Connect with us

Technology

Due diligence increasingly critical for Canadian businesses reconfiguring supply chains amid U.S. tariffs

Published

on

Switching suppliers requires robust due diligence as fraud and cybersecurity risks are on the rise, KPMG forensic and cybersecurity specialists warn

TORONTO, March 6, 2025 /CNW/ – With the recent implementation of 25 per cent, across-the-board tariffs on Canadian goods, Canadian businesses that are considering or already making changes to their supply chain must remain extra vigilant for increased fraud and cybersecurity risks, KPMG in Canada specialists warn.

A recent KPMG in Canada survey of Canadian businesses found that in anticipation of tariffs, nearly half (44 per cent) of respondents said they are already reconfiguring their supply chains to divert U.S.-destined exports to these third-party countries, with another 44 per cent exploring that option.

Changing suppliers and reconfiguring supply chains can introduce numerous fraud risks, says Myriam Duguay, Partner and National Forensic Leader at KPMG in Canada.

“With U.S. tariffs now in place for Canadian exporters, many businesses might rush to switch suppliers, and in doing so, they might not do the rigorous due diligence that’s needed to reduce third party risks,” she says.

“Businesses must be vigilant about engaging new suppliers that make illegitimate or overstated claims about their capabilities,” she adds.

Hartaj Nijjar, KPMG in Canada’s National Cybersecurity Leader adds that engaging new suppliers increases an organization’s cybersecurity risks.

“If the new suppliers do not have robust cybersecurity measures in place, they could become a weak link in an organization’s supply chain, potentially leading to data breaches,” he says.

“Businesses should also be aware of fake suppliers that appear legitimate but are actually threat actors in disguise. This is becoming more prevalent now with the rise of AI-powered deepfakes,” he adds. 

KPMG’s forensic and cybersecurity specialists recommend Canadian organizations consider the following points when changing suppliers.

Supplier Due Diligence: When switching suppliers, conducting an integrity due diligence is the first and most critical step. This includes verifying the legitimacy and integrity of the new suppliers, checking their financial stability, and assessing their reputation. Skipping this critical step could lead to partnerships with potentially fraudulent entities that might engage in practices such as overcharging, delivering substandard goods, or even disappearing with prepayments.Contractual Risks: New contracts with suppliers can be a source of fraud if not carefully reviewed. There may be hidden clauses that could be exploited, or the supplier may misrepresent their capabilities or the quality of their products. Legal experts must review contracts to mitigate these risks.Payment Fraud: Changing suppliers often involves new payment processes. This can create opportunities for fraud, such as invoice fraud, where a fraudulent invoice is submitted for payment. According to Payments Canada, one in five Canadian businesses experienced some form of payment fraud in the past six months. Implementing strict controls and verification processes for invoices can help reduce this risk.Supply Chain Visibility: A reconfigured supply chain may lead to reduced visibility over the entire process. If there are multiple intermediaries involved, it can be challenging to track the flow of goods and payments, increasing the risk of fraud. Utilizing technology such as AI-powered digital twins or blockchain can enhance transparency and traceability in the supply chain.Internal Controls: Changes in suppliers and supply chain configurations may also affect internal controls. If these controls are not updated or reinforced, it can create vulnerabilities that fraudsters may exploit. Regular audits and assessments of internal controls are necessary to ensure they remain effective.Cybersecurity Risks: Engaging new suppliers could expose organizations to cybersecurity risks. If new suppliers do not have robust cybersecurity measures in place, they could expose an organization to a security breach. Before onboarding new suppliers, organizations should conduct rigorous risk assessments to evaluate their cybersecurity posture. Deepfake Risks: Deepfakes could be used to create false narratives about a supplier’s reliability or capabilities, which could lead to further risks and supply chain disruptions for organizations. Investing in advanced verification technologies and educating employees on how to identify deepfakes could help mitigate these risks. Employee Training: Employees in the supply chain and accounting departments should be trained to recognize potential fraud and cybersecurity risks associated with new suppliers. This includes understanding red flags and knowing the proper procedures for reporting suspicious activities.Regulatory Compliance: Depending on your industry, changing suppliers may also involve compliance with various regulations. Non-compliance can lead to legal issues, corruption and potential fraud if suppliers are not adhering to the necessary standards.

“While changing suppliers and reconfiguring supply chains can help businesses mitigate the added cost of tariffs, they need to be aware of the associated fraud and cybersecurity risks. Implementing robust due diligence, maintaining strong internal controls, and ensuring compliance with regulations can help mitigate these risks,” Ms. Duguay adds.

