Navigating the terrain of synthetic and traditional theft scams

Introduction
In an increasingly interconnected digital world, safeguarding personal and financial information has never been more crucial. Cybercriminals can exploit stolen identity information to commit financial fraud, gain unauthorized access to accounts, and engage in other criminal activities. In the context of identity theft – there is both synthetic identity theft and traditional identity theft.
Synthetic identity theft combines personally identifiable information (PII) to manufacture a person or entity for the use of illegal, nefarious activity.
Traditional identity theft involves stealing an individual’s existing personal data to impersonate them.
Alternatively, synthetic identity theft involves criminals obtaining small fragments of a real person’s identity to fabricate a completely new identity. The real elements of the fabricated individual adds a sense of legitimacy to the identity.
Preventing identity theft of all kinds
Protecting yourself from identity theft, fraud, and unauthorized access to your sensitive data is our responsibility. Below, we have compiled a comprehensive list of security measures and best practices to help you fortify your defenses against potential threats.
By following these guidelines, you can take proactive steps to enhance your security and financial well-being. From monitoring your credit report to secure document disposal, each suggestion in this list is designed to empower you with the knowledge and tools to protect your valuable information and minimize the risks associated with identity theft and fraud.
- Monitor Your Credit Report: Regularly monitor your credit report to detect any unauthorized activity. If you come across information unrelated to you, contact the creditor and inquire about the account or inquiry.
- Limit What You Carry: Avoid carrying additional credit cards, birth certificates, SIN cards, or passports in your wallet or purse unless absolutely necessary. This precaution reduces the amount of information a potential thief could access if your wallet or purse gets lost.
- Secure Your Mailbox: Consider installing a mailbox with a lock at your residence to minimize the risk of mail theft.
- Securely Dispose: Never dispose of credit card receipts or personal information documents in a public trash container; use a shredder instead.
- Secure Your Purse or Wallet: Never leave your purse or wallet unattended, whether at work or in places like churches, restaurants, fitness clubs, parties, or shopping carts. Also, avoid leaving your purse or wallet visible in your car, even if the vehicle is locked.
- Limit Your Credit: Limit the number of credit cards you possess and cancel inactive accounts to simplify your financial security.
- Be Careful of What you Disclose: Do not disclose your credit card, bank, or Social Insurance information over the phone, even if you initiated the call, unless you can confidently verify the call’s legitimacy
- Secure Receipts: Securely store and shred credit, debit, and ATM card receipts before disposing of them.
- Scrutinize Your Bills: Scrutinize your utility and subscription bills regularly to confirm the accuracy of the charges.
- Do Not Write Down Your Passwords (except in a Password Vault): Memorize your passwords and personal identification numbers (PINs) to eliminate the need to write them down or use a password vault. Remain vigilant when entering your PIN to ensure no one is observing you.
- Secure Your Information: Maintain a comprehensive list of all your credit and bank accounts in a secure location, such as a password vault. This will facilitate quick communication with issuers if your cards go missing, including providing account numbers, expiration dates, and customer service and fraud department contact numbers.
- Shred Pre-approved Credit Offers: Before discarding pre-approved credit offers, credit card receipts, or phone bills, tear them into small pieces or cross-cut shred them to prevent potential identity theft. Thieves can use such offers to apply for credit cards in your name and redirect them to their address.
- Keep Your Credit Information Accurate: According to consumer reporting legislation, if you believe any entry on your credit report is incorrect or incomplete, you can notify a major credit reporting bureau, which will verify the information at no charge. Remember that they typically do not accept disputes from third parties unless accompanied by a notarized power of attorney authorizing a licensed attorney or a family member to represent you or if the power of attorney is unlimited and irrevocable.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.
%20(1).png)
Protect your digital life by detecting risks before they escalate
Richter Guardian gives you enterprise-level cybersecurity tailored for individuals, families, and executives.

