Skip to content

They paid the invoice — to a criminal impersonating their supplier.

a national health-profession association · Canada · October 2019. A national health-profession association wired an invoice payment to a criminal posing as its supplier, while the attacker sat inside two staff mailboxes as the real correspondence flowed through them. It found out when the genuine vendor asked where its money was.

What happened

Identified in the record as Alberta OIPC Decision P2020-ND-048.

Gone paid to a criminal who had spent weeks inside their mailboxes
Missing control

Multi-factor authentication and staff training — both bought afterwards

First page of Decision P2020-ND-048 Alberta OIPC decision Read the original →

On October 24, 2019, a vendor followed up about payment of an invoice. That is how the association learned it was the victim of a social engineering and phishing attack — a wire transfer had already been made to a threat actor posing as the vendor.

“the Organization learned that there had been an intrusion into two employee inboxes. The suspected point of entry was a phishing email likely received by the employees.”

The incident ran from October 2 to November 26, 2019. Nobody was tricked by a bad forgery: the attacker had been inside two staff mailboxes while the real invoice correspondence flowed through them.

The exposure reached 348 people, 21 of them in Alberta — which is what brought the case before Alberta's Commissioner, who found a real risk of significant harm and required notification. The decision does not state how much money was transferred, and neither do we.

“Implemented multi-factor authentication and arranging for mandatory cybersecurity and privacy training for staff.”

The association is a national body, not a small practice. What transfers is the method: an intruder inside the mailboxes, a genuine invoice thread, and a payment that went to the wrong account.

The rule that applied — in Alberta

Alberta PIPA s.34.1 and s.37.1 — report the breach, then notify everyone affected

“There is a real risk of significant harm to the individuals affected by this incident. The Organization is required to notify the individuals whose personal information was collected in Alberta, pursuant to section 37.1 of the Personal Information Protection Act (PIPA).”

The document

The part that matters

Nobody was tricked by a bad forgery. The attacker sat in two mailboxes for weeks, read the real invoice thread, and stepped into it. The fraud was only discovered because the genuine vendor asked where its money was.

Invoice redirection is the most common way money actually leaves a small professional firm, and it does not require anyone to be careless: the attacker was inside a mailbox while the real correspondence flowed through it. Any firm that pays suppliers by transfer has this exposure.

The documents

We hold dated copies — ask and we will send you what we read.

DocumentOur copy
Decision P2020-ND-048 Copy held 2026-08-20

The decision does not state how much was transferred, and neither do we. The organisation is a national professional association rather than a small practice — what transfers is the method, not the size of the organisation it worked on.

Who checks the bank details on an invoice?

No cost, no obligation — you keep the findings either way.

Get your free Security Snapshot