We know.
It’s September, and apparently everyone is required to publish a back-to-school blog. Lunches are being packed. Calendars are filling up. School portals have new passwords. Someone needs money for a field trip. Someone else needs an app downloaded by tomorrow morning.
And somewhere, a cybercriminal is thinking: PERFECT!
Because back-to-school season creates exactly the kind of environment scammers love: lots of new emails, new websites, new software, new payment requests—and people moving quickly.
So yes, this is another back-to-school blog.
But a two-minute reminder now could potentially save your business a much more expensive headache later.
“I was expecting that email” is exactly the problem
Think about how many perfectly legitimate messages arrive at this time of year.
A school asks you to log into a new parent portal.
A sports team sends a registration link.
A teacher shares a Google document.
A daycare requests an e-transfer.
A university asks for tuition or residence fees.
An after-school program wants you to download its new app.
Normally, an unexpected payment request or unfamiliar login page might raise an eyebrow.
In September? Not so much.
And attackers depend on that.
The Canadian Centre for Cyber Security warns that phishing messages frequently impersonate trusted organizations and use links, login pages, attachments and QR codes to steal information or convince victims to transfer money. It also notes that AI is making some of these messages considerably more convincing.
The Canadian Anti-Fraud Centre reported approximately $351 million in fraud losses during the first six months of 2026 alone, with spear phishing among the types of fraud showing notable activity.
So a little extra suspicion this September isn't paranoia.
It's good cyber hygiene.
Before You Click “Pay”
School-related payments deserve an extra moment of attention simply because there are so many of them at this time of year.
Tuition. Registration. Pizza day. Sports. Trips. Uniforms. Fundraising. Supplies.
If you receive an unexpected request for money—or the payment instructions have suddenly changed—don't use the contact information contained in the email to verify it.
Go directly to the school's website, open the portal you normally use, or call a number you already know.
The same rule should apply at work.
New banking information + urgency + email = verify before paying.
It may add two minutes to the process.
Those could be two very profitable minutes.
“Dad, I Just Need to Download This…”
Here's another September classic.
Your child needs something for school.
Right now.
A new piece of software. A browser extension. A PDF reader. An app. A collaboration platform. A website you've never heard of.
And because this is apparently due tomorrow at 8:00 a.m., there isn't exactly time for a procurement committee meeting.
On a family computer, you should still be cautious.
On a computer you also use for work, you should be very cautious.
New applications and browser extensions can introduce security and privacy risks. The Cyber Centre recommends reviewing the privacy and access requirements of apps before installing them and keeping operating systems and applications updated.
If your business allows employees to work remotely, this is worth reminding your team about too.
Corporate devices should remain corporate devices, even during science fair season.
The Back-to-School Five-Minute Cyber Check
Nobody needs another 37-point checklist in September.
So let's keep this one short:
Stop before paying. Unexpected request? Changed banking information? Verify it using a second, trusted method.
Don't automatically trust a familiar name. Email addresses, websites and even communications from compromised accounts can look legitimate.
Think before installing. Avoid installing school-related apps, browser extensions or software on company-owned devices without approval.
Use MFA. Especially on email, banking, Microsoft 365, Google and other important accounts. The Cyber Centre continues to recommend MFA as an important defence against account compromise.
When something feels slightly off, ask. Your IT or cybersecurity provider would much rather look at a suspicious email before you click than investigate it afterward.
That's it.
No homework.
Cybersecurity Has Seasons Too
Cybercriminals are opportunistic.
Tax season creates tax scams. Holidays create delivery and gift-card scams. Major news events create fake donation pages.
And back-to-school season creates a wonderful mixture of new technology, unfamiliar communications, payment requests, busy parents and shortened attention spans.
You don't need to become suspicious of every email from your child's school.
You just need to remember that being expected doesn't automatically make a message legitimate.
Take the extra few seconds.
Check the sender.
Verify the payment.
Think before downloading.
And maybe—just maybe—this year's obligatory back-to-school blog really did save you some money.
We are happy to look at this with you
If you are not sure where you stand on any of the above, that is a normal place to be, and it is a short conversation rather than a big project. Book a 20-minute consultation with one of our Cybersecurity Experts and we will walk through it with you.