BadgerQuest
Play a roundWhy it sticksFor managersWho it's forLearnDocsPricingSign in
For accounting and bookkeeping firms

Your firm sits between clients and the CRA, which is exactly where the scams sit

CRA impersonation, changed banking details and tax-season lures, practised by your staff before the real one arrives.

An accounting practice concentrates everything a fraudster wants: financial records, social insurance numbers, banking details, and standing authority to move money and deal with the tax authority on a client's behalf. Its busiest weeks are exactly the weeks the scams surge.

The profession's own bodies say so plainly. The CRA-impersonation shapes circulating each spring are documented by CPA British Columbia, fake rebate offers, false compromised-account warnings and fraudulent audit letters among them, and every one of them is aimed at somebody busy enough to click.

See what the evidence looks likeTalk to us

The evidence, and where it comes from

Every figure below links to the source it came from. We have quoted what each number counts, because a percentage without its denominator is not evidence, it is decoration.

Tax season

is when the pressure peaks, and the shapes are documented by the profession itself: CPABC's warning names fake Canada Carbon Rebate offers, false compromised-account warnings, AI-generated fake CRA news and fraudulent audit letters, all circulating while a firm is at its busiest.[1]

191,561

phishing complaints to the FBI's Internet Crime Complaint Center in 2025, the most-reported crime type in the report. These are complaints people filed themselves, so the real count is higher.[2]

$3.0 billion

reported lost to business email compromise in the same year, across 24,768 complaints: the changed-banking-details and urgent-payment scams that live wherever a firm pays suppliers or moves client money.[2]

$704 million

lost to fraud by Canadians in 2025 as reported to the Canadian Anti-Fraud Centre, with reported losses since 2022 past $2.4 billion, and the release's own caveat that only 5 to 10 per cent of frauds are reported.[3]

What this does not say

None of these figures counts accounting firms specifically. The FBI and CAFC numbers count reported fraud across whole economies, and CPABC documents the shapes in circulation rather than totals. That is the honest state of the public data, and we would rather show you the denominators than borrow a vendor survey we cannot link.

Does CPA Canada or my provincial body require staff security training?

No. Your obligations are confidentiality under your professional code and the safeguard duties in privacy law, and neither names a training product. What the provincial bodies publish is scam guidance. In practice, the party asking about staff training is usually an insurer, or a client's own security questionnaire.

  • A certificate per person, naming them and the course, dated the day they finished.
  • A serial on every certificate that anyone can verify on our site without an account.
  • A record for every person on your roster, including who has not finished, because a report that lists only the people who passed is not evidence of a programme.
  • An export you can hand to an insurer or attach to a client's security questionnaire as a document.
And the part we cannot answer for you

Whether a particular insurer or client accepts it is their decision, not ours: a certificate evidences that a named person completed named training, and nothing beyond that. Put one line to whoever is asking: “ongoing security awareness training for all staff, with dated per-person completion records and verifiable certificates”, and you will know before you spend anything.

How practice here maps to what reaches a firm

The CRA shapes, forged safely

Tax-authority refund lures and audit threats are shapes our generator produces, in Canadian and American variants, practised inside the product and never sent to a real inbox.

Client data stays out of it

Training your staff needs their names and work email addresses, and nothing else. No client records, no tax files, no CRA credentials anywhere near us.

Certificates with a verifiable serial

Completion issues a certificate carrying a serial anyone can check on our site without an account, so the evidence stands up on its own.

The misses come back around

A few minutes a week, and the scam types somebody keeps missing return until they stop missing them, rather than one annual module before tax season wipes the memory.

What your people will practise, explained free

These are the same scams this page is about, written for the person who has to spot one on a Tuesday morning. No account needed to read them.

Tax scams: fake refunds and threats from the "CRA" or "IRS"Fake invoices and "our bank details have changed"How to spot a phishing email

What is true in every sector

62%

of breaches involved the human element, up from 60% the year before, across more than 22,000 confirmed breaches in 145 countries.[4]

31%

of breaches began with vulnerability exploitation, which this year overtook credential abuse (down to 13%) as the single most common way in. People are involved in most breaches, but they are not the most common entry point, and we are not going to tell you otherwise.[4]

16%

of breaches came through social engineering, the third most common pattern. In simulations, the median click rate for voice and text lures runs 40% higher than for email.[4]

And the uncomfortable part, which we would rather you heard from us

One of the largest field studies of phishing training ever published followed roughly 19,500 staff at a large health system through ten simulated campaigns over eight months. It did not flatter the industry we are in.

