For much of the past month, someone has been trying to break into my Apple account. I receive regular e-mail and text notifications confirming a password change, which are soon followed by spoofed phone calls with caller ID that purports to be from the company but likely originates from Russia. As my Globe and Mail op-ed notes, I know enough to ignore the calls, delete the messages, and ensure I have two-factor authentication enabled to help keep hackers out.
The same can’t be said for many Canadians, however – particularly seniors who are too often vulnerable to online fraud. The Canadian Anti-Fraud Centre reports that losses from fraud exceeded $700 million in 2025, with those over the age of 60 losing more per incident than any other age group. The average individual loss exceeds $21,000, which can be serious money for many, especially retirees dependent on savings and government pensions. In fact, that estimate surely understates the severity of the problem since we know that only a tiny percentage of fraud cases are ever reported. Many victims, distraught over being deceived, blame themselves and are too embarrassed to report the incidents to the authorities.
The frauds that target seniors typically rely on abusing their trust. Calls or e-mails that claim to come from tech support or a local bank create a false sense of urgency and too many fall victim to the scams. Technology plays an increasingly important role through voice cloning, phony websites, and attempts to steal passwords. The common theme is to create panic and prey on those who tend to be more isolated.
Seniors may be the most at risk for these frauds, yet you wouldn’t know it from government policy. Ottawa’s plans for online harms have prioritized protecting kids, with the controversial social media ban for those under 16 as a centrepiece. Yet a nearly identical ban was just struck down as unconstitutional by France’s constitutional court, and the Canadian version would likely face the same challenge should it become law. Beyond the doubts about its constitutionality, critics emphasize that a safer online environment comes from establishing age-appropriate design and enforceable regulatory requirements, not by seeking to ban a particular cohort of users.
The same principle applies to online fraud. No one would ever consider blocking internet use for seniors, so it falls to the government to deal with the fraud head-on. Digital literacy is part of the solution, but my experience with Apple demonstrates how perpetrators leverage the security notifications, caller ID, and password safeguards that digital literacy programs highlight. The problem is that even vigilant targets can be scammed, and the losses are often worst for those who can least afford it.
The government has responded with a National Anti-Fraud Strategy consultation that ran earlier this year, acknowledging that Canadian businesses that hold sensitive information generally lack proactive duties to prevent, detect, disrupt, and respond to fraud threats. Its response includes plans for a new Financial Crimes Agency to investigate complex fraud. Moreover, the government will now require banks to maintain fraud-prevention policies and to allow customers to lower their own transaction limits or disable account features that are frequent targets of fraud. These are useful measures, but too much emphasis is placed on consultations and consumer responsibility rather than on clear-cut obligations on those best positioned to identify and counter fraud.
For example, British banks are now required to reimburse victims of authorized push payment fraud, which occurs when a fraudster tricks a victim into sending money from their own bank account to a fraudulent account. Because the victim must log in and approve the transfer themselves, recovering the money is very difficult. The British rule places the cost of scams on the institutions best placed to detect them and has already resulted in most losses being repaid. Canada does not have a similar rule, leaving Canadians at greater risk of loss.
The government has contemplated new measures to address telecom and digital fraud, but others have moved faster to address the issue. Australia has introduced plans for network-level blocking of spoofed calls and texts, verification requirements for platform advertisers, and obligations to remove fraudulent ads. The measures are backed by penalties of up to $50 million, creating incentives to act. The Canadian approach has relied on caller ID requirements, but my experience with Apple highlights the limitations of that policy.
Meanwhile, Singapore has focused on how fraud is carried out online by establishing regulations requiring banks to implement cooling-off periods for logins on new devices and to provide real-time transaction alerts, along with mandating that telecom providers block text messages from unregistered senders. If the institutions fail to do their jobs, they must fully reimburse victims, with no cap on compensation.
The solutions to online harms, whether risks to kids or seniors, will not come from limiting access. Rather, they require legal frameworks that mandate safer environments and impose real consequences for intermediaries such as social networks, banks, and telecom providers that fail to do their part.











