(Disponible uniquement en anglais)
par : Amanda Farina
Abstract
Digital fraud targeting older Canadians has reached crisis proportions. In 2024 alone, the Canadian Anti-Fraud Centre recorded over $643 million in fraud losses, with seniors aged sixty and above accounting for 40.3 percent of total dollar losses. The true scale of the problem is almost certainly far greater: the CAFC estimates that only five percent of incidents are ever recorded. Despite this, Canadian law remains a patchwork of general criminal provisions, provincial consumer protection statutes, anti-spam legislation, and voluntary banking measures. This framework was not designed for today’s AI-driven fraud landscape and has not been meaningfully reformed to protect older adults. This paper diagnoses six structural gaps in the existing framework: the AI gap, the definitional gap, the enforcement gap, the banking gap, the underreporting gap, and the intersectional gap. Drawing on legal developments in the United Kingdom, Australia, and the United States, the paper proposes five legislative reforms, including a federal Elder Digital Fraud Act, mandatory fraud-prevention duties for banks, targeted Criminal Code amendments, AI-specific liability for synthetic media fraud, and a national coordination framework. Digital elder fraud is not a consumer protection problem at the margins of Canadian law. It is an elder justice crisis, and the law must treat it as one.
Section I: Introduction
In February 2025, Erin Rud was convicted of fraud over $5,000 for her role in a sophisticated grandparent scam that targeted hundreds of elderly Canadians across the country.1 Her sentence: eighteen months to be served in the community, with conditions permitting her to leave the house regularly to go to the gym.2 One of her victims, eighty-five-year-old Francine Jarry of Montreal, had been manipulated into handing over $4,200 in cash to a masked man who came to her door – money she has never recovered.3 The restitution order made in her favour is unenforceable without her filing a civil suit against her own scammer.4 Jarry’s response to the sentence was blunt: “The punishment and the sentencing are ridiculous, absolutely ridiculous.”5
She is not wrong. But the problem runs far deeper than one lenient sentence.
Digital fraud targeting older Canadians has become one of the most pervasive and economically devastating crimes in this country, and the legal system’s response has been, at every level, inadequate. In 2024, seniors aged sixty and above accounted for 40.3 percent of the total dollar losses reported to the Canadian Anti-Fraud Centre (CAFC), which recorded over $643 million in fraud-related losses that year.6 The CAFC estimates that just five percent of fraud incidents are ever reported to authorities, suggesting that actual annual losses may reach into the billions.7 The fraud landscape has been transformed by artificial intelligence: scammers now deploy deepfake videos, voice clones, and AI-generated websites so convincing that even sophisticated users struggle to detect them.8 One Regina senior, Jill Finn, described a call she received from what she was certain was her granddaughter’s voice, complete with the young woman’s “little ups and downs.” It was an AI-generated clone.9 The technology has outpaced both the fraudsters of a decade ago and the lawmakers of today.
Canadian law has not kept pace. The existing response to digital elder fraud is a patchwork: general criminal provisions that make no meaningful distinction between defrauding a corporation and preying on a cognitively vulnerable eighty-five-year-old; provincial consumer protection statutes designed for an era of door-to-door salespeople; anti-spam legislation that has never seriously grappled with AI-assisted phishing; and a financial sector in which banks bear no legal obligation to pause a plainly suspicious transaction.10 As Anthony Quinn, president of the Canadian Association of Retired Persons, has put it: “If the law is so weak and has so few teeth that there’s no disincentive for the scammers, then what is Canada doing?”11 It is a question this paper takes seriously.
This paper argues that Canadian law fails older adults at every stage of the digital fraud lifecycle, before the crime occurs, during it, and after it, and that this failure is not incidental but structural. The existing framework was not designed with aging populations, digital technology, or the intersection of the two in mind. Meaningful protection will require not incremental adjustment, but deliberate, elder-conscious legal reform. Part II surveys the landscape of digital fraud targeting Canadian seniors and the factors that make older adults disproportionately vulnerable. Part III maps the existing legal framework across criminal, civil, regulatory, and elder-specific law. Part IV identifies the critical structural gaps in that framework. Part V draws on comparative experience from the United Kingdom, Australia, and the United States. Part VI proposes concrete reforms. The paper concludes by arguing that digital elder fraud is not merely a consumer protection problem; it is an elder justice crisis, and the law must treat it as one.
Francine Jarry has not received a single dollar of her restitution. Erin Rud has served her sentence. The scam networks that employed them both are still operating.12
Section II: The landscape of digital fraud targeting Canadian seniors
A. A Growing and Wealthy Target Population
To understand why digital fraud targeting seniors has reached crisis proportions in Canada, one must first understand the demographic and economic context in which it operates. As of July 1, 2023, approximately 7.6 million Canadians were aged 65 and older, accounting for nearly one-fifth of the total population, and by 2030, seniors are projected to represent between 21.4 and 23.4 percent of all Canadians.13 This is not merely a demographic curiosity. It represents the largest concentration of accumulated private wealth in Canadian history. Seniors hold substantial retirement savings, home equity, and pension income built over lifetimes of work, assets that are, by definition, largely irreplaceable. Researchers have long noted that the resources of many seniors, including homeownership, savings, and pensions, make them structurally attractive targets for financial fraud.14 Fraudsters are not random in their predation. They are rational actors, and the math points them squarely at Canada’s aging population.
The consequences of victimization are correspondingly severe and frequently permanent. Unlike a younger fraud victim who may have decades of earning capacity ahead, older persons who are victimized lose assets accumulated over a lifetime, with limited opportunities to recover from financial losses due to retirement, limited employment options, or physical and cognitive disabilities.15 A senior defrauded of $50,000 in retirement savings cannot simply work overtime to recover. The loss is, in many cases, final.
B. The Taxonomy of Digital Elder Fraud
Digital fraud targeting seniors in Canada is not a single phenomenon but a family of related schemes, each exploiting different vulnerabilities and operating through different digital channels. The major categories warrant individual examination.
Grandparent and Emergency Impersonation Scams
The grandparent scam is perhaps the most emotionally brutal form of elder fraud. A caller, often using AI-generated voice-cloning technology to mimic a grandchild’s actual voice, contacts an older adult claiming to be a family member in crisis: arrested, injured, or in urgent need of bail money. In one documented Ontario case, scammers used voice cloning combined with spoofed caller identification and a fake lawyer to convince an elderly woman to send over $21,000.16 A Regina senior, Jill Finn, described receiving a call from what she was certain was her granddaughter’s voice, complete with the young woman’s characteristic “little ups and downs” in her speech; it was an AI-generated clone.17 The scheme works precisely because it weaponizes the deepest instinct of a grandparent: the unconditional impulse to protect a grandchild. Urgency is manufactured, deliberation is foreclosed, and money changes hands before reason can intervene.