2 points

was the entire effect of embedded phishing training on the likelihood of clicking a phishing link. Having recently completed annual mandatory security training showed no significant relationship with falling for phishing at all.[5]

75%

of the people who landed on the training page spent a minute or less on it, and about a third closed it immediately. That is a finding about attention, not about people being careless.[5]

We read that as the strongest argument for how BadgerQuest is built, not against it. What the study measured is the industry standard: an annual module, an ambush simulation, and a training page served to somebody who has just been told they failed. Nobody reads that page. Training that gets skimmed for forty seconds is not a smaller dose of training that works, it is a different thing entirely.

So the daily round is two minutes and it is a game, because that is the version people voluntarily finish. We do not send simulated phishing to real inboxes, because being ambushed by your own IT department is what produces the closed tab. Nobody is shamed for a wrong call, and what we train is the judgement to tell the two apart rather than a reflex to flag everything. Topics somebody keeps missing come back around instead of being marked complete.

The study's authors also recommend refocusing on technical countermeasures, specifically two-factor authentication and password managers that only fill on the correct domain. They are right, and those will stop more attacks than any training will. Do them first. We will say the same on a sales call. Training is for the part those controls do not cover, and it should be honest about being exactly that.

Sources

Read them yourself. That is the entire habit we are trying to teach, and it would be a strange thing for us to ask of your staff and not of ourselves.

  1. [1]Chartered Professional Accountants of British Columbia (CPABC). 4 CRA-related scams to stay vigilant about this tax season CPABC newsroom, 16 April 2024. Names the impersonation shapes in circulation rather than publishing totals.https://www.bccpa.ca/news-events/cpabc-newsroom/2024/april/4-cra-related-scams-to-stay-vigilant-about-this-tax-season/
  2. [2]FBI Internet Crime Complaint Center (IC3). 2025 IC3 Annual Report Published 2026. 1,008,597 complaints and US$20.877 billion in reported losses for 2025. Figures count complaints the public filed with IC3, so they are self-reported, United States centred, and a floor rather than a total. Figures quoted here were read from the report PDF.https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
  3. [3]Competition Bureau Canada. Fraud Prevention Month to bring hidden crime into the spotlight News release, 6 March 2026. Loss figures are Canadian Anti-Fraud Centre data, and the release itself carries the caveat that only 5 to 10 per cent of frauds are reported.https://www.canada.ca/en/competition-bureau/news/2026/03/fraud-prevention-month-to-bring-hidden-crime-into-the-spotlight.html
  4. [4]Verizon Business. 2026 Data Breach Investigations Report, Executive Summary 19th edition, published May 2026. More than 31,000 security incidents, of which more than 22,000 were confirmed data breaches, across organisations in 145 countries. Figures quoted here are from the executive summary PDF.https://www.verizon.com/business/resources/executivebriefs/2026-dbir-executive-summary.pdf
  5. [5]Ho et al., University of Chicago, UC San Diego and UC San Diego Health. Understanding the Efficacy of Phishing Training in Practice 46th IEEE Symposium on Security and Privacy, May 2025. Roughly 19,500 staff at UC San Diego Health, ten simulated campaigns over eight months. Findings summarised by UC San Diego Today, 17 September 2025.https://today.ucsd.edu/story/cybersecurity-training-programs-dont-prevent-employees-from-falling-for-phishing-scams

See what the evidence looks like

Free for individuals, forever. Teams are $4 CAD per person per month, month to month, no minimum, cancel whenever you like.

See what the evidence looks likeTalk to us

Not quite your sector?

MSPsSmall businessNon-profitsHealthcareSchools & collegesCard paymentsPublic sectorLaw firmsAll of them
BadgerQuest by CyberBadger
Who it's forLearnDocsAPIHelpCheck a certificatePrivacyTermsMade in Canada