For more resources on fraud prevention, visit: Fraud prevention – KPMG Canada

Tune in to KPMG in Canada’s upcoming DX Coffee Chat, Outsmarting Fraud in a Digital World: Outsmarting fraud in a digital world Registration

For more resources on U.S. tariffs, visit: Navigating tariffs – KPMG Canada

About KPMG in Canada
KPMG LLP, a limited liability partnership, is a full-service Audit, Tax and Advisory firm owned and operated by Canadians. For over 150 years, our professionals have provided consulting, accounting, auditing, and tax services to Canadians, inspiring confidence, empowering change, and driving innovation. Guided by our core values of Integrity, Excellence, Courage, Together, For Better, KPMG employs more than 10,000 people in over 40 locations across Canada, serving private- and public-sector clients. KPMG is consistently ranked one of Canada’s top employers and one of the best places to work in the country. 

The firm is established under the laws of Ontario and is a member of KPMG’s global organization of independent member firms affiliated with KPMG International, a private English company limited by guarantee. Each KPMG firm is a legally distinct and separate entity and describes itself as such. For more information, see kpmg.com/ca 

For media inquiries:
Roula Meditskos
National Communications and Media Relations
KPMG in Canada
416-549-7982
rmeditskos@kpmg.ca

SOURCE KPMG LLP

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Florida Physician Specialists Data Breach: Edelson Lechtzin LLP Launches Investigation into Exposure of Personal Information

Published

on

By

National class action firm offering free case evaluations to individuals impacted by the Florida Physician Specialists cybersecurity incident

JACKSONVILLE, Fla., May 3, 2026 /PRNewswire/ — Edelson Lechtzin LLP, a national class action law firm, is investigating data privacy claims arising from the Florida Physician Specialists data breach. Florida Physician Specialists learned of the cybersecurity incident between November 27 and 29, 2025.

What Happened

Florida Physician Specialists discovered that its network was hacked between November 27 and 29, 2025. An investigation launched in late November 2025 confirmed that an unauthorized third party accessed its network. The review of the exposed data was completed on April 6, 2026.

Information Exposed

Affected personal data includes full names and one or more of the following: Social Security numbers, driver’s license numbers or state identification numbers, other government identification numbers, financial account information, credit or debit card information, medical information, and/or health insurance policy information.

Who May Be Impacted

Individuals who received a data breach notification from Florida Physician Specialists may face an increased risk of identity theft and fraud.

Your Legal Options

Edelson Lechtzin LLP is investigating a potential class action to pursue legal remedies on behalf of individuals whose sensitive personal data may have been compromised in the Florida Physician Specialists breach. The firm will evaluate your rights and potential claims at no cost.

Recommended Protective Steps

Review account statements and credit reports regularly and remain vigilant for suspicious activity. Confirm whether your information was involved in the Florida Physician Specialists incident and preserve any letters or emails you received about the breach. Consider placing fraud alerts and credit monitoring.

Contact Us for a Free Case Evaluation

Speak confidentially with a data privacy attorney today: Marc Edelson, Esq., Edelson Lechtzin LLP, 411 S. State Street, Suite N-300, Newtown, PA 18940; Phone: 844-696-7492 ext. 2; Email: medelson@edelson-law.com; Web: www.edelson-law.com. Or click HERE to request a free consultation.

About Florida Physician Specialists

Based in Jacksonville, Florida, Florida Physician Specialists is a multi-specialty private physician practice serving patients in Northeast Florida.

About Edelson Lechtzin LLP

Edelson Lechtzin LLP is a national class action law firm with offices in Pennsylvania and California. In addition to data breach litigation, the firm handles class and collective actions involving securities and investment fraud, federal antitrust violations, ERISA employee benefit plans, wage theft, and consumer fraud

Media and Partnership Inquiries: Use the contact information above to connect with our team regarding interviews, co-counsel opportunities, and referral partnerships.

Legal Notice: This press release may be considered Attorney Advertising in some jurisdictions.

View original content to download multimedia:https://www.prnewswire.com/news-releases/florida-physician-specialists-data-breach-edelson-lechtzin-llp-launches-investigation-into-exposure-of-personal-information-302760742.html

SOURCE Edelson Lechtzin LLP

Continue Reading

Technology

Sandhills Medical Foundation, Inc., d/b/a Sandhills Medical Data Breach: Edelson Lechtzin LLP Launches Investigation into Exposure of Personal Information

Published

on

By

National class action firm offering free case evaluations to individuals impacted by the Sandhills Medical cybersecurity incident

MCBEE, S.C., May 3, 2026 /PRNewswire/ — Edelson Lechtzin LLP, a national class action law firm, is investigating data privacy claims arising from the Sandhills Medical data breach. Sandhills Medical learned of the cybersecurity incident between November 27 and 29, 2025.

