| A phishing scam impersonates a trusted person or organisation to trick someone into revealing information, approving a payment or giving access. It can arrive by email, text, phone or a message containing a QR code. A convincing message may contain no obvious mistakes, so protection against phishing scams has to combine staff awareness, verification rules and technical controls. |
Consider this example, because the phishing scams that take real money often look like it. An invoice arrives from a supplier your accounts clerk pays every month. The amount is plausible, the reference is right, the sender name is the person she has dealt with for two years, and the only thing that has changed is the bank account number. Nothing in it is misspelled. Nothing about it is odd.
It passed the filter, and it can pass a person who was trained to look for the things that used to give phishing scams away, because none of those things are there.
Phishing scams did not so much get more numerous as get harder to detect by eye. Many business defences are still built on the assumption that somebody will notice something, and that assumption is no longer safe to rely on by itself.
If that sounds like an operational nuisance, look at where it ends. The money can leave the same day, recovery depends on how quickly the bank is told and is never guaranteed, and the conversation you have afterwards is with your own clients.
What follows covers what these attacks look like now, what New Zealand businesses are reporting, the five controls that still hold when the message is convincing, and what a phishing protection service should include if you decide to buy one instead of assembling it. Staff awareness is part of the answer to phishing scams, and it is not the part to rely on alone.
Why Do Phishing Scams Get Past Trained Staff?
Because the tells staff were taught to spot were never features of the attack. They were symptoms of attackers writing phishing scams at volume in a second language, and that constraint has gone. A language model writes correctly, matches a house style, and personalises a message from a LinkedIn profile and a company website.
The result is the same lie with the seams taken out. Bad spelling, an unfamiliar address or an unusual request can still be warning signs, and they are still worth teaching. What has changed is that their absence no longer proves a message is genuine. Train staff to check the action being requested, to verify sensitive requests through a route they already trust, and to report uncertainty promptly, including when the message looks convincing.
One measurement here is usually quoted wrongly. In a 2024 study of 101 participants, fully AI-generated spear phishing achieved a 54 per cent click-through rate, and emails written by human experts scored exactly the same 54 per cent. A control group of ordinary phishing scored 12. That third number is the one people remember, and the only one of the three that ever gets quoted.
So in that experiment AI matched a skilled human rather than out-performing one, and it did so automatically. The significance is cost and scale rather than persuasion, because work that once needed a skilled person can now be produced cheaply. It is one study of 101 people measuring clicks rather than accounts actually compromised, so read it as a signal about the economics of phishing scams and not as a success rate against your business. The quality of attack once reserved for a handful of high-value targets is now affordable against everybody, including a firm of twenty people in Rangiora.
It also decides where your money should go. If the problem were simply a cleverer email, harder training would answer it. Because the problem is cost and scale, the answer to phishing scams has to be structural.
A control that depends only on a person feeling suspicious is a weak control on its own. It still helps, and it still catches phishing scams. It cannot be the only thing standing between a convincing message and a payment.
A second change sits underneath the first. Phishing scams used to be written once and sent to thousands, so one alert staff member could warn the whole company on the strength of an identical message. A message built for one recipient does less of that work. Reporting still matters, because it lets somebody check the account, remove the message from other mailboxes and warn people about the pattern even when the wording differs.
Attackers gather the material for phishing scams faster too. A staff list, a supplier name and a recent project are enough to build a phishing scam that reads like internal correspondence, and all three are public. These now arrive inside threads that already exist, where the history above the reply does the persuading.
Volume has not fallen to pay for the quality. The cost per attempt dropped, so the rational move was to send more of them and aim them better.
What Do Phishing Scams Look Like in New Zealand?
In New Zealand phishing scams commonly arrive as a redirected supplier invoice or as a director asking for an urgent payment. NCSC reporting shows the risk is live: in the first quarter of 2026, phishing and credential harvesting led the incident categories that did not require specialist technical support, with 437 reports. In the second quarter, scams and fraud became the largest category, followed by phishing and credential harvesting. These figures cover reports affecting individuals as well as organisations, rather than businesses alone.

The category count also understates the part phishing scams play, because a phishing scam is often the opening move in an incident counted as something else, and a ransomware case and a fraudulent payment case can begin with the same stolen login. The NCSC handled 1,129 incident reports between April and June 2026, of which 92 were triaged for specialist technical support because of their potential national significance rather than because they were the most severe.