Investment Fraud and Cryptocurrency Scams
Investment scams accounted for half of all funds lost to fraud in Canada in 2024, and reports targeting seniors have surged dramatically.18 These schemes frequently deploy AI-generated deepfake videos of trusted public figures to lend false legitimacy to fraudulent investment platforms. In one notable Canadian case, an AI-generated video appeared to show Prime Minister Mark Carney endorsing a cryptocurrency investment allegedly backed by the federal government; a retired teacher from Prince Albert, Saskatchewan, lost $2,800 as a result.19 A particularly insidious variant allows early victims to withdraw small initial “gains”, establishing a false sense of credibility before the larger extraction occurs.20
Romance Scams
Romance scams were the second most lucrative fraud category targeting Canadian seniors in 2024, responsible for $54 million in losses.21 Fraudsters create fictitious personas on dating platforms and social media, often claiming to be military personnel, engineers, or professionals working abroad, and invest weeks or months cultivating emotional intimacy before engineering a financial crisis requiring urgent monetary transfer. AI face-swapping technology is increasingly used to make these personas visually convincing during video calls.22 The exploitation of loneliness and the human need for connection make romance scams among the most psychologically devastating forms of elder fraud, combining financial loss with profound emotional betrayal.
Government Impersonation Scams
Fraudsters impersonating the Canada Revenue Agency, Service Canada, and law enforcement agencies represent a persistent and particularly effective category of elder fraud. These schemes exploit the deference that many older Canadians, raised in an era when government authority was largely unquestioned, feel toward official institutions. Callers use spoofed government phone numbers and threaten victims with arrest, deportation, or suspension of benefits unless immediate payment is made through gift cards, cryptocurrency, or wire transfer.23 The CRA has itself confirmed that these scams have reached endemic proportions, with fraudulent messages circulating through phone, text, and email simultaneously.24
Phishing, Smishing, and Bank Investigator Scams
Those aged 55 and older are more likely than younger Canadians to be victimized by phishing and the unauthorized use of their bank or credit cards.25 Bank investigator scams, in which a caller posing as a fraud investigator from the victim’s own financial institution convinces the victim to withdraw savings or surrender their debit card, have grown significantly, with bank investigator fraud registering the largest single-category increase in CAFC reports in 2024 at 16.5 percent.26 AI-enhanced caller ID spoofing now makes these calls appear to originate from the victim’s actual bank phone number, making independent verification feel redundant.
C. Why Seniors Are Disproportionately Targeted: The Vulnerability Architecture
The disproportionate targeting of older Canadians is not accidental, nor is it simply a function of wealth. Fraudsters exploit a specific architecture of vulnerabilities, cognitive, psychological, social, and structural, that converges in aging populations with particular force.
i. Cognitive Factors
A substantial and growing body of neuroscientific research establishes that normal aging is accompanied by changes in cognition that increase susceptibility to deception. Research demonstrates that lower cognitive function is associated with greater susceptibility to scams among older adults, and that this susceptibility is a consequence of subtle cognitive decline even among individuals who show no clinical signs of impairment.27 The brain regions most implicated, those governing executive function, working memory, and the evaluation of social trustworthiness, are among the earliest affected by age-related neurological change. Importantly, vulnerability to financial exploitation may serve as an early behavioural warning sign of future cognitive decline, with the entorhinal cortex, a region affected very early by Alzheimer’s disease, implicated in financial decision-making capacity.28 Scammers, in effect, prey on neurological change before it is clinically visible.
ii. Psychological and Social Factors
Certain personality traits associated with older generations, including a trusting nature, politeness, and compassion, increase susceptibility to fraud, and perpetrators deliberately exploit these traits through tactics of isolation, urgency, and fear.29 Social isolation compounds the risk: many older Canadians live alone, particularly after the loss of a spouse, and the resulting loneliness increases openness to engagement with unknown callers or online contacts.30 Isolation also removes the informal checks, such as a spouse, a friend, or a family member, that might otherwise prompt a second opinion before money is transferred.
iii. The Underreporting Crisis
One of the most legally significant features of digital elder fraud is its systematic underreporting. Laura Proctor, an elder abuse prevention consultant with Elder Abuse Prevention Ontario, reports that the most prevalent feeling she hears from seniors who have been scammed is shame, and that many refuse to report for fear that authorities will question their competency and threaten their independence.31 A study on mass marketing fraud identified a cluster of barriers to reporting, including feelings of shame and guilt, not knowing where to turn, fear that reporting would lead to a loss of legal or financial control, and lack of confidence in the ability of authorities to respond.32 These barriers are not incidental: they are features of the fraud itself. Scammers routinely instruct victims not to tell anyone, and the resulting silence protects perpetrators as much as it harms victims. The legal and policy implications of systematic underreporting are profound: it means that every statistic cited in this paper is almost certainly a significant undercount of the true scale of the crisis.
Section III: The existing legal framework
The Canadian legal response to digital fraud targeting seniors is distributed across four distinct domains: criminal law, civil law, regulatory and consumer protection law, and elder-specific legislation. Each domain offers some measure of protection. None of them, individually or collectively, was designed with digital elder fraud in mind, and the cumulative effect is a framework that is reactive, fragmented, and systematically unable to protect the most vulnerable.
A. Criminal Law
i. Fraud and the General Offence Provisions
The primary criminal law vehicle for prosecuting digital fraud is section 380 of the Criminal Code, which creates the offence of fraud, defined as defrauding another person of property, money, or any valuable security by deceit, falsehood, or other fraudulent means.33 The offence carries a maximum penalty of fourteen years’ imprisonment where the value of the fraud exceeds five thousand dollars, and a mandatory minimum of two years where it exceeds one million dollars.34 The mens rea requirement, established in R v Theroux, demands subjective knowledge of the prohibited act and knowledge that it could have the consequence of depriving another of their economic interests.35 Section 380 is broad enough to capture the full range of digital elder fraud schemes, grandparent scams, investment fraud, CRA impersonation, and romance scams, all of which satisfy its definitional elements without difficulty.
The Criminal Code also addresses identity-related offences that arise in digital fraud contexts. Section 402.2 creates the hybrid offence of identity theft, the knowing possession of another person’s identity information in circumstances giving rise to a reasonable inference that it will be used to commit an indictable offence involving fraud, deceit, or falsehood.36 Section 403 creates the offence of identity fraud, fraudulently personating another person with the intent to gain an advantage, obtain property, or cause disadvantage to the person being personated.37 The definition of “identity information” under section 402.1 is broad, encompassing fingerprints, voice prints, Social Insurance Numbers, financial account numbers, and digital signatures, a definition that on its face captures AI-generated voice clones used in grandparent scams.38
ii. Sentencing Provisions and Age as an Aggravating Factor
Parliament has made two targeted amendments to the Criminal Code to account for the particular vulnerability of older victims. The first, introduced by Bill C-21 in 2011, added section 380.1(1)(c.1), which requires sentencing courts to treat as an aggravating circumstance the fact that a fraud offence “had a significant impact on the victims given their personal circumstances, including their age, health and financial situation.”39 The second amendment, introduced by Bill C-36 in 2012, incorporated vulnerability due to age and personal circumstances as an aggravating factor in the general sentencing provisions under section 718.2.40
These amendments, while symbolically important, have faced sustained criticism. As one commentator has observed, prior to Bill C-36 coming into force, sentencing judges were already taking the vulnerability of elder victims into account as an aggravating factor; the legislation simply codified what courts had already been doing.41 In R v Kralik, decided in 2006, six years before Bill C-36, the sentencing judge stated that abuse of a frail, isolated elderly person who “was not as sharp as she once was” could be considered an aggravating circumstance.42 The amendment thus added little beyond a legislative statement of existing common law. More fundamentally, aggravating factors at sentencing only matter if perpetrators are identified, charged, prosecuted, and convicted, a sequence that rarely occurs in the context of digital elder fraud, where perpetrators are typically anonymous, offshore, and operating at scale.
