Phishing emails used to be easy to spot. Bad grammar, generic greetings, and obvious spelling mistakes gave them away. Generative AI has removed most of those tells, and AI phishing attacks are now landing in Markham inboxes disguised as a supplier invoice, a colleague’s request, or a bank notification. This piece covers why these attacks are getting past experienced staff, what’s already happening to Canadian businesses, and six practical steps you can put in place this month.
Why AI-generated phishing is harder to catch
Older phishing attempts relied on volume. Send thousands of messages and hope a percentage of recipients make a mistake. AI-generated phishing works differently. Generative models can pull details from a LinkedIn profile, a company website, or a leaked email thread, then produce a message with the correct names, the right tone, and no obvious errors.
The Canadian Centre for Cyber Security’s National Cyber Threat Assessment 2025-2026 flags this shift directly. The assessment notes that cybercriminals are increasingly using AI chatbots to craft convincing phishing emails and that phishing remains one of the most reported forms of cybercrime affecting Canadians, with spear phishing carrying one of the highest financial impacts per incident. Canada’s Competition Bureau reported that Canadians lost more than $704 million to fraud in 2025, with reported losses since 2022 surpassing $2.4 billion.
For a business in Markham, Richmond Hill, or Vaughan, the old advice of watching for spelling mistakes and odd formatting no longer holds up. The message might be flawless. The judgment call has to happen somewhere else in the process.
AI phishing attacks already reaching Markham inboxes
In April 2026, Microsoft’s Detection and Response Team published details of a campaign it tracks as Storm-2755, a financially motivated group targeting Canadian employees specifically. Victims searching common terms like “Office 365” were led to fraudulent sign-in pages through paid ads and manipulated search results. Once someone entered their credentials, the attacker captured the live session and used it to search the victim’s mailbox for payroll information, then redirected their salary deposit to a different account, often without triggering the obvious signals a user would notice.
Microsoft’s writeup is worth reading in full if you want the technical detail. What matters for a Markham business is simpler. The attacker did not need to breach a network. They needed one employee to click one search result.
6 ways to strengthen phishing prevention for your Markham business
Six changes make the biggest difference:
Turn on phishing-resistant multi-factor authentication
Standard text or app-based codes can be captured and reused in adversary-in-the-middle attacks like Storm-2755. FIDO2 security keys or passkeys prevent this because they verify the site itself, which the user alone cannot.
Filter email on behaviour patterns beyond known bad senders
Modern filtering should flag look-alike domains, unusual sending patterns, and links that redirect through several hops, the pattern behind most AI-generated lures.
Verify payment and payroll changes through a second channel
If a message asks to update a direct deposit or banking detail, confirm it by phone using a number already on file, not one supplied in the email.
Watch for new inbox rules
Attackers who gain access often create rules that hide messages containing words like “bank” or “direct deposit” so the real account holder never sees them. Regular audits catch this quickly.
Keep sign-in monitoring current
Reviewing sign-in logs for unusual locations or repeated failures helps catch a compromised session before it causes financial damage.
Run phishing simulations on a rolling schedule
Staff who see realistic, varied examples regularly get noticeably better at spotting the next one.
Why employee training still matters
VBS IT Services’ cybersecurity awareness training points to Ponemon Institute research showing that organizations running regular phishing simulations and awareness training see roughly a 64% improvement in employee phishing click rates. That figure lines up with a broader pattern. Human error remains the largest single cause of data breaches, well above technical failures or unpatched systems.
Training works best when it’s short, frequent, and specific to the scams currently in circulation. A single annual session gets forgotten within weeks. A Markham business with a dozen employees does not need a security operations centre. It needs a handful of people who know what a suspicious request looks like and feel comfortable flagging it, even if they turn out to be wrong.
Why managed cybersecurity beats DIY when threats move this fast
Reading about phishing-resistant MFA and inbox rule audits is one thing. Implementing and maintaining them across every employee, every device, and every new hire is another matter, and it competes for attention with the rest of running a business.
A managed cybersecurity partner keeps these defences current without asking a business owner to become a security specialist. That means continuous monitoring, a prioritized set of recommendations, and someone accountable for making sure phishing-resistant MFA, email filtering, and staff training get rolled out and stay in place as the business grows.
Most cybersecurity tips aimed at small businesses assume someone in-house has the time to research, test, and maintain them. Few Markham SMBs have that spare capacity, which is exactly the space a managed partner is built to fill.
VBS IT Services has worked through exactly this kind of transition before. One engineering services client replaced an informal IT setup with a structured, secure foundation, reducing risk without slowing the business down.
Phishing attacks do not announce themselves. The right IT partner catches them before your team has to. If you want a clear picture of where your Markham business stands today, from email filtering to sign-in monitoring to how ready your team is to spot the next AI-generated message, book a call with VBS IT Services to talk through email security and staff protection.
Often you can't from the writing alone. Check the sender's actual email address behind the display name, hover over links before clicking anything, and confirm any request involving money or credentials through a separate channel like a phone call.
Standard MFA, such as text codes or app prompts, can be bypassed by adversary-in-the-middle attacks. Phishing-resistant MFA, like FIDO2 security keys or passkeys, is built specifically to stop this kind of session hijacking.
Isolate the device from the network right away, reset the account's credentials and active sessions, and check sign-in logs and inbox rules for anything unusual. Acting within minutes limits how much damage a compromised session can do.


