Canada is preparing for the introduction of its real-time payment rail, a shift that will compress the window banks have to detect and stop fraud from hours to seconds. Against that backdrop, Capco (a Wipro company) surveyed 1,000 Canadian consumers in 2026 on their experience of payment fraud, their fears about AI-enabled and "deep fake" threats, and how they weigh security against convenience when choosing a financial institution. The findings, published as the Canada Payments Fraud Survey, describe a market where fraud protection has become a primary purchase decision, yet confidence in that protection lags well behind consumer expectations.
The data below is drawn directly from Capco's survey and the accompanying analysis by Gaelan Woolham, Partner and Canada Head of Financial Crime, Risk, Regulation & Finance, and Harley Wonder, Managing Principal in the same practice. We're presenting it here because the patterns it surfaces, particularly around which communication channels fraud travels through and how large the gap is between perceived and actual risk, closely mirror what we see in DefenceNet's own detection data across email, SMS, and web-based phishing traffic. Where a finding lines up with something we can independently verify from our own telemetry, we've said so explicitly; everything else in this article is Capco's research, cited as such.
Security Has Become a Primary Purchase Decision
When Capco asked respondents what matters most when choosing a financial institution for payment services, security topped the list at 60%, followed by advanced fraud protection at 46%. Both figures ran well ahead of customer service quality (39%), transaction speed and reliability (36%), 24/7 accessibility (36%), and brand reputation (31%).
Woolham interprets this gap as evidence that fraud protection has moved from a compliance obligation to a genuine market differentiator: institutions that can demonstrably out-protect their competitors have a real acquisition and retention lever, not just a cost center to manage.
Consumers Fear One Set of Frauds, and Experience Another
Capco asked respondents to name up to four payment fraud types that concern them most. The full ranking:
- Card or card data theft: 45%
- Identity theft: 45%
- Account takeover: 41%
- A purchase you did not make: 38%
- Phishing: 27%
- A transfer payment you did not make: 24%
- Impersonation or social engineering: 17%
- "Deep fake" or AI-enabled fraud: 17%
- Fake or spoofed online stores and marketplaces: 17%
- Push payment fraud (e.g., being tricked into transferring money): 14%
- Employment scam: 13%
- Money muling: 8%
- Romance scam: 6%
- Not concerned about payment fraud: 6%
What Fraud Canadians Actually Experienced
Thirty-six percent of respondents said they had faced an attempted payment fraud in the past two years. Among that group, Capco asked which type of fraud was attempted; multiple selections were permitted:
- A purchase you did not make: 37%
- Phishing: 32%
- Card or card data theft: 20%
- Fake or spoofed online stores and marketplaces: 18%
- A transfer payment you did not make: 17%
- Push payment fraud: 15%
- Impersonation or social engineering: 14%
- Account takeover: 13%
- Employment scam: 12%
- Identity theft: 10%
- Money muling: 9%
- Romance scam: 9%
- Deepfake or AI-enabled fraud: 8%
The Gap Between the Two Lists
Line the two rankings up and the mismatch is hard to miss. Card or card data theft and identity theft are the top-feared frauds at 45% each, but they rank third and tenth, respectively, by actual incidence. Phishing sits sixth on the fear list at 27%, yet it is the second most commonly experienced fraud type at 32%, trailing only unauthorized purchases.
In other words, the fraud consumers are most anxious about isn't always the one hitting them most often, and the one that does hit them most often, after unauthorized purchases, arrives by phishing.
Confidence Hasn't Caught Up With the Stakes
Asked how confident they are that their primary financial institution will protect them from payment fraud, only 33% of respondents said "very confident." A further 52% described themselves as only "somewhat confident," 12% were neutral, 3% said less than confident, and 1% said not confident at all.
Woolham frames this as an opportunity as much as a warning: institutions that close the confidence gap, not just the technical detection gap, stand to differentiate on trust in a market where 36% of consumers have already faced an attempted fraud.
Email, Text, and Phone Remain the Front Line
When fraud was attempted, the communication channel behind it was overwhelmingly email (45%), text (39%), or phone (38%), with social media at 25%, in person at 12%, and other channels at 12%. Email, text, and phone, the channels organizations rely on daily to reach customers and employees alike, are also where DefenceNet's own detection systems observe the highest concentration of AI-generated phishing and smishing attempts across web, email, and SMS traffic. Capco's survey and our own telemetry measure different populations, but they point at the same conclusion: the communication layer, not the payment rail itself, is where most fraud attempts still originate.
The Deep Fake Blind Spot
Forty-eight percent of respondents said their financial institution had informed them about the "deep fake" threat in payments and how to reduce the associated risk; 52% said their institution had not informed them, or they could not recall being told. That gap widens with age: only 34% of respondents aged 25 to 35 recalled being informed, falling to 18% among those aged 55 to 65, where 60% said they had not been informed or could not recall.
The underlying anxiety is broad-based. Fifty-three percent of respondents said they are very concerned, and a further 38% concerned (91% combined), that personal data available online could make it easier for someone to impersonate them or answer their security questions. Seventy-eight percent also worry that biometric or facial-ID authentication is, or will be, threatened by deep fake technology.
"Banks must quickly incorporate AI into their own operations to orchestrate the detection of complex patterns and behaviors across product and operational silos and enable real-time decision-making as the fraud arms race speeds up," Woolham said. He also advocates a fraud risk score for new customers, similar to a credit risk score, to help institutions calibrate exposure before a relationship is established.