The sentencing crisis in elder fraud cases is not merely theoretical. In R v Rud, Erin Rud, convicted of fraud over $5,000 for her role in a grandparent scam targeting hundreds of victims, received eighteen months to be served in the community, with conditions permitting regular gym visits.43 A comparable perpetrator arrested and sentenced in the United States received six and a half years in federal prison.44 The disparity, as Queen’s University law professor Lisa Kerr has noted, reflects the substantially more rigid and punitive sentencing guidelines that apply at the federal level in the United States.45 Canada’s sentencing framework for elder fraud, even with its aggravating factors, produces outcomes that neither deter perpetrators nor reflect the severity of the harm caused.
iii. Practical Limitations of Criminal Law
The criminal law framework faces three structural limitations that substantially diminish its effectiveness in the digital elder fraud context. First, the anonymity problem: digital fraud is deliberately designed to conceal the identity and location of perpetrators. Grandparent scam networks operating out of Montreal use offshore money mules, encrypted communications, and constantly rotating phone numbers; over the past four years, police have arrested at least fifty people in the Montreal area linked to three major grandparent scam networks, and the networks have continued operating.46 Arrests, when they occur, tend to capture couriers and low-level operatives rather than the architects of the fraud.
Second, the cross-border problem: the majority of digital fraud targeting Canadian seniors originates outside Canada. Several seniors consulted by the National Seniors Council noted that when fraud is committed from outside Canada, it can be nearly impossible to track and punish the perpetrator.47 CAFC data confirm that a significant proportion of suspected fraud operations are located abroad, with Canadian enforcement agencies having no jurisdiction to compel cooperation, production of evidence, or extradition without bilateral treaty mechanisms that are slow, resource-intensive, and rarely invoked for fraud cases of this scale.48
Third, the capacity problem: the Auditor General of Canada found that the RCMP and other agencies are under-resourced to deal with cybercrime, and called for a one-stop shop for Canadians to report it.49 The criminal law, in the context of digital elder fraud, is a tool that works well on paper and poorly in practice.
B. Civil Law
i. Tort Remedies
Victims of digital elder fraud may pursue civil remedies in tort. The most directly applicable causes of action are the tort of deceit, requiring proof of a fraudulent misrepresentation made knowingly or recklessly with intent to induce reliance and resulting in damage, and negligent misrepresentation under the principles established in Hedley Byrne & Co Ltd v Heller & Partners Ltd and adopted in Canadian jurisprudence.50 Unjust enrichment may provide an additional avenue where the victim can trace assets into the hands of an identifiable defendant.
In practice, civil remedies offer almost no meaningful protection to senior victims of digital fraud. The fundamental problem is identification: a victim cannot sue a person they cannot find. Digital fraudsters operate through layers of technological obfuscation, VPNs, spoofed phone numbers, cryptocurrency wallets, and international money mule networks that render the identification and service of defendants practically impossible. Even where a domestic perpetrator is identified, the question of financial recovery is bleak: Francine Jarry obtained a court-ordered restitution award of $4,200 against Erin Rud, and was told by the court that there was no mechanism to enforce it outside of filing a separate civil suit.51 Restitution orders under section 738 of the Criminal Code, while available in principle, are in practice unenforceable against defendants who have already dissipated their assets through the fraud network.
ii. Bank Liability: The Emerging Frontier
The most legally significant and underdeveloped area of civil law in this context concerns the potential liability of financial institutions for permitting or facilitating fraudulent transactions. Canadian courts have historically adopted a restrained approach to bank liability in fraud cases. In McDonald v Toronto-Dominion Bank, the Ontario Court of Appeal held that there is no general category of proximity between banks and their customers in relation to “banking services,” and specifically declined to impose a general duty to detect fraud.52
However, the law in this area is evolving. The British Columbia Court of Appeal found that a bank with knowledge of a “prevailing fraud” could form the basis for a duty to inquire and to warn if it appeared the customer might be falling victim to that type of scam, and declined to summarily dismiss the claim, finding it a genuine issue to be resolved at trial.53 In Quebec, the Superior Court in Alfagomma held that where transactions are “objectively out of the ordinary,” a bank’s “duty to act with reasonable prudence and diligence” requires it to do something, and imposed liability where HSBC failed to enforce the account’s transfer limits and accepted a single signature where two were required.54
The relevance of the English Quincecare duty to this developing Canadian jurisprudence deserves careful attention. In Barclays Bank plc v Quincecare Ltd, the English court established that a bank must refrain from executing a payment instruction if it has reasonable grounds to believe the instruction may be an attempt to misappropriate funds.55
While the UK Supreme Court in Philipp v Barclays Bank subsequently limited Quincecare’s application to authorized push payment fraud by individual customers, the principle that banks can bear liability for executing transactions in the face of obvious red flags remains alive in both English and emerging Canadian law.56 The gap in Canadian law is that this duty, where it exists at all, is judicially implied and highly fact-specific; there is no statutory obligation compelling Canadian banks to identify, pause, or flag transactions that match the known profile of elder fraud. TD Bank has voluntarily introduced a form for customers making large cash withdrawals that warns of scam activity, but lawyers have noted that such forms provide uncertain protection both for the customer and the bank if it cannot be shown the customer understood what they were signing.57 Voluntary measures are no substitute for legal obligations.
C. Regulatory and Consumer Protection Law
i. Canada’s Anti-Spam Legislation
Canada’s Anti-Spam Legislation (CASL), in force since 2014, prohibits the sending of commercial electronic messages without the recipient’s express or implied consent, and also prohibits the installation of malware and the unauthorized alteration of transmission data.58 CASL is enforced primarily by the CRTC, with penalties of up to one million dollars per violation for individuals and ten million dollars for organizations.59
CASL is largely irrelevant to the digital elder fraud problem. Its consent framework was designed to regulate legitimate commercial marketers who send bulk email without authorization, not criminal fraud networks that have no interest in compliance. The CRTC has stated that it will work with international counterparts to enforce CASL against foreign actors, but acknowledged that the effectiveness of any investigation may be limited by the ability to access information residing outside Canada.60 A criminal gang running a grandparent scam operation from an offshore call centre does not concern itself with CASL consent requirements. The legislation does not address AI-generated voice calls, deepfake videos, or social media impersonation, the primary vectors of modern digital elder fraud. Its enforcement record against fraud-adjacent conduct has been modest: in 2021-22, CRTC investigations under CASL resulted in a total of $327,500 in administrative monetary penalties.61 That figure is trivially small compared to the billions lost annually to fraud.