New Zealand businesses attract a particular kind of attempt. Invoice redirection aimed at accounts staff, and impersonation of a director asking for an urgent transfer, are two patterns that come up repeatedly. Both work on procedure rather than technology. Neither requires the attacker to break anything, and a business with good systems and a loose payment process is still exposed.
Your industry matters less than you would think. Phishing scams aimed at a law firm and at a building company differ in the pretext, not the method. That is good news, because the defences are the same in both.
Being small is not protection. A shorter approval chain and a looser process make a business easier to work on once it is reached, and automation means an attacker no longer has to judge a target worth the effort first.
Read the national figures for what they are. Reporting to the NCSC is voluntary, so they describe reported activity rather than everything that happens, and they are evidence that phishing scams are a live risk rather than a measure of the odds facing your particular business.
What Are the Main Types of Phishing Scam?
Six kinds of phishing scams cover what a New Zealand business will see: bulk email phishing, spear phishing, business email compromise, whaling, smishing by text and vishing by phone. They differ less in method than in who they target and which channel they arrive on, which matters because your defences are organised by channel.
| Type | Who it targets | How it works |
|---|---|---|
| Bulk email phishing | Anyone, at volume | Cheap to send, so a low success rate still pays |
| Spear phishing | A named person, researched first | References real colleagues, projects and suppliers |
| Business email compromise | Finance and payroll staff | Impersonation or a real account, often with no link or attachment |
| Whaling | Directors and senior managers | Uses apparent authority to discourage questions about the request |
| Smishing | Anyone with a work mobile | Arrives by text, outside email filtering |
| Vishing | Reception, finance, helpdesk | A cloned or plausible voice, with no written record |
The channel that phishing scams arrive on matters. Email filtering does not see a text message and does not answer a phone, so smishing and vishing bypass it, though mobile, browser and account protections may still apply.
Business email compromise uses impersonation or access to a real account to manipulate a business transaction, and the message may carry no malicious link or attachment. That does not make it technically undetectable, because email and account security can pick up impersonation of a user, a domain or a familiar sender, along with unusual mailbox activity. What settles it is independent verification of any change to bank details. QR codes belong to the same family, since a code printed on a notice or pasted into a document can open a malicious destination on a managed or a personal device, so check what your mobile, browser and account protections cover there.
Somebody trained to be careful with email can answer the phone with far less suspicion. Attackers know which channels are best defended, and they send phishing scams down the others.
What Does a Phishing Scam Cost a Business?
One phishing scam that redirects an invoice can take a six-figure sum from a business in an afternoon, and the transfer is the smaller half of the bill. Nationally, the NCSC put reported direct losses at $2.7 million for the April to June quarter of 2026, roughly half the previous quarter. Those are totals across every reporter, so the spread matters far more than the average.
IBM’s 2026 Cost of a Data Breach report puts the global average cost of a breach at USD 4.99 million, and reports that one in four malicious breaches were AI-enabled, a 56 per cent increase on the year before. Neither figure measures New Zealand small business phishing losses, and the average is drawn from organisations far larger than most New Zealand businesses.
The costs that never appear in either number are the ones our clients say hurt most. A compromised mailbox gets used against your own customers, and explaining to them why they received a convincing request from your real address is harder than replacing the money. There is a regulatory tail too. Where there are reasonable grounds to believe a privacy breach has caused, or is likely to cause, serious harm, the Privacy Act 2020 requires you to notify the Privacy Commissioner and the people affected as soon as practicable, with exceptions applying to telling the people themselves. Not every phishing scam meets that test.
Then there is your own time, which nobody budgets. A single compromised mailbox takes days to work through properly, because somebody has to read what the attacker read and decide what it means for every client named in it. That somebody is usually the owner, because it is the one job that cannot be handed to a person who does not know the clients.
Insurance changes the arithmetic without removing it. Cover, the controls an insurer expects you to hold, the exclusions and the notification conditions all depend on the policy, so read yours and check what it requires before an incident rather than after.
What Stops Phishing Scams From Working?
Five controls do the work against phishing scams: phishing-resistant login, a verification rule for money, filtering that reads intent, restricted payment approval, and staff who report fast. They are not ranked, because which one matters most depends on the attack. Stronger authentication addresses account theft, while payment verification addresses a fraudulent instruction, including one sent from a supplier mailbox that has been compromised.

Take the login first, because it removes what most phishing scams are after. Passkeys resist fake-site login attacks because they work only with the legitimate service they were created for, and they cannot be handed over the way a password and a texted code can. They do not stop every form of session or token theft after sign-in, and they do not stop a fraudulent payment request at all, so keep devices secure and review the recovery and fallback sign-in methods as part of any rollout. Where passkeys are not available, use the strongest supported multi-factor authentication method. Prefer FIDO2 security keys or app-based prompts to codes sent by text, which can be read off a locked screen or intercepted.