Security Without Sacrificing Convenience
Asked which statement best captures their attitude toward balancing security and convenience, 40% of respondents said security is their absolute priority even at the cost of convenience, 31% want security first with decent convenience, 26% want an even balance of the two, 3% want convenience first with decent security, and 1% said convenience is their absolute priority. At the same time, 33% find complex passwords frustrating and 27% find one-time security codes inconvenient, friction that consumers tolerate but do not enjoy.
Woolham argues the trade-off is increasingly a false one: "The aim should be to prevent fraud through stronger but lower-friction authentication, with advanced biometrics, digital wallets, tokenization and passkeys all helping to strengthen security while preserving or enhancing convenience." He points to step-up measures, such as push notifications, transaction confirmation, and real-time card controls, as ways to intervene without making customers feel penalized.
Five Fraud Types Defining the Current Threat Landscape
Capco's full report expands on five fraud categories institutions are actively defending against heading into the real-time payments era:
- Account Takeover: prevention is shifting away from static, login-stage credential checks toward continuous, risk-based authentication and cross-channel identity orchestration.
- Authorized Push Payment and Social Engineering: as real-time rails remove the settlement delay that once gave institutions time to intervene, impersonation and social engineering become harder to reverse once a payment is authorized. A UK real-time rail data-sharing pilot that combined transaction data across institutions with machine learning reported a 40% uplift in fraud detection.
- Payment Card and Emerging Digital Payment Fraud: fraud is following consumers into digital wallets and card-not-present channels as fast as new payment methods are adopted.
- Identity and Synthetic Identity Fraud: a 2025 TransUnion study found Canadian businesses reported CAD $111 billion in fraud losses, with synthetic identities accounting for 26% of that figure, up from 18% the year before. Separately, an estimated 12 million first-party fraud incidents occurred in North America in 2025, a figure projected to exceed 14 million by 2028.
- Insider-Driven Payment Fraud: roughly 60% of data breaches involve a human element, underscoring that fraud controls built solely around external threat actors leave a real gap.
Where the Communication Layer Fits
The channel data in Capco's survey, with email, text, and phone accounting for the large majority of attempted fraud, lines up with how DefenceNet's own AI Fraud Prevention Framework is structured. We treat communication and access defense as Layer 1: real-time AI phishing detection across email, SMS, and web browsing, applied before a user ever acts on a fraudulent message. Layers 2 and 3, covering identity and authentication and transaction monitoring, are the domain of the account takeover, authentication, and payment fraud controls Capco's report addresses at the institutional level.
The point isn't that one layer replaces the others. It's that if the large majority of fraud still starts as an email, a text, or a phone call, the communication layer is where the earliest and cheapest intervention is available, before the more complex and costly layers of identity verification and transaction monitoring are ever tested.
What Institutions Are Being Told to Do About It
Capco's recommendations for payment providers center on four operating-model shifts: moving from post-event detection toward prevention, detecting fraud across the ecosystem rather than within siloed products, preparing for fraud at scale as AI and agentic automation lower the cost of attacks, and adopting AI operationally rather than only for after-the-fact investigation.
Recovery experience is treated as part of the fraud strategy, not an afterthought. Woolham's recommendations include in-app reporting, the ability to flag multiple suspicious transactions at once, fast provisional credit, transparent claim tracking, and easy card replacement. "Customers should feel believed, guided and protected," he said, "rather than feeling they are entering an administrative maze."
About This Data
The statistics and quotes in this article are drawn from Capco's 2026 Canada Payments Fraud Survey, based on a survey of 1,000 Canadian consumers conducted by Capco, a Wipro company. The underlying research and analysis, including the deep-dive fraud-type breakdowns referenced above, belong to Capco. We're presenting it here, with attribution, because the channel and confidence patterns it identifies are consistent with what we observe independently in DefenceNet's own detection data across email, SMS, and web phishing traffic.
Frequently Asked Questions
What is the Capco Canada Payments Fraud Survey?
It is a 2026 survey of 1,000 Canadian consumers conducted by Capco (a Wipro company), examining attitudes toward payment fraud, deep fake threats, and the trade-off between security and convenience as Canada prepares to launch its real-time payment rail.
Which type of payment fraud worries Canadian consumers the most?
Card or card data theft and identity theft tied for the top concern at 45% each, followed by account takeover at 41%. Phishing ranked lower on the list of fears (27%) despite being the second most commonly experienced fraud type in practice (32%).
Why are email, text, and phone still the primary fraud channels?
Capco's survey found that 45% of attempted fraud arrived by email, 39% by text, and 38% by phone. These channels remain the easiest for attackers to reach large numbers of people cheaply, consistent with the concentration of phishing and smishing activity DefenceNet observes in its own detection data.
How confident are Canadian consumers in their financial institution's fraud protection?
Only 33% described themselves as very confident, and 52% as only somewhat confident, even though security and fraud protection are the top two factors consumers weigh when choosing a financial institution.
What does Canada's real-time payment rail mean for fraud risk?
A real-time rail removes the settlement delay that once gave institutions a window to catch and reverse fraudulent transfers. Capco's guidance calls for a shift toward prevention-first, continuous authentication and cross-ecosystem fraud detection rather than post-event review.