Related posts

On August 4, 2026, the claims process opened for a $8.7 million settlement of a class action against the Government of Canada.
This covered people whose personal or financial information in a Government of Canada online account, including the Canada Revenue Agency portal, was accessed without authorization in 2020.
KPMG is the court appointed administrator, and eligible class members can submit claims online or by mail until February 3, 2027.
The settlement is legitimate, but the publicity around it is exactly the conditions fraudsters look for:
- A national news story
- A real government linked payout
- A real deadline
- A real administrator asking people to enter a last name and the last three digits of a Social Insurance Number on a website
That combination gives criminals a credible pretext to build convincing fake eligibility checkers and claim portals, and to harvest identity data and account credentials at scale.
Our expectation
A wave of phishing email, SMS, social media advertising, sponsored search results, and voice calls impersonating KPMG, the CRA, the Federal Court, and class counsel, beginning within days of the news coverage and continuing through the February 2027 claim deadline.
The only legitimate channels and what to watch for
Official settlement website
https://www.breachsettlementcanada.kpmg.ca (English and French). This is the court appointed administrator's website.
Official email address
breachsettlementcanada@kpmg.ca
What the real eligibility check asks for
- Last name
- Last three digits of the SIN
- An email address
- Nothing more at the eligibility stage
What the real process NEVER asks for
- Full SIN
- Date of birth
- Banking credentials
- CRA My Account user ID or password
- A multi factor authentication code
- A credit card number
- A copy of a government ID uploaded to a chat window
- Any payment or fee. There is no fee to file a claim
Anything arriving by unsolicited text, direct message, or phone call that pushes you toward a different address, a shortened link, or an app download should be treated as fraudulent until proven otherwise.
What the fakes will look like
The following mock ups were produced by Richter Guardian for training purposes.
These are not real messages and the addresses and links shown are illustrative only.
Share them with your household, your office staff, and anyone who manages correspondence on your behalf.
Example 1: Phishing email impersonating the claims administrator

What to watch for
- Look-alike sender domain rather than https://www.breachsettlementcanada.kpmg.ca
- A pre-approved dollar figure the real administrator would never quote up front
- A 48 hour forfeiture threat against a deadline that is actually February 3, 2027
- A request for the full SIN
- CRA sign-in details
- Banking information
Example 2: Smishing text message

What to watch for
- The administrator does not solicit claims by text message
- The domain is not kpmg.ca
- The amount is presented as guaranteed
- Urgency is manufactured
Legitimate class action notice arrives by mail or from the administrator's own address.
Example 3: Fake eligibility and claim portal

What to watch for
- An unencrypted look-alike domain
- A full SIN and CRA credentials requested where the real site asks only for a last name
- Three SIN digits
- An email address
- An ID upload
- A processing fee where the real claim is free
- False scarcity counters
Criminals also buy sponsored search advertisements so these pages appear above the real one.
Example 4: Voice call and voicemail pre-text

What to watch for
- An inbound unsolicited call
- Identity verification demanded by the caller rather than by you
- Above all, a request to read back a code sent to your phone. That code is a multi factor authentication (MFA) prompt for an account the caller is trying to take over at that moment. No legitimate organization will ever ask for it
Example 5: Social media and search advertising

