BMO Scam Highlighting Vulnerabilities in Two-Factor Authentication

Introduction
A recent article published by CBC news highlighted a concerning scam that involved the Bank of Montreal (BMO). The scam managed to exploit vulnerabilities associated with the two-factor authentication (2FA) system of the bank. This advisory aims to provide an overview of the issue, its implications, and recommendations.
Summary of the incident
The scam primarily targeted customers with lines of credit. Perpetrators pose as bank employees and use a combination of phishing techniques and flaws in the 2FA process to gain unauthorized access to customers’ accounts, subsequently making unauthorized transactions.
Implications
- The trustworthiness of 2FA is at stake. Customers generally perceive 2FA as a robust security measure, but this incident underscores potential vulnerabilities.
- The scam demonstrates that even with the second layer of authentication, user accounts can be compromised if the process isn’t foolproof.
- Potential loss of customer trust in banking institutions due to such vulnerabilities.
Recommendations
- Stay Informed: Regularly update oneself about the latest scams and phishing techniques. Always be skeptical of unsolicited calls or emails asking for personal or banking information.
- Use Advanced Security Features: Wherever possible, use advanced security features like biometric authentication or hardware-based security keys.
- Monitor Accounts: Regularly check bank accounts for unauthorized transactions and report any discrepancies immediately.
- Stay Educated: Participate in security awareness sessions provided by your Richter Guardian team, the bank or other trusted organizations.
While 2FA is an essential security feature, it is not infallible. Richter Guardian clients should be proactive in understanding its limitations and continuously seek ways to enhance their security posture.
Contact us at anytime you are unsure. If you receive a call from someone purporting to be your bank and you are unsure, call us to help you determine the legitimacy of their communication.
Table 1 – Levels of two-factor authentication that may be available to protect your bank account.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.
%20(1).png)
Protect your digital life by detecting risks before they escalate
Richter Guardian gives you enterprise-level cybersecurity tailored for individuals, families, and executives.