The second control may need no additional software and it stops the expensive cases. Any change to bank account details, any unusual payment instruction and any change to a sensitive account gets verified by ringing a number you already held, never a number supplied in the message. Write that rule down and make it apply to everyone including senior staff. Invoice fraud works when the rule exists only informally and gets waived for whoever sounds senior and in a hurry.
Modern email security is the third, scoring intent and relationships instead of hunting for known-bad strings, which catches phishing scams carrying nothing a scanner would flag. It will not catch everything, and it does not need to, provided the other four controls are actually in place.
Fourth is who may approve the change at all. Requiring a second name is a policy decision rather than a purchase, and the second approver has to check the change independently, because two people trusting the same fraudulent email is not an independent check.
Fifth is the staff themselves, and the job has widened rather than narrowed. Recognition still matters, because an unusual request or an unfamiliar address is still worth questioning. Alongside it, teach people to check the action being asked for, to verify through a route they already trust, and to report quickly and without blame, so somebody can check the account and warn others. That is what security awareness training should be aiming at, and reporting rate is a better measure of it than how confident people say they feel.
None of these stops every phishing scam and none of them needs to. Each removes a class of attack, and what is left over is what staff awareness and fast reporting are for.
If you do one thing after reading this, write the payment verification rule down and tell the finance team it applies to senior staff as well. It may need no additional software, and it closes the phishing scams that empty the account.
What Should Phishing Protection Include for a NZ Business?
Protection against phishing scams has four components: email filtering, phishing-resistant authentication, simulation and training, and someone who responds when a credential is caught. Bought separately they are four products. Bought as a service they should arrive as one arrangement with one number to ring.
Ask a provider which accounts and devices are covered, whether the scope is email only or takes in other channels, what hours a person is available, what they are permitted to do without reaching you, and what falls outside the agreement. Ask what happens at two in the morning when a staff account starts sending mail it should not, and whether anybody is permitted to disable it before ringing you.
If you already have a provider, the same questions are reasonable to ask this month, and the answers belong in writing rather than in a conversation.
Pin down the scope as well. Ask whether the arrangement covers text-message and phone-based phishing scams or only email, because a brochure does not always say. Check what sits outside the monthly fee too, since investigation beyond a set number of hours and support with a Privacy Act notification are common exclusions and they surface at the worst possible moment.
Buying protection against phishing scams moves the work, not the obligation, so judge a service on how fast it gets you the facts you will need after a breach.
Exodesk can provide these as one managed arrangement, and what is included is set by the service you agree rather than assumed. Our cyber security team operates controls as well as advising on them, and we agree in writing which accounts and devices are covered, what hours a person is available, and what we may act on without ringing you first.
What Should You Do After a Suspected Phishing Attempt?
Stop interacting with the message and contact your IT or security team through a route you already trust, because the response to phishing scams starts with telling somebody. Tell them exactly what happened: whether you only opened it, followed a link, entered information, approved a sign-in prompt, opened a file or sent money. Keep the message for the investigation and avoid forwarding it around the business.
| What happened | Immediate action |
|---|---|
| Opened or clicked only | Report it and close the page. Do not enter information or approve any further prompts. A click alone does not establish that an account is compromised, and IT should assess the link, any downloads and the device activity. |
| Entered credentials or approved access | Contact IT urgently. The response may include blocking sign-in, resetting the exposed credentials, revoking sessions and removing unauthorised access. Use a device and a sign-in route you trust. |
| Ran a file or installed software | Disconnect the device from networks and contact IT from another device. Avoid further use, and do not delete material that may be needed for the investigation. |
| Sent money or disclosed banking details | Contact your bank immediately on a number you already held, alongside telling IT. Recovery is time-sensitive and cannot be guaranteed. |
Where an account or a device may have been compromised, administrators handle containment and investigation. That means checking authentication methods, application permissions, mail forwarding rules and activity across connected services, and preserving the available records while the incident is contained. Resetting a password and revoking active sessions both matter, because a password change on its own can leave an attacker signed in, but neither replaces the investigation and neither guarantees that every route back in has been removed.
Tell the rest of the business quickly and without blame, so other people recognise the same pattern. The person who reported it is the reason you know, and treating them as the problem guarantees the next one stays silent.