ii. Provincial Consumer Protection Statutes
Provincial consumer protection legislation, such as Ontario’s Consumer Protection Act, 2002, provides certain remedies for unfair practices, misleading representations, and unconscionable transactions.62 However, these statutes are directed at the regulation of commercial relationships between businesses and consumers operating within a provincial marketplace. They were not designed to address strangers impersonating government agencies, family members, or bank investigators in digital communications. Their enforcement mechanisms presuppose an identifiable domestic business with a legal presence, a presupposition that digital elder fraud systematically defeats.
iii. Financial Sector Regulation
FINTRAC, Canada’s financial intelligence unit, requires reporting entities, including banks and money services businesses, to report suspicious transactions and large cash transactions.63 These obligations exist primarily for the purpose of detecting money laundering and terrorist financing, and any elder fraud detection benefit is incidental. There is no FINTRAC-based mechanism that flags transactions fitting the profile of elder fraud, large cash withdrawals by elderly customers at the direction of an urgent caller, as a distinct category requiring elevated scrutiny. OSFI, the federal banking regulator, similarly does not impose elder-specific transaction monitoring obligations on regulated financial institutions.64
D. Elder-Specific Legislation
There is no specific crime of “elder abuse” in the Criminal Code of Canada.65 Unlike many American states, which have enacted specific elder abuse statutes that define financial exploitation as a distinct criminal offence with enhanced penalties, Canadian law addresses elder fraud through general provisions supplemented by aggravating factors at sentencing. At the provincial level, elder abuse legislation varies considerably. Ontario’s Long-Term Care Homes Act and its successor legislation address abuse within long-term care settings; the Substitute Decisions Act regulates capacity and powers of attorney. Neither instrument addresses digital fraud perpetrated by strangers against community-dwelling seniors.66 British Columbia’s Adult Guardianship Act provides for investigation and intervention in cases of abuse and neglect of adults, but its mechanisms are designed for relational abuse rather than stranger-perpetrated digital crime.67 No province has enacted legislation specifically addressing digital fraud targeting older adults or imposing obligations on financial institutions to protect senior customers. The resulting picture is one of comprehensive legal inadequacy. Canadian law knows how to punish fraud; it does not know how to prevent it, protect vulnerable older adults, or impose legal obligations on the institutions best positioned to intervene: banks.
Section IV: Structural gaps in the Canadian legal framework
The preceding section mapped what Canadian law does. This section diagnoses what it does not do, and why those omissions are not incidental oversights but structural failures that will persist unless deliberately addressed. Six gaps emerge from the analysis: the AI gap, the definitional gap, the enforcement gap, the banking gap, the underreporting gap, and the intersectional gap. Together, they constitute a comprehensive indictment of the current framework’s adequacy.
A. The AI and Technology Gap: Law Designed for Yesterday’s Fraud
The most fundamental gap in Canadian law is temporal. The criminal and regulatory framework governing fraud was constructed in an era of human deception, a fraudster calling on a phone, sending a letter, or knocking on a door. It was not designed for an era in which a single actor can deploy AI-generated voice clones, deepfake videos, and personalized phishing emails simultaneously at an industrial scale.
Canada has no specific deepfake law as of 2025.68 The Criminal Code’s identity fraud provisions, sections 402.1 through 403, define “identity information” to include a “voice print,” which may encompass AI-generated voice clones in principle.69 But this interpretive extension has never been tested in Canadian courts in the context of AI-generated audio, and the definitional provision was enacted in 2009, fifteen years before voice-cloning technology became widely accessible to criminal networks.70 As of the date of the most recent analysis, there is no reported civil decision in Canada where a victim of deepfake technology has successfully brought a legal action against a creator of deepfake content.71 The law exists in name; its application to AI-generated fraud is almost entirely untested.
Bill C-63, the Online Harms Act, introduced in February 2024, represented a partial legislative response to the deepfake problem, but it was prorogued along with Parliament in January 2025 and died on the order paper before receiving Royal Assent.72 Even if it had passed, Bill C-63 was primarily directed at protecting children from sexual exploitation and at regulating platform content moderation; it did not specifically address AI-generated fraud targeting older adults, impose obligations on financial platforms, or create new investigative tools for law enforcement in the elder fraud context.73
The practical consequence of this legislative vacuum is that Canadian seniors defrauded through AI voice cloning or deepfake video impersonation must rely on general fraud provisions enacted decades before these technologies existed, applied through interpretive arguments that have no binding precedent. Governance remains fragmented, with media law, cybersecurity policy, financial regulation, and AI governance operating in silos, allowing malicious actors to exploit institutional gaps.74 The law does not just lag behind the technology; it is operating in an entirely different era.
B. The Definitional Gap: Who Counts as an Elder?
A framework designed to protect older adults requires, at a minimum, a definition of who qualifies for that protection. Canadian law provides none. No Canadian law that applies to abuse or neglect applies exclusively to people over 65 years of age. In this sense, there is no such thing as an “elder abuse law” in Canada.75 The Criminal Code references age as an aggravating factor at sentencing,g but does not define the threshold at which a victim’s age becomes legally relevant. Section 380.1(1)(c.1) requires courts to consider the “personal circumstances, including age” of victims without specifying what age matters or why.76 Provincial statutes addressing adult protection use varying definitions, some referring to “adults”, others to “seniors”, others to “vulnerable persons”, without a consistent standard.77
This definitional vacuum has three concrete consequences. First, it prevents the development of elder-specific legal obligations; one cannot impose duties specifically protecting a class of persons that the law has never defined. Second, it produces inconsistency in the application of aggravating factors at sentencing, as judges must make individualized determinations about when a victim’s age triggers enhanced consideration without legislative guidance. Third, and most significantly for this paper, it makes it legally impossible to impose age-sensitive transaction monitoring obligations on financial institutions because Canadian law has no operative concept of an “elder” customer whose transactions warrant heightened scrutiny.
The contrast with the United States is instructive. The federal Elder Justice Act defines an “elder” as an individual aged sixty or older, creating a legislative foundation for a comprehensive suite of protective obligations that flow from that definition.78 Canada’s approach, by contrast, treats age as a sentencing consideration rather than a legal status, a choice that dramatically limits the law’s protective capacity.
C. The Enforcement Gap: A System That Cannot Catch What It Cannot Reach
Even where Canadian criminal law is theoretically applicable to digital elder fraud, enforcement faces structural obstacles that render it largely ineffective in practice. Three specific enforcement failures deserve attention.
First, the prosecution rate for digital fraud against seniors is vanishingly low. It is estimated that only five to ten percent of all fraud and cybercrime incidents are reported in Canada,79 and of that fraction, only a small subset result in charges, and a smaller subset still result in convictions. The gap between the scale of the problem and the reach of enforcement is not a resource allocation failure alone; it reflects the genuine jurisdictional and evidentiary challenges of prosecuting crimes that are designed to be anonymous, cross-border, and technically complex.
Second, the cross-border architecture of digital elder fraud networks systematically defeats Canadian enforcement jurisdiction. Despite multiple waves of arrests targeting at least fifty individuals in Montreal-area grandparent scam networks over four years, new networks have continued to emerge and operate.80 Enforcement has succeeded in disrupting individual cells while leaving the underlying architecture of the criminal enterprise intact.