Related posts

What happened
A Calgary investor is suing TD Waterhouse Canada Inc. after fraudsters allegedly broke into his TD Direct Investing accounts while he vacationed in Hawaii.
According to The Globe and Mail, the intruders sold his holdings and poured more than $5 million into a thinly traded Hong Kong stock.
When it collapsed, he lost roughly $4.5 million in retirement savings.
TD says he either made the trades himself or failed to secure his account. Nothing has been proven in court, but the case shows how fast wealth can vanish once login credentials fall into the wrong hands.
Why this keeps happening
This isn't an isolated incident.
TD Bank has faced other serious regulatory scrutiny in recent years, and securities fraud attorneys continue to field claims from investors who say controls failed them.
Banks guard their own core systems closely, but the real weak points are often somewhere else: the client's personal devices, account passwords, and email accounts, all sitting outside the bank's oversight and controls.
Why travel makes you a target
It's worth pausing on the timing here: the alleged fraud happened while the investor was away in Hawaii. That's not a coincidence worth overlooking.
Vacations pull people out of their normal routines on purpose, and that's exactly what makes them good for rest, and terrible for security.
At home, most people have habits without even thinking about them: checking accounts over morning coffee, noticing a strange email between meetings, recognizing when something on a statement looks off.
Travel disrupts every one of those habits at once:
- You're on hotel or airport Wi-Fi, which is rarely as secure as your home network.
- You're checking email and banking apps quickly, often on borrowed time between activities, so a suspicious login alert can get skimmed past instead of read carefully.
- Time zone changes mean notifications may arrive at 3 am and get dismissed unread.
Many people intentionally "unplug" from their finances while traveling, treating vacation as a break from monitoring entirely.
Fraudsters understand this pattern well. Account takeovers cluster around known absences: holidays, long trips and/or business travel.
A window of even a few days without anyone watching an account closely is often all it takes to sell off holdings and move funds into a single volatile position, which is exactly what allegedly happened in this case.
None of this means people shouldn't travel or unplug — they should. It means the monitoring can't rely on the account owner remembering to check in from a beach in Hawaii.
Steps you can take right now
Basic habits, especially before and during travel, meaningfully reduce your own risk:
- Turn on multi-factor authentication for every brokerage, banking, and email account.
- Use a unique, strong password for each financial account — never reuse them.
- Avoid logging into financial accounts on public or hotel Wi-Fi while traveling.
- Set up account alerts for trades, withdrawals, and login attempts before you leave.
- Designate someone you trust to glance at statements while you're away.
- Review account activity closely in the days right after returning.
- Ask your brokerage about limiting or freezing margin trading if you rarely use it.
Where personal habits aren't enough
Even careful people get targeted, especially the moment they step away from their routine.
This is a gap Richter Guardian is built to close.
Corporate and bank-side security stops at the workplace door — it doesn't watch the personal phone, laptop, or email account a fraudster actually needs.
Richter Guardian's monitoring and prevention service watches continuously, including while clients travel, for compromised credentials and suspicious activity. If something looks wrong, clients aren't left to figure it out alone.
Our incident response team, the Cyber Defence Desk, is reachable via phone, email, video or a mobile app to explain what's happening and guide next steps.
The bottom line
Vacations should mean rest, not vigilance. For high-net-worth individuals and families with complex accounts and multiple devices, someone still needs to be watching while you're not. Protection shouldn't stop where your routine does.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Cheaper Cyber Insurance, Costlier Risk: The Family Office Coverage Gap
The cyber insurance market is softening just as the threats driving demand for it accelerate.
Premiums are falling, yet more than 40% of cyber claims are now denied — most often because controls attested to on the application were never actually in place.
For family offices, with their informal governance and concentrated wealth, a cheaper policy is increasingly a policy that will not pay.
The defensible position for family offices is verifiable security controls, not a lower premium.
The market contradiction
Reporting from the Family Office Cybersecurity Forum in New York describes a market where competition is outpacing risk. New entrants including major carriers have pushed prices down, and average premiums were projected to fall a further 11% in 2026.
Buyers are being advised to shop around — but price is now the least important variable.
The frequency and severity of losses continue to climb even as rates drop, and the early signs suggest the rate of decline is starting to slow.
By the numbers
- ~50% of US family offices were hit by a cyberattack in 2025.
- 40%+ of cyber insurance claims are currently being denied — driven by missing controls, late notification and absent policy provisions, not exclusions.
- ~75% of carriers now run external attack surface scans during underwriting, replacing self-attestation.
- $713K average global ransomware claim in 2025 — nearly double the $374K recorded in 2024.
- 60% of family offices are confident their staff can detect and prevent AI-powered attacks.
- 2,137% rise in deepfake-driven fraud attacks since 2022; now 6.5% of all fraud.
Why family offices are uniquely exposed
Forum specialists characterized family offices as structurally vulnerable in ways that standard commercial cyber exposure does not capture.
The same traits that make a family office efficient make it exploitable:
- Cultures of informal approval and trust-based authorization.
- Heavy reliance on personal assistants and a small circle of staff.
- A bias toward speed over documented process.
- Multi-generational structures that widen the attack surface and blur accountability.
Layered on top is an AI-driven threat surface: deepfake voice impersonation of principals, AI-generated phishing, and business email compromise.
The FBI logged a 37% rise in AI-assisted BEC incidents using cloned executive voices, and attackers can now sit undetected inside a compromised environment for 100 days or more.
The regulatory squeeze
Family offices and their advisers face a tightening regulatory environment that mirrors what insurers already demand.
Amendments to the SEC's Regulation S-P took effect for smaller registered investment advisers on June 3, 2026, introducing a written incident response program, a 30-day customer breach notification obligation, and expanded vendor oversight.
The SEC's examiners have named S-P compliance a 2026 priority.
The controls the regulator now mandates are in most cases, the same controls cyber insurers require for a claim to be honored. One program satisfies both.
How Richter Guardian can help family offices
- Controls verification and attestation readiness — ensuring what you tell underwriters is true and evidenced.
- External attack surface assessment aligned to carrier underwriting scans.
- Regulation S-P alignment: written incident response program, breach notification readiness, vendor risk oversight.
- Human-layer defence against deepfake and AI-enabled social engineering, including principal and staff awareness.
- Ongoing managed monitoring so that controls stay in place between renewals.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Understanding Business Email Compromise: Why Trusted Emails Still Need Verification
Business Email Compromise, or BEC, is a targeted scam in which a criminal impersonates someone you trust. They may pose as an executive, lawyer, vendor, advisor, employee, or family member and ask you to send money, change banking details, or share sensitive information.
The message may come from a lookalike email address or a real account that has been compromised. This can make the request appear normal and include details that only a trusted person would seem to know.
Executives, high-net-worth individuals and their families, and anyone able to move money or release sensitive information are valuable criminal targets. AI-written emails and voice cloning can make these scams even more convincing.
How it works
An attacker sends a message that appears to come from someone you know. It is designed to seem routine or urgent so that you act before confirming the request another way.
If a real email account has been compromised, the attacker may review conversations, invoices, contacts, and travel details. They can use this information to create a convincing request at the right time.
The risk works both ways. You may receive a fraudulent message, or your own account may be taken over and used to contact others in your name.
Why BEC is a major threat
According to the FBI Internet Crime Complaint Center’s 2025 Annual Report, BEC led to 24,768 reported complaints and more than $3 billion in reported losses in 2025. Only investment fraud caused greater reported losses that year.
BEC is also becoming harder to identify. AI can create professional messages without the spelling mistakes or awkward wording often linked to scams. Voice cloning may also make a call or voice message sound like someone you know.
Warning signs of business email compromise
Watch for:
- Urgency combined with secrecy
- New or changed payment or banking details
- A reply-to address that differs from the sender’s address
- A request that skips the normal approval process
- Pressure to move the conversation to text or WhatsApp
- An unusual request for sensitive information
A message from a compromised account may not show any of these signs. Verifying the request is more reliable than deciding whether the email looks suspicious.
How to protect yourself
Confirm every new payment instruction, banking change, or urgent transfer by calling the person directly. Use a number saved in your contacts, shown on a previous statement, or obtained from another trusted source.
Never use a number provided in the same email as the request.
During the call, confirm the payment amount, recipient, bank, account details, and reason for the transaction. Be especially careful if any information has changed.
Require approval from a second trusted person for payments above a set amount. Everyone involved should be expected to pause and verify a request, even if this causes a short delay.
Protect every email account including personal accounts, with a strong, unique password and multi-factor authentication. Keep recovery information current and check for unfamiliar forwarding rules, filters, connected applications, or signed-in devices. Do not reuse your email password on other services.
If you have been targeted
If you sent money or shared banking information, contact your financial institution immediately. Ask whether the payment can be stopped, recalled, or frozen. Keep the original emails, messages, and payment records.
If you believe your email account was compromised:
- Change the password from a trusted device.
- Sign out of other active sessions.
- Review the account’s security and recovery settings.
- Remove unfamiliar rules or connected applications.
- Notify anyone who may have received a fraudulent message from your account.
How Richter Guardian can help you
Richter Guardian can help reduce BEC risk by monitoring for exposed credentials and identifying impersonation attempts, including lookalike domains, websites, or accounts created in your name.
We can also help secure your accounts, review suspicious requests, and provide guidance if you believe an account has been compromised.
If you receive a suspicious email, payment request, banking change, or request for sensitive information, contact us before taking action.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.
.png)
