evidence organisation, legal opinion, complaint drafting, court filing or another defined task. Reject anyone who wants credentials, a seed phrase, a transfer to a safe account or a tax paid in cryptocurrency. Add the recovery approach to existing reports because it may reveal linked infrastructure.

Recovery contact verification
Claim madeIndependent checkSafe response
‘CAFC has your funds’Contact CAFC through its official siteDo not pay or continue through the caller
‘A lawyer has a court order’Verify the lawyer and court file independentlyRequest the public order and written engagement terms
‘Crypto is frozen, pay gas or tax’Verify with the named platform through its official accountNever disclose a seed phrase or send an unlock payment
‘Guaranteed bank chargeback’Ask for the actual rule, entity and complaints processNo private company can guarantee the issuer’s decision

Source: Canadian Anti-Fraud Centre: recovery scamsModified 16 January 2026

Source: Canadian Anti-Fraud Centre: Fraud Prevention Month 20262025 data; modified 1 April 2026

Concise answers

Frequently asked questions

Can an Interac e-Transfer be reversed after a scam?

Contact the sending institution immediately and ask it to alert the receiving institution and attempt recovery. An account-takeover transfer and a payment you personally authorised are assessed differently. Interac e-Transfer does not provide universal purchaser protection for an authorised scam payment.

How long do I have to dispute an unauthorized bank transaction in Canada?

FCAC says deposit-account agreements usually require notice within 30 days after the statement date, but the agreement may differ. Credit cards, PADs and chargebacks have different rules. Report immediately rather than relying on an outer period.

When can I complain to OBSI about my bank?

For a federally regulated bank, generally after its final written response or after 56 calendar days have elapsed. A complaint normally must reach OBSI within 180 calendar days after the final response, subject to OBSI’s mandate and other time limits.

Does reporting to CAFC get my money back?

No. The national report supports fraud intelligence and coordination but does not itself order reimbursement. Notify the financial institution separately, report to local police, and pursue the product-specific dispute and complaint route.

Is a company legitimate if it charges only after recovery?

A fee structure alone does not establish legitimacy. Verify the legal entity, named professionals, regulator, written agreement, deliverables and complaints route. Never provide banking credentials, one-time codes, a seed phrase or remote access, and reject guarantees of a result controlled by a bank or authority.

Evidence register

Sources and relevant dates

We link to primary sources whenever available. Sources are grouped under the section they support; the displayed date may be a publication, effective or editorial-review date. A public outcome does not promise the same result in another case.

  1. Financial Consumer Agency of Canada: resolving an unauthorized transactionUpdated 2 September 2025
  2. Canadian Anti-Fraud Centre: what to do if you are a victim of fraudModified 16 January 2026
  3. RCMP and Canadian Anti-Fraud Centre: Report Cybercrime and FraudAccessed 28 July 2026
  4. Financial Consumer Agency of Canada: protection from unauthorized transactionsUpdated 15 October 2025
  5. Ombudsman for Banking Services and Investments: can OBSI help?Accessed 28 July 2026
  6. Ombudsman for Banking Services and Investments: disputed credit card chargesAccessed 28 July 2026
  7. Financial Consumer Agency of Canada: pre-authorized debitsUpdated 12 March 2026
  8. Financial Consumer Agency of Canada: file a complaint about a financial institutionAccessed 28 July 2026
  9. Ombudsman for Banking Services and Investments: 2025 annual report releasePublished 13 March 2026
  10. Office de la protection du consommateur: cancelling an online purchaseAccessed 28 July 2026
  11. Canadian Anti-Fraud Centre: recovery scamsModified 16 January 2026
  12. Canadian Anti-Fraud Centre: Fraud Prevention Month 20262025 data; modified 1 April 2026

Continue the review

Guides for adjacent questions

A final step without pressure

Check which actions may still be available

ScamCompass is an information hub, not a law firm. With your separate consent, an enquiry may be shared with an independent legal or recovery partner. Recovery is never guaranteed.

We never request an unlocking fee, seed phrase, password or remote access.

How ScamCompass earns revenue: with the separate optional consent below, we may receive payment from an independent legal or recovery partner for a qualified referral. This does not guarantee that a partner will accept the matter or that funds will be recovered. About our model.

Never include passwords, seed phrases, one-time codes or full card details.