Third, the Auditor General’s finding that the RCMP and partner agencies are under-resourced for cybercrime enforcement has never been adequately addressed through new investment.81 The RCMP launched a new national cybercrime and fraud reporting system in November 2025, which is a welcome development, but a reporting system is not an enforcement capacity. Only a small percentage of cybercrimes or frauds are reported to police in Canada, making it difficult for law enforcement to keep up with the ever-changing threat landscape.82 Encouraging more reporting without building the enforcement infrastructure to respond to those reports creates a cruel expectation gap for victims who come forward.
D. The Banking Gap: The Last Line of Defence Has No Legal Obligation to Defend
Of all the structural gaps identified in this paper, the most legally significant and the most amenable to targeted reform is the absence of any statutory obligation on Canadian financial institutions to identify, flag, or pause transactions that fit the profile of elder fraud.
Banks occupy a uniquely privileged position in the digital elder fraud lifecycle. They are present at the moment the crime is completed: when a senior walks into a branch to withdraw their retirement savings at the direction of a fraudster, or initiates a wire transfer to an overseas account. Bank tellers, fraud detection algorithms, and transaction monitoring systems all possess information that could, in principle, interrupt fraud before money leaves the country. Yet as established in Section III, Canadian law does not require them to act on that information. The Ontario Court of Appeal in McDonald v Toronto-Dominion Bank held that there is no general category of proximity between banks and their customers that includes a duty to detect fraud.83
The result is a system in which the institution best positioned to prevent elder fraud bears the least legal responsibility for doing so. TD Bank has voluntarily introduced a form for customers making large cash withdrawals, warning of scam activity, but lawyers have observed that such forms provide uncertain legal protection if the bank cannot establish that the customer understood what they signed.84 Voluntary measures, adopted selectively and without standardization, are no substitute for legal obligations applicable across the industry.
The gap is especially stark when considered alongside the developing jurisprudence canvassed in Section III. The BC Court of Appeal’s reluctance to summarily dismiss a duty-to-warn claim against a bank with knowledge of a prevailing fraud suggests that Canadian courts are open to the evolution of bank liability in this space.85 But judicial evolution is slow, fact-specific, and unpredictable. It cannot substitute for a clear legislative statement that financial institutions serving senior customers bear affirmative obligations to protect them, obligations with teeth.
E. The Underreporting Gap: A Legal System That Punishes Disclosure
Section II established the sociological dimensions of underreporting. This section focuses on its legal consequences. A legal framework that depends on victim reports to function, through criminal prosecution, civil litigation, or regulatory enforcement, is structurally compromised when the victims it serves are systematically unable or unwilling to report.
The barriers to reporting identified in the literature are not merely psychological; many of them are legally constructed. Seniors report that they fear reporting fraud to authorities because they worry that doing so will cause others to question their competency and threaten their independence.86 This fear is not irrational; it reflects a real dynamic in which disclosure of cognitive vulnerability can trigger guardianship proceedings, loss of driving privileges, or family interventions that seniors experience as a loss of autonomy. Canadian law, which links capacity to the ability to make legally binding decisions, creates a structural disincentive for older fraud victims to come forward. The legal system simultaneously needs their disclosure and punishes them for making it.
A government-commissioned study on mass marketing fraud found that one reason seniors resist reporting is a fear that reporting would lead to a loss of legal or financial control.87 No Canadian statute or policy addresses this deterrent directly. There is no provision analogous to the protections offered to witnesses in other contexts, no assurance that a fraud report cannot be used to initiate guardianship or capacity proceedings against the reporting victim. The legal system asks seniors to trust it with their most vulnerable moments, while offering no protection against the consequences of that trust.
F. The Intersectional Gap: The Law’s Failure to See Compounded Vulnerability
The final structural gap is perhaps the most undertheorized. Canadian law treats victims of elder fraud as a relatively homogeneous class, distinguished primarily by age. It does not account for the compounding vulnerabilities that make certain subgroups of older Canadians dramatically more exposed than the general elder population.
Research consistently shows that social isolation, cognitive decline, lower financial literacy, and dependence on others for daily activities compound the risk of fraud victimization beyond what age alone predicts.88 Immigrant seniors who lack fluency in English or French face additional barriers: they may be more vulnerable to impersonation by government agencies, more reluctant to report to law enforcement, and less able to navigate financial institutions’ complaint systems. Research confirms that scam and fraud risks are elevated during periods of social isolation, particularly for minority elders with cognitive impairments, many of whom face limited resources and a lack of language fluency that further increases their vulnerability.89 Seniors living alone, a demographic that grows as the population ages, face the additional risk that the social check of a trusted confidant is absent at the moment a fraudster calls.
Canadian law is blind to these compounding factors. Aggravating factors at sentencing acknowledge age and vulnerability in general terms; they do not require prosecutors or courts to engage with the specific intersectional circumstances that made a particular victim especially vulnerable to a particular fraud. Regulatory frameworks do not mandate that financial institutions develop culturally sensitive or language-accessible elder fraud protection programs. The law assumes a prototypical elder victim, educated, English-speaking, and community-connected, and it designs its protections around that prototype. The result is systematic underprotection of those who need protection most.
Taken together, these six gaps reveal that Canada’s legal response to digital elder fraud is not merely inadequate but structurally so. Patching individual provisions will not suffice. What is required, as Part VI will argue, is deliberate, coordinated, elder-conscious reform across multiple legal domains simultaneously.
Section V: Comparative analysis, lessons from the United Kingdom, Australia, and the United States
The gaps identified in Section IV are not inevitable features of a modern legal system confronting a novel problem. Three comparable common law jurisdictions, the United Kingdom, Australia, and the United States, have each developed legal and regulatory responses to digital fraud and elder financial exploitation that demonstrate, with concrete statutory detail, what deliberate reform looks like. Canada’s failure to act is not a function of the problem being intractable. It is a function of political will.
A. The United Kingdom: Mandatory Reimbursement and Platform Accountability
The United Kingdom’s response to digital fraud is the most instructive for Canada because it addresses the banking gap, the most legally significant structural failure identified in this paper, directly and through binding law.
In October 2024, the UK’s Payment Systems Regulator (PSR) brought into force a mandatory reimbursement regime for authorized push payment (APP) fraud, the category of scam in which a victim is manipulated into instructing their bank to transfer funds to a fraudster.90 Under the regime, all payment service providers participating in the Faster Payments Scheme are required to reimburse customers who fall victim to APP scams, with the cost shared equally between the sending and receiving payment providers.91 The maximum reimbursement is 85,000 pounds per claim, a figure calibrated to cover the vast majority of individual fraud losses while remaining commercially manageable for smaller institutions.92
The design of the regime is as important as its existence. The burden of proving that a consumer acted with gross negligence, the only basis on which reimbursement can be refused, falls on the sending payment service provider, and the PSR has clarified that gross negligence requires a “significant degree of carelessness”, a standard set deliberately higher than the common law negligence threshold.93 Critically, the gross negligence exception does not apply to vulnerable consumers, meaning that seniors and others identified as vulnerable are entitled to mandatory reimbursement regardless of any finding that they may have acted carelessly.94 This provision is a direct legislative acknowledgment of what the neuroscientific literature makes clear: that cognitive vulnerability is not the same as contributory negligence, and that a legal system which treats them as equivalent will systematically fail its most vulnerable members.