What to watch for
- An invented average payout
- A fabricated deadline
- A paid placement above the genuine result
Reach the administrator by typing the address directly - https://www.breachsettlementcanada.kpmg.ca - rather than by clicking any advertisement or search result.
Red flags to brief your household and staff on
Unsolicited contact
The administrator contacts class members by mail or from its own domain. It will not cold call, text, or direct message you.
A guaranteed amount up front
Real compensation is up to $80 or up to $200 for time spent, plus up to $5,000 in documented out of pocket costs, and amounts may be reduced depending on how many claims are approved. Nobody can promise you $5,000.
Artificial urgency
The real deadline is February 3, 2027. Any message giving you 24 hours, 48 hours, or "this week" is manufacturing pressure.
Over collection of identity data
The genuine eligibility check asks for a last name, the last three digits of your SIN, and an email address. A request for the full SIN, date of birth, ID scans, or CRA credentials is a data harvest.
Any request for a fee
Filing a claim is free. A processing, verification, or expedite fee means fraud.
Any request for a code
A one time passcode read aloud, forwarded, or typed into a third party site hands over your account.
Look-alike domains
Check the address carefully. The genuine site is https://www.breachsettlementcanada.kpmg.ca.
Anything ending in .info, .net, .co, .ca-claims, or a hyphenated variant of the KPMG name is not it.
Payment by unusual method
Requests to move funds, buy gift cards, or receive a payout through e-transfer to a new recipient are not part of any settlement.
What we recommend you do
For principals and family members
Type the address, never click
Reach the eligibility check only by typing https://www.breachsettlementcanada.kpmg.ca into the web browser. Do not use links from email, text, social media, or search advertisements.
Verify by calling back
If someone claims to be the administrator, hang up and contact breachsettlementcanada@kpmg.ca from the details on the official site.
Treat the SIN as a credential
Never provide a full Social Insurance Number to an inbound contact.
Check your CRA account directly
Sign in to CRA My Account by typing the address, confirm your direct deposit details and mailing address have not been changed, and enable multi factor authentication if it is not already on.
Consider a credit file alert
If you believe your information was exposed, place a fraud alert with Equifax Canada and TransUnion Canada.
For family offices and business staff
Brief your team this week
Forward or print this email to anyone who handles correspondence, banking, or tax filings on a principal's behalf.
Add a verification step
Any instruction arising from a settlement, refund, or government notice must be verified by an out of band call to a known number before any data or funds move.
Watch for lookalike domains
Ask your IT provider to monitor for newly registered domains that combine your family or firm name with settlement, claim, refund, or CRA terms.
Tune your email filtering
Quarantine newly registered sender domains and flag external mail referencing CRA settlements or class action payouts.
Report and preserve
Report suspected scams to the Canadian Anti-Fraud Centre at 1-888-495-8501 and preserve the original message headers rather than deleting them.
If you think you've already been caught
Move quickly
Change the password on any account whose credentials were entered, starting with CRA My Account and your email, and revoke active sessions.
Call the CRA
If CRA credentials were disclosed, contact the CRA immediately and ask that the account be locked and reviewed for changes to direct deposit or address.
Notify your bank
Report the exposure and ask for enhanced verification on outbound payments.
File a credit alert
Contact Equifax Canada and TransUnion Canada.
Contact Richter Guardian
Speak to your Richter Guardian team. We can help contain the incident, assess what was exposed, and coordinate monitoring.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Why Richter Guardian's Digital Executive Protection Works Like a Home Security System
Most families already understand physical home security. A monitored home security system watches the doors, the windows, and the driveway, and it alerts a real person the moment something looks wrong.
Few high-net-worth families would consider their primary residence unprotected in this way.
Yet the equivalent protection is often missing for the digital side of an executive's family life, where far more of their exposure now lives: within personal email accounts, mobile phones, computers, social media profiles, and financial credentials.
Richter Guardian is built around the same underlying idea as a home security system, just applied to a family's digital footprint.
It is worth walking through the comparison directly, because it makes clear what "protection" should include.
Sensors on every door and window, not just the front entrance
A home security system is only as strong as the size of its coverage. A system that only watches the front door leaves every other entry point open. This is why home security systems place sensors on every window, every door, and often the garage too.
Richter Guardian applies this same principle to an executive's digital life on the home and family front. Personal digital protection means every meaningful entry point is covered, not just the obvious one. This includes:
- Personal laptops, tablets and phones, which are frequently the least protected devices in a household.
- Personal and family email accounts, often the single most valuable target since they often double as the recovery method for banking and investment accounts.
- Social media accounts, which can be cloned or impersonated to reach family members, friends, or staff.
Just as an unmonitored side window undermines a home security system's front-door sensor, one unprotected personal device or account can undermine protection everywhere else.
24/7 monitoring, not a sign in the yard
A home security sign discourages some opportunistic activity, but it does not stop a determined intruder, and it certainly does not respond to one.
The value of a real home security system comes from continuous monitoring: sensors that are always active and a monitoring center that is always watching.
The digital equivalent is continuous monitoring for leaked credentials, impersonation, and malware:
- A stolen password sitting on the dark web is like a duplicated house key sitting in a stranger's pocket. It does nothing on its own, but it becomes dangerous the moment someone decides to use it.
- Ongoing dark web and credential monitoring means that exposure is caught before it turns into a break-in, rather than being discovered only after money or data is already gone.
Monitoring that connects you with a real person, not just an app that pings you
When a home alarm is triggered, the value isn't only the alert. It's what happens next.
A monitoring centre verifies the situation and, if needed, contacts emergency services on the homeowner's behalf. Compare that to a security system that simply sends a phone notification and leaves the resident to figure out what to do.
With Richter Guardian, when an issue arises or clarification is required, our concierge support team contacts you in a secure, private and discreet manner. You can also contact us at any time. Either way, communication takes place through the Guardian mobile app, a phone call, or another agreed-upon channel.