Assess the privacy position alongside containment rather than after it. Where there are reasonable grounds to believe a breach has caused, or is likely to cause, serious harm, the Privacy Commissioner and the people affected have to be notified as soon as practicable, subject to the exceptions that apply to notifying individuals. Decide in advance who makes that call, and keep the message and the sign-in logs, because an insurer or an investigator will ask for both.
Reporting phishing scams to the NCSC is voluntary and separate from that legal duty. Where money has moved, the call to the bank is the time-critical one and it goes alongside telling IT rather than after it.
Frequently Asked Questions
What is a phishing scam?
It is a message pretending to come from someone the recipient already deals with, sent to get a login, a payment or a way in. Email, text, phone and QR codes all carry them. Because the method is deception rather than a technical fault, filtering catches some and cannot catch all, which is why phishing scams need verification rules and staff awareness alongside the technology.
What are the most common phishing scams in New Zealand?
Invoice redirection and director impersonation come up repeatedly in New Zealand. Both arrive as ordinary email, ask for a payment or a change of bank details, and often carry no malware for a filter to find. Bulk email phishing works on volume, and text-message scams about parcels and tolls are common. NCSC reporting covers individuals as well as organisations, so it shows activity rather than which pattern costs businesses the most.
What happens if you open a phishing email but do not click anything?
Opening an email without following links, opening attachments or replying does not usually compromise a fully updated device. Report the message through your business process and avoid further interaction. If you clicked, entered information or opened a file, tell IT exactly what happened so they can assess the right response.
What is the difference between phishing and spear phishing?
Bulk phishing goes to as many people as possible and relies on volume, while spear phishing targets one named person and is researched first, so it cites real colleagues, suppliers and projects. Spear phishing converts more often in the studies that have measured it, and automation has made it cheap enough to use at scale.
What is smishing?
Smishing is a phishing scam delivered by text message, and it matters because your email filtering never sees it. Mobile, browser and account protections may still apply, so ask what covers that channel rather than assuming it is either protected or wide open.
What is business email compromise?
Business email compromise uses impersonation or access to a real mailbox to manipulate a business transaction, often with no malicious link or attachment. That does not make it undetectable, because email and account security can pick up impersonation of a user, a domain or a familiar sender, along with unusual mailbox activity. The control that settles it is procedural, which is verifying any change of bank details on a number you already held.
Can phishing scams get past multi-factor authentication?
Some can. Attacks that relay a login in real time capture the session rather than the password, which is why phishing-resistant methods matter. Passkeys and FIDO2 security keys resist that because they work only with the legitimate service they were created for. They do not stop every form of session or token theft after sign-in, and they do not stop a fraudulent payment request, so keep devices secure and review the fallback sign-in routes.
What should you do if someone clicks a phishing link?
Stop interacting with the message and tell IT or your security team through a route you already trust, saying exactly what happened. Where an account may be compromised, administrators should check authentication methods, application permissions, forwarding rules and activity across connected services. Resetting the password and revoking sessions both matter, because a password change alone can leave an attacker signed in, but neither replaces the investigation.
Do you have to report a phishing scam in New Zealand?
There are two separate things. Reporting to the NCSC is voluntary and feeds the national picture. Separately, where there are reasonable grounds to believe a privacy breach has caused, or is likely to cause, serious harm, the Privacy Act 2020 requires you to notify the Privacy Commissioner and the people affected as soon as practicable, with exceptions applying to notifying individuals. Not every phishing message meets that test.
How much do phishing scams cost New Zealand businesses?
There is no reliable average. The $2.7 million the NCSC reported for the April to June quarter of 2026 is a national total across all reported incident types and all reporters, not a phishing figure and not a per-business one. What a single incident costs depends on whether money moved, whether an account was compromised, and the time spent working out what was exposed.
What should you look for when buying phishing protection?
Which accounts and devices are covered, whether the scope is email only or takes in text and phone, what hours a person is available, who is permitted to disable a compromised account without reaching you first, and what falls outside the agreement. Get the answers in writing before the service starts rather than during an incident.
Can email filtering stop phishing scams on its own?
No. Filtering removes bulk volume and is worth having, and it can also flag impersonation and unusual activity. It will not settle a business email compromise on its own, and text messages and phone calls never pass through it, so pair it with verification rules for payments and a way for staff to report quickly.
NEXT STEP
Make payment checks and phishing protection work together
Talk to Exodesk about email security, staff training and stronger sign-ins for your business. We can discuss the controls you need, the work your team will retain, and the response arrangements to agree before an incident.
Start with an IT assessment.