The incentive structure the regime creates is also transformative. By requiring banks to reimburse fraud victims, the UK has made fraud prevention a financial priority for the institutions best positioned to prevent it. The PSR set out steps that payment service providers can take to mitigate APP scam risks, including setting appropriate transaction limits, improving know-your-customer controls, strengthening transaction monitoring systems, and stopping or freezing payments considered suspicious.95 These are not suggestions; they are the practical steps institutions must take to avoid bearing the cost of reimbursement.
The Online Safety Act 2023 complements the reimbursement regime by imposing obligations on large technology platforms to prevent fraudulent content on their services, and making them subject to substantial fines if they fail to do so.96 The combined effect is a multi-layered approach: banks bear financial responsibility for transactions, platforms bear responsibility for the fraudulent content that initiates those transactions, and the victim, particularly if vulnerable, is protected at both ends of the fraud lifecycle.
Canada has neither element. Banks bear no reimbursement obligation, platforms bear no content-moderation obligation in relation to fraud, and the victim, however vulnerable, has no statutory right to recovery against the institutions that processed or enabled the loss.
B. Australia: Economy-Wide Mandatory Obligations and Sector-Specific Codes
Australia enacted the Scams Prevention Framework Act 2025 on 13 February 2025, making it the most current and most ambitious piece of scam prevention legislation anywhere in the common law world.97 Described by the Australian Competition and Consumer Commission as “world-first legislation,” the Framework creates enforceable obligations for businesses in key sectors where scammers operate, with the explicit goal of making Australia one of the toughest places in the world for scammers to target.98
Rather than addressing fraud through isolated amendments to criminal or consumer protection law, Australia has created a principles-based, economy-wide regulatory framework applicable initially to banks, telecommunications providers, and digital platform services. The Framework is explicitly designed to address the “piecemeal and inconsistent” nature of existing scam protections, an observation that applies with equal force to Canada’s current approach.99
Regulated entities must comply with six overarching principles: prevent, detect, report, disrupt, and respond.100 Sector-specific codes, developed through mandatory consultation with industry and consumer groups, will establish the detailed operational standards for each principle within each sector.
Examples of what sector codes may include are illustrative: banks must implement technology to give customers greater confidence that they are paying whom they intended; digital platforms must verify that advertisers of financial products hold the required Australian Financial Services Licence; telecommunications providers must implement anti-scam filters to block SMS messages with known phishing links.101 Businesses that fail to meet their obligations under the Framework face fines of up to $50 million.102 A dedicated external dispute resolution body, the Australian Financial Complaints Authority, will handle consumer complaints arising under the Framework, providing a low-barrier redress mechanism that Canada entirely lacks.103
The Framework’s consumer-protective philosophy is also significant. Its explanatory documents state explicitly that “individuals have been bearing the brunt of the responsibility to combat scammers for far too long” and that it is time for the private sector to consistently step up its efforts.104 This reflects a normative judgment that the appropriate locus of fraud prevention responsibility lies with well-resourced institutions rather than individual victims, which Canadian law has never made. Canada continues to place the burden of fraud prevention primarily on seniors themselves, offering education campaigns and voluntary banking measures as the primary response to a billion-dollar crisis.
C. The United States: A Dedicated Federal Elder Justice Infrastructure
The United States presents a different model, less focused on financial institution liability than the UK and Australia, but further advanced in creating a dedicated federal institutional architecture for elder justice that Canada has no equivalent of.
The foundation is the Elder Justice Act, enacted as part of the Affordable Care Act in 2010, which defines elder financial exploitation as “the fraudulent or otherwise illegal, unauthorized, or improper act or process of an individual, including a caregiver or fiduciary, that uses the resources of an elder for monetary or personal benefit, profit, or gain”.105 This definition, operationalized through a legislative age threshold of sixty years, creates the legal foundation for a comprehensive suite of obligations, programs, and enforcement mechanisms that flow specifically from the status of being an elder victim.
The Department of Justice’s Elder Justice Initiative (EJI) coordinates federal elder fraud enforcement across all relevant agencies, and is statutorily required to publish annual reports to Congress, designate elder justice coordinators in every federal judicial district, and develop best practices for elder abuse prevention.106 The scale of enforcement activity that this infrastructure enables is striking: from July 2023 to June 2024 alone, the Department pursued over 300 enforcement actions against more than 700 defendants charged with stealing nearly $700 million from approximately 225,000 victims, and provided services and assistance to over 230,000 older victims while returning over $31 million to them.107 The most recent annual report covers over 280 additional enforcement actions targeting offenders who attempted to steal more than $2 billion from over one million older Americans.108
The Consumer Financial Protection Bureau (CFPB) operates a dedicated Office for Older Americans, providing financial institutions with supervisory guidance specific to elder financial exploitation.109 The Financial Crimes Enforcement Network (FinCEN) issues elder financial exploitation trend analyses and guidance to financial institutions on suspicious activity reporting in the elder context.110 The result is an ecosystem in which multiple federal agencies, coordinated through a statutory framework, approach elder financial fraud as a distinct and serious federal priority, with dedicated budgets, specialized prosecutors, and mandatory reporting requirements.
Canada has no equivalent of any of these elements. The CAFC is a valuable resource, but it operates primarily as an intelligence-gathering and public education body, not a prosecution or victim services infrastructure. The RCMP’s National Cybercrime Coordination Centre investigates cybercrime generally, without a specific elder mandate. No federal agency publishes annual reports to Parliament on elder fraud enforcement. No dedicated elder justice coordinator exists in any federal judicial district. The contrast with the United States is not merely one of scale; it is one of institutional commitment.
D. What Canada Can Learn: Three Transferable Principles
Three transferable principles emerge from the comparative analysis, each directly applicable to the Canadian context.
The first is the institutional responsibility principle: the UK and Australia have each legislated that financial institutions, not individual fraud victims, bear primary responsibility for preventing and compensating fraud losses. This principle is both normatively correct and practically effective: institutions have the resources, the data, and the technological capacity to detect fraud patterns that individual seniors cannot. Placing liability on institutions creates incentives for prevention that no public education campaign can replicate.
The second is the definitional foundation principle: the United States has demonstrated that meaningful elder-specific legal protection requires, at a minimum, a statutory definition of who qualifies as an elder and what constitutes financial exploitation. Without that definitional foundation, elder-specific obligations cannot be constructed, elder-specific enforcement programs cannot be targeted, and elder-specific data cannot be collected or reported. Canada’s definitional vacuum is not merely an academic gap; it is a structural obstacle to reform.
The third is the whole-of-economy coherence principle: Australia’s Framework illustrates the inadequacy of addressing scam fraud through isolated sector-specific measures. Because digital elder fraud operates across the intersection of banking, telecommunications, and digital platforms simultaneously, meaningful protection requires obligations that span all three sectors under a coordinated regulatory architecture. Amending the Criminal Code alone, or imposing obligations on banks alone, will not be sufficient; scammers will simply exploit the unregulated sectors that remain.
These three principles form the analytical foundation for the reforms proposed in Part VI.