What Happened

On May 8, 2025, Sandhills Medical discovered it had been the victim of a ransomware attack. Sandhills Medical began an investigation with the help of cybersecurity experts and a forensic firm. That investigation determined an unauthorized third party accessed Sandhills Medical’s server directly and obtained personal information for select patients.

Information Exposed

Affected personal data includes names, personal health information, and birth dates. This data breach has affected an estimated 169,017 people.

Who May Be Impacted

Individuals who received a data breach notification from Sandhills Medical may face an increased risk of identity theft and fraud.

Your Legal Options

Edelson Lechtzin LLP is investigating a potential class action to pursue legal remedies on behalf of individuals whose sensitive personal data may have been compromised in the Sandhills Medical breach. The firm will evaluate your rights and potential claims at no cost.

Recommended Protective Steps

Review account statements and credit reports regularly and remain vigilant for suspicious activity. Confirm whether your information was involved in the Sandhills Medical incident and preserve any letters or emails you received about the breach. Consider placing fraud alerts and credit monitoring.

Contact Us for a Free Case Evaluation

Speak confidentially with a data privacy attorney today: Marc Edelson, Esq., Edelson Lechtzin LLP, 411 S. State Street, Suite N-300, Newtown, PA 18940; Phone: 844-696-7492 ext. 2; Email: medelson@edelson-law.com; Web: www.edelson-law.com. Or click HERE to request a free consultation.

About Sandhills Medical

Based in McBee, South Carolina, Sandhills Medical operates as a Federally Qualified Community Health Center (FQHC) that provides community-based primary health care services.

About Edelson Lechtzin LLP

Edelson Lechtzin LLP is a national class action law firm with offices in Pennsylvania and California. In addition to data breach litigation, the firm handles class and collective actions involving securities and investment fraud, federal antitrust violations, ERISA employee benefit plans, wage theft, and consumer fraud

Media and Partnership Inquiries: Use the contact information above to connect with our team regarding interviews, co-counsel opportunities, and referral partnerships.

Legal Notice: This press release may be considered Attorney Advertising in some jurisdictions.

View original content to download multimedia:https://www.prnewswire.com/news-releases/sandhills-medical-foundation-inc-dba-sandhills-medical-data-breach-edelson-lechtzin-llp-launches-investigation-into-exposure-of-personal-information-302760743.html

SOURCE Edelson Lechtzin LLP

Continue Reading

Technology

Danish Publisher Automates Digital Textbook Delivery with Integrated WooCommerce-Webdoxx Solution

Published

on

By

Danish educational publisher eliminates manual processing errors and delivers instant access to more than 20 digital learning products

LONDON, May 3, 2026 /PRNewswire-PRWeb/ — Forlaget 94, a Danish educational publisher serving commercial colleges and vocational schools since 1994, has transformed its digital textbook distribution by implementing a fully automated WooCommerce-Webdoxx solution.

“Using the Webdoxx-WooCommerce integration we have achieved full automation of order processing, fewer errors, and happier customers,” Tom Gertsen, IT Manager at Forlaget 94

Previously, Forlaget 94 relied on manual processes to distribute digital textbooks to customers. As demand for online educational materials grew, the publisher required a faster, more reliable way to manage orders, provision access, and reduce the risk of administrative errors.

Through its integration of WooCommerce with Webdoxx, Forlaget 94 now runs more than 20 educational products through a 100% automated workflow. The solution automatically processes customer orders and provides instant access to purchased digital textbooks, improving the experience for both customers and internal teams.

“The result is full automation of order processing, fewer errors, and happier customers,” said Tom Gertsen, IT Manager at Forlaget 94 and architect behind the WooCommerce-Webdoxx integration. The automated system has enabled Forlaget 94 to eliminate manual errors, accelerate customer processing, and increase customer satisfaction through immediate access provisioning. The implementation demonstrates how educational publishers can modernize digital content delivery while maintaining secure, managed access to learning materials.

Webdoxx, a service created and managed by Drumlin Security Ltd, provides online DRM and managed document delivery services for publishers, educational organizations, institutions, and commercial content providers.

About Forlaget 94

Forlaget 94 is a Danish educational publisher established in 1994, providing educational products for commercial colleges and vocational schools.

About Webdoxx

Webdoxx is an online DRM and managed document delivery service created and managed by Drumlin Security Ltd. The platform supports secure access to digital publications and documents across a range of sectors, including education, healthcare, government, finance, and publishing.

Media Contact

Mike de Smith, Drumlin Security Ltd, 44 7768404712, info@drumlinsecurity.com, https://www.drumlinsecurity.com/

View original content to download multimedia:https://www.prweb.com/releases/danish-publisher-automates-digital-textbook-delivery-with-integrated-woocommerce-webdoxx-solution-302759942.html

SOURCE Forlaget 94

Continue Reading

Trending