Our Guardian professionals, also known as the Cyber Defence Desk, explain what’s happening in clear language and guide next steps in a way that fits into your broader wealth and risk strategies.
This matters most in the moment it's needed: when there's a convincing call, a strange pop-up, or an unexpected wire request.
When you know exactly who to speak with, and have those questions be answered by a real person, is the difference between a contained incident and a costly one.
Motion sensors around the perimeter, not just the locks
Good home security doesn't rely on locks alone. It adds motion sensors, cameras, and perimeter alerts, so that suspicious activity is noticed even if no door has actually been breached yet.
The digital version of this is reputation and identity protection. A cloned social media profile or an impersonation attempt is a form of activity around the perimeter of a family's digital life, well before any account can be compromised.
Monitoring for that activity, and acting on it early, is what keeps a small warning sign from becoming a full-blown incident involving fraud or reputational harm.
Covering every household under one family's roof, not just one address
Here is where the comparison becomes especially important for high-net-worth families with more than one residence, or with members living in different homes altogether.
A homeowner with a vacation property, or an adult child in a separate residence, would not consider that second home "covered" by the security system installed at the primary address. Each home needs its own protection.
The same is true digitally, and it is often overlooked.
A family's digital exposure does not stop at one address. It follows every family member:
- the adult child at university;
- the parent living independently; and
- the staff working across more than one property.
Each of these people and their accounts and devices represents a separate point of exposure, and each needs to be covered on its own, not assumed to be safe because "the family" has security somewhere.
This is why Richter Guardian's approach extends coverage across the full footprint of a family, not just one principal or one property.
Extended visibility across multiple households means that a family member living somewhere else entirely is not left outside the perimeter simply because they aren't under the same roof.
The value of thinking about digital executive protection this way
None of this is meant to suggest that digital executive protection and home security are the same thing, because they aren't.
The underlying logic that makes a home security system worth having is exactly the logic that should apply to a family's digital exposure: full coverage, continuous monitoring, a real response when something goes wrong, and protection that follows every member of the family, not just one address.
Families who wouldn't leave a single window unmonitored at home are, in many cases, leaving several digital windows wide open without realizing it.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Protecting Against Real Estate Wire Fraud
Introduction
Real estate wire fraud is a scam where criminals impersonate trusted parties to redirect money during a property transaction.
These transactions often involve large wire transfers, and time-sensitive communication between buyers, sellers, lawyers, real estate agents, title companies, notaries, and financial institutions.
Together, these factors make real estate transactions a prime target for fraud.
For high-net-worth individuals, and executives, the risks can be especially significant.
Property purchases and sales may involve large sums of money, multiple advisors, and sensitive personal or financial information. A single fraudulent email or payment can lead to substantial financial loss.
The most important rule is simple: before sending money, always verify wire instructions by phone using a trusted number you already have, not one provided in an email.
Why it matters
Real estate transactions remain a major target for fraud. In 2025, the FBI’s Internet Crime Complaint Center reported more than 12,000 real estate fraud complaints and over $275 million in reported losses. This was higher than 2024, when losses were about $173 million.
These losses show how common and damaging real estate fraud can be. In many cases, the victim believes they are sending funds to a legitimate party, only to discover that the money was redirected to a fraudulent account.
How the attack works
Attackers often begin by gaining access to an email account involved in the transaction or by impersonating one of the parties. They may silently monitor the conversation and wait for the right moment to intervene.
Once attackers understand the details of the deal, they send a convincing email with fraudulent bank details that redirect the money to the attacker. Attackers may impersonate any party involved in the transaction, such as a real estate agent, lawyer, title company representative, or even the buyer or seller themselves.
Because the attacker may know specifics like dollar amounts, property addresses, and names of people involved, the message can look legitimate, making the email extremely convincing.
How to protect yourself
The most effective protection is independent verification. Before sending any wire transfer, call the intended recipient using a trusted phone number that was provided in person, saved previously, or found through an independently verified source.
Do not rely on contact information included in an email containing wire instructions. If an attacker controls the email conversation, they may also provide a fake phone number to “confirm” the fraudulent details.
This is especially important as AI voice cloning becomes more convincing. A phone call is only useful if the number is trusted. When in doubt, use a number you already know or independently verify the number through an official website or previously established contact.
The same approach should be used for any high-value payment, account change, or request involving sensitive financial information.
Red flags to watch for
Be cautious of:
- Last-minute changes to wire instructions
- Pressure to wire immediately
- Email addresses that look slightly off, such as ‘titlecompany.co’ instead of ‘titlecompany.com’
- Request to confirm payment details only via email
- Unusual urgency, secrecy, or changes in communication style
- New bank account details that were not previously discussed
However, a well-crafted attack may not include any obvious warning signs. Rather than trying to decide whether an email “looks suspicious”, treat all wire instructions as unverified until they are confirmed by phone using a trusted number.
Before sending a wire transfer
Before sending funds, take these steps:
1. Confirm the wire instructions by phone using a known, trusted number.
2. Verify the recipient's name, bank name, account number, routing number, and payment amount.
3. Do not use phone numbers or links provided in the same email as the wire instructions.
4. Be especially cautious about last-minute changes.
5. If anything feels unusual, pause the transaction and contact your advisor, bank, or security team.
How Richter Guardian can help you
Richter Guardian can help reduce the risk of wire fraud through proactive monitoring, personal cybersecurity guidance, and expert support to secure accounts, devices, credentials, and identity-related information.
If you are unsure about a transaction, receive suspicious payment instructions, or want added protection before a high-value transfer, contact us.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.
.png)