Section VI: Recommendations for reform
The analysis in the preceding sections establishes two propositions: that Canada’s existing legal framework fails older adults at every stage of the digital fraud lifecycle, and that comparable jurisdictions have demonstrated workable legislative solutions to each of the structural gaps identified. What remains is to translate those findings into concrete proposals for Canadian law. This section advances five reform proposals, each grounded in the constitutional framework of Canadian federalism, calibrated to the specific gaps diagnosed in Section IV, and informed by the comparative models examined in Section V.
The proposals are presented in order of urgency, beginning with the reform that would have the most immediate protective effect for the most people.
A. Amend the Bank Act to Create a Mandatory Elder Fraud Protection Obligation
The single most consequential reform available to Parliament is the creation of a statutory duty, enforceable through the existing FCAC consumer protection regime, requiring federally regulated financial institutions to implement elder fraud detection and intervention protocols for transactions that fit the established profile of elder-directed digital fraud.
The constitutional foundation for this reform is unambiguous. Banking in Canada falls under federal jurisdiction, with Parliament holding legislative authority over “Banking, Incorporation of Banks, and the Issue of Paper Money” under section 91(15) of the Constitution Act, 1867.111 The Bank Act already governs consumer protection obligations for all federally regulated financial institutions, and Parliament amended the Financial Consumer Protection Framework within that Act as recently as 2022, demonstrating both the constitutional authority and institutional capacity to impose new consumer protection requirements on banks.112 The FCAC already holds the power to impose penalties of up to $10 million per violation and to direct banks to take actions to comply with their legal obligations.113 The enforcement infrastructure exists. What is missing is the substantive obligation.
The proposed amendment to the Bank Act would require federally regulated financial institutions to: first, implement real-time transaction monitoring systems capable of flagging transactions matching the documented profile of elder-directed digital fraud, including large cash withdrawals by customers aged sixty or older, wire transfers to first-time international recipients initiated following urgent caller contact, and cryptocurrency purchases by customers without prior digital asset history; second, upon flagging such a transaction, implement a mandatory pause of up to seventy-two hours to allow the institution to verify the nature of the transaction with the customer and, where appropriate, a trusted contact person previously designated by the customer; and third, in cases where the institution executes a transaction it had reasonable grounds to believe constituted elder fraud, bear presumptive civil liability to the customer for losses resulting from that transaction, with the burden of demonstrating gross negligence falling on the institution, not the victim.
This proposal draws directly on the UK’s APP fraud reimbursement regime, with two important modifications calibrated to the Canadian context. First, the seventy-two-hour pause mechanism goes beyond the UK model’s purely retrospective reimbursement approach, incorporating a prospective fraud-prevention element that is particularly appropriate for elder fraud, given the irreversibility of many losses. Second, the liability framework places the burden of disproving negligence on the institution, reversing the current position, established in McDonald v Toronto-Dominion Bank, in which victims bear the burden of establishing bank liability in the absence of any statutory duty.114
The objection that imposing mandatory pause protocols will inconvenience legitimate banking customers is answered by two considerations. First, the protocols are triggered by a combination of factors, including customer age, transaction type, urgency markers, and transaction history, that can be calibrated to minimize false positives while capturing the vast majority of elder fraud transactions. Second, the inconvenience of a seventy-two-hour verification delay is trivially small compared to the devastation of an irreversible fraud loss. A legal system that prioritizes transactional convenience over the financial security of its most vulnerable citizens has fundamentally misordered its values.
B. Enact a Federal Elder Digital Fraud Act Establishing a Statutory Definition and a Dedicated Institutional Response
The definitional gap identified in Section IV cannot be closed through amendments to existing statutes alone. What Canada requires is a standalone federal statute, an Elder Digital Fraud Act, that accomplishes four things simultaneously: defines the legal category of elder digital fraud; establishes an age-based threshold for elder status; creates a dedicated institutional mandate within an existing federal agency; and imposes mandatory annual reporting to Parliament on the state of elder digital fraud in Canada.
The definition proposed for “elder digital fraud” is: any fraudulent or deceptive act or scheme, conducted wholly or partially through digital or electronic means, that targets a person aged sixty or older with the intent to obtain money, property, or personal information from that person. The age threshold of sixty, drawn from the Elder Justice Act framework in the United States, reflects both the research literature on fraud vulnerability, which consistently identifies this threshold as the point of significantly elevated risk, and the existing CAFC data collection methodology, which uses sixty as the baseline for “senior” categorization.115 The use of a fixed age threshold, rather than the amorphous “vulnerability” language currently found in section 380.1(1)(c.1) of the Criminal Code, creates the definitional foundation for specific obligations, specific enforcement mandates, and specific data collection that general vulnerability language cannot provide.
The institutional mandate proposed for the Act would vest primary responsibility for elder digital fraud enforcement coordination in the CAFC, the body that already collects the most comprehensive national data on fraud, and require it to: publish annual statistical reports to Parliament specifically addressing elder digital fraud, disaggregated by fraud type, geography, and victim characteristics; operate a dedicated elder fraud hotline modelled on the US National Elder Fraud Hotline, staffed by personnel trained in both fraud response and elder communication; and coordinate with provincial Adult Protection Services programs to develop joint investigation and victim referral protocols. The annual reporting requirement is not a bureaucratic formality; it is a mechanism for institutional accountability, creating a public record against which the adequacy of the government’s response can be measured year by year.
C. Amend the Criminal Code to Create a Specific Elder Digital Fraud Aggravating Factor and Minimum Sentencing Guidance
The current sentencing framework for elder fraud, discussed in Section III, is inadequate in two respects: its aggravating factor provisions are too general to direct courts toward consistent outcomes, and its application to digital fraud networks produces sentences, as the Rud case illustrates, that bear no rational relationship to the scale and sophistication of the underlying criminal enterprise.
This paper proposes two targeted amendments to the Criminal Code. The first would add a new specific aggravating factor to section 380.1, requiring courts sentencing for fraud offences to treat as an aggravating circumstance the fact that the offence was committed through digital or electronic means against a victim aged sixty or older, or against a victim whose vulnerability was known to or ought to have been known to the offender. This provision is more targeted than the existing section 380.1(1)(c.1), which requires only a general consideration of personal circumstances, including age. By naming digital means and elder victimhood as specific co-occurring factors, the combination that defines the crisis this paper addresses, the amendment signals Parliament’s specific concern and provides courts with clearer guidance on how that concern should be weighted.
The second amendment would add section 380.1(1.2), requiring courts, when sentencing for a fraud offence committed through digital means against a victim aged sixty or older, to specifically address in their reasons the impact of the offence on the victim’s capacity for financial independence and recovery. This provision, modelled loosely on the victim impact statement requirements in section 722 of the Criminal Code, does not mandate a specific sentence; it mandates judicial attentiveness to the dimension of elder fraud that is most legally distinctive and most inadequately addressed in current sentencing reasons: the irreversibility of loss for a victim with no meaningful opportunity to rebuild.116 The Rud sentencing, which permitted the convicted fraudster to attend the gym while Francine Jarry’s $4,200 remained unrecovered, might look different if the sentencing judge had been required to address, on the record, the impact of the fraud on Jarry’s financial independence and her capacity to recover her losses.
D. Amend CASL and Introduce AI-Specific Criminal Liability for Fraudulent Synthetic Media
The AI gap identified in Section IV requires two parallel responses: strengthening the existing regulatory framework to address AI-generated fraud communications, and creating specific criminal liability for the fraudulent use of voice-cloning and deepfake technology against elder victims.
The CASL amendment proposed here would extend the Act’s prohibition on commercial electronic messages sent without consent to explicitly include AI-generated communications, voice calls, video messages, and text communications that purport to originate from a person or institution with whom the recipient has a relationship, when those communications are designed to induce the recipient to transfer money or disclose personal information. The current CASL framework captures spam email but is silent on AI-generated voice calls and deepfake video communications that are the primary vectors of modern elder fraud.117 This extension would not require a new statute; the existing CASL architecture, enforcement agencies, and penalty provisions are adequate, but would require targeted definitional amendments to the Act’s definition of “commercial electronic message” and “electronic address.”
The Criminal Code amendment proposed here would add a new section 380.2, creating the offence of fraudulent synthetic media, defined as the creation, distribution, or use of AI-generated audio, visual, or audiovisual content that falsely represents a real person, with intent to defraud another person of money, property, or personal information. The maximum penalty would be ten years’ imprisonment, consistent with the existing penalty for identity fraud under section 403. Where the victim is a person aged sixty or older, the offence would carry a mandatory minimum of one year’s imprisonment on indictment. Canada has no specific deepfake law as of 2025,118 the enactment of this provision would make Canada among the first jurisdictions globally to criminalize AI-generated fraud specifically and with elder-protective intent, placing it ahead of most comparable legal systems on this dimension.
E. Establish a National Vulnerable Consumer Digital Fraud Coordination Framework
The final reform proposed in this paper is the most structurally ambitious and the most directly drawn from the Australian model. Canada should enact legislation, ideally as part of the Elder Digital Fraud Act proposed in Recommendation B, establishing a National Vulnerable Consumer Digital Fraud Coordination Framework (NVCDFF) that imposes mandatory anti-fraud obligations across the banking, telecommunications, and digital platform sectors, coordinated through existing federal regulatory bodies.
The NVCDFF would operate through a principles-based architecture drawn directly from Australia’s Scams Prevention Framework Act 2025: regulated entities in designated sectors would be required to prevent, detect, disrupt, report, and respond to elder digital fraud affecting their customers or users. The Australian model’s explicit recognition that existing scam protections are “piecemeal and inconsistent” mirrors precisely the structural diagnosis of Canadian law advanced in this paper.119 Sector-specific codes, developed through mandatory consultation with industry, consumer groups, and elder advocacy organizations, would establish detailed operational standards. Regulated entities that fail to meet their obligations would face civil penalties enforced through the FCAC for the banking sector, the CRTC for telecommunications, and the Competition Bureau for digital platforms.
Critically, the NVCDFF would include a standalone consumer redress mechanism, a dedicated elder digital fraud dispute resolution body, potentially administered through the existing Ombudsman for Banking Services and Investments (OBSI), which was designated as Canada’s single banking external complaints body in 2024.120 This body would provide a low-barrier, accessible pathway for senior fraud victims to seek compensation from regulated entities that failed to meet their obligations, a pathway that currently does not exist and that the Francine Jarry story illustrates is desperately needed.
The NVCDFF proposal acknowledges that coordinated multi-sector regulation is constitutionally complex in Canada, given the division of powers between federal and provincial governments over consumer protection and telecommunications. However, the federal government’s exclusive jurisdiction over banking, its authority over telecommunications under section 92(10) of the Constitution Act, 1867, and its criminal law power under section 91(27) together provide a solid constitutional foundation for federal legislative action across all three sectors simultaneously. The CASL model, already a multi-sector, multi-agency regulatory framework enacted under federal authority, demonstrates that this kind of coordinated approach is constitutionally achievable and practically workable.
Section VII: Conclusion
This paper began with Francine Jarry, eighty-five years old, defrauded of $4,200 by a voice she believed was her granddaughter’s, and left without recourse by a legal system that convicted her fraudster and then permitted her to attend the gym. It ends in the same place, because the law has not moved.
Digital fraud targeting Canadian seniors is not a niche problem at the margins of elder law. It is a national crisis that consumed over $643 million in reported losses in 2024 alone, that affects a population whose losses are permanent and whose capacity to recover is structurally limited, and that operates through technological mechanisms Canadian law was not designed to address and has not been reformed to confront. The CAFC estimates that only five percent of fraud incidents are reported. The true scale of the crisis is unknown. What is known is that it is worse than the numbers suggest.
The central argument of this paper has been that Canada’s legal failure in this domain is not incidental but structural. The existing framework, a patchwork of general criminal provisions, provincial consumer protection statutes, anti-spam legislation, and voluntary banking measures, was constructed in a different technological era for a different fraud landscape. It treats elder digital fraud as a variant of ordinary fraud, rather than as a distinct harm with distinct victims, distinct perpetrators, and distinct institutional actors capable of prevention. It punishes fraud but does not prevent it. It acknowledges vulnerability but does not protect it. It creates restitution orders that cannot be enforced, aggravating factors that produce sentences measured in gym visits, and regulatory penalties that amount to a fraction of the losses they are meant to deter.
The comparative analysis in Section V establishes that this failure is not inevitable. The United Kingdom has created a mandatory reimbursement regime that makes banks financially responsible for elder fraud losses and gives vulnerable consumers a statutory right to compensation. Australia has enacted economy-wide, principles-based legislation that shifts the burden of scam prevention from individual victims to the institutions best positioned to act. The United States has built a dedicated federal elder justice infrastructure, with statutory definitions, institutional mandates, annual congressional reporting, and specialized prosecution capacity, that treats elder fraud as what it is: a distinct category of crime requiring a distinct legal response. Canada has done none of these things.
The five reforms proposed in Section VI, a mandatory bank obligation under the Bank Act, a federal Elder Digital Fraud Act, targeted Criminal Code amendments, AI-specific criminal liability, and a National Vulnerable Consumer Digital Fraud Coordination Framework, are not radical departures from Canadian legal tradition. They are applications of existing legislative tools, constitutional authorities, and regulatory architectures to a problem that those tools were never aimed at. Parliament already regulates banks. It already sets sentencing aggravating factors. It already operates multi-sector regulatory frameworks. It already criminalizes fraud. The question is not whether Parliament can do these things; it plainly can, but whether it will choose to before more Canadians lose everything they have spent a lifetime building.
Digital fraud does not wait for legal reform. The technology that enables it evolves in months; Canadian law evolves in decades. Every year that the Bank Act imposes no elder fraud obligations is a year in which billions of dollars flow from Canadian seniors to offshore criminal networks through institutions that had the data to see the fraud coming and the regulatory freedom to do nothing. Every year that Canada lacks a statutory definition of elder digital fraud is a year in which the law cannot build the targeted enforcement infrastructure the problem demands. Every year that AI-generated voice cloning remains unaddressed in the Criminal Code is a year in which Jill Finn in Regina hears her granddaughter’s voice, and it is not her granddaughter.
The law must catch up. It has the tools. What has been missing is the will to use them.