Attacks

How AI is used against your business

Not what AI vendors do with your data — that is the other set. This is how attackers use AI against you, and which of the checks you rely on it has already outrun.

These are kept separate from our vendor-practice patterns on purpose. Both are threat patterns and both matter, but they answer different questions. A reader who wants to know how money leaves the business will not find it among training defaults, and a reader asking whether their notetaker is a liability will not find that here.

The structure is the same, because it is the part that does the work: each generation names the control that stopped the previous one, and shows how it was defeated. If the check you rely on was designed against generation one and you are facing generation three, you are protected against a problem that no longer exists.

Why this reaches New Zealand firms specifically

New Zealand’s National Cyber Security Centre reported NZ$12.4 million in direct financial losses in the third quarter of 2025, up 118 per cent on the quarter before, and attributed much of it to business email compromise. It names the organisations being targeted: those that manage large financial transactions, like law firms and real estate agencies.

The NCSC also says only a small proportion of losses are ever reported to it. Every figure here is a floor, not a measure.

Each pattern below states whether a person has read its sources in full. Where it says they have not, treat it as a draft position: the facts are cited and dated, but somebody still has to sit down with the originals. We would rather publish that distinction than imply a level of checking that has not happened. When we get something wrong we correct it and say so — see Corrections.


The phishing email you could spot

Credential
Generation 1 · as at 2026-09-03

How this family has moved:

  1. Generation 1: The phishing email you could spot ← this one
  2. Generation 2: The message that reads like your colleague
  3. Generation 3: The second factor is handed over too

A message pretending to be your bank, your supplier or your IT provider asks you to log in, and the login page is the attacker's.

The control that made this survivable was a person noticing: the odd domain, the clumsy English, the logo slightly wrong, the greeting that no colleague would use.

It worked because writing convincingly in someone else's voice, at scale, was expensive. Most attempts were poor, and poor attempts are visible.

This is not a fringe risk in New Zealand. The NCSC recorded phishing and credential harvesting as the MOST COMMON incident type it received in the first quarter of 2026, with 437 incidents in three months.

What still works:

  • Never authenticate from a link in a message. Go to the service the way you normally reach it - a bookmark, the app, the address you already know.
  • Treat the request and the route as separate things: the message may be genuine and the link still not be.
  • Make it normal to check with the sender by a channel they did not choose, and normal to be wrong about it. A culture where people feel stupid for asking is a control that fails quietly.

Why the second one holds and the first did not. The control this generation defeated rested on a person noticing something. What still works rests on a fact you hold in advance, and holds only for as long as that fact stays true.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleMEDIUMhas A6; does not have A7
real estate, 1-10 peopleHIGHhas A6, A7
real estate, franchise or multi-officeHIGHhas A6, A7
retail or hospitality, 1-10 peopleMEDIUMhas A7; does not have A6

A6 Distributed staff who transact by video or phone. A7 High turnover, casual or contract staff.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • NZ National Cyber Security Centre, Quarter One Cyber Security Insights 2026 (1 January to 31 March 2026): 1,164 incidents responded to, of which 77 required specialist technical support. Phishing and credential harvesting was the most common incident type reported, with 437 incidents.
  • The same quarter recorded THREE incidents categorised as highly significant - the first of that category since 2021/22 - and NZ$5.6 million in direct financial loss, up 76 per cent on the NZ$3.2 million reported in Q4 2025, with NZ$5.2 million of it borne by individuals.
  • The NCSC states that basic measures including multi-factor authentication, managing who has full access to the network, and protecting network edges could have prevented these incidents. Generation three below is about what happened to the first of those.
  • NOT marked reviewed, 3 September 2026: these figures were read from the NCSC website rather than from the quarterly PDF itself. The Q2 2026 report is now the most recent and is summarised on the later generations of this pattern.

Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.

The message that reads like your colleague

Credential
Generation 2 · as at 2026-09-03

How this family has moved:

  1. Generation 1: The phishing email you could spot
  2. Generation 2: The message that reads like your colleague ← this one
  3. Generation 3: The second factor is handed over too

The tells are gone. The grammar is correct, the tone matches the sender, the subject line refers to a real project, and the timing fits your week.

Generative tools removed the cost that made generation one survivable. Writing fluently in another person's register, at volume, in any language, is no longer the expensive part of the attack - and the material to imitate someone is on their public profile and in the emails they have already sent.

Frequently the message is not an imitation at all. It comes from a colleague's genuinely compromised account, in a real thread, which is where this family joins the payment one.

What this defeats is not carelessness. It defeats CAREFUL READING, which is the control every awareness programme teaches.

What used to work and no longer does:

  • Look for bad spelling and grammar - the most widely taught anti-phishing advice in existence, and now close to useless.
  • It does not sound like them - it does, because their writing was the training material.
  • Check it refers to something real - it does; the attacker read the mailbox first.
  • Awareness training built around spotting a badly written email. Retire that lesson rather than repeat it, because a person who was taught to look for tells and finds none concludes the message is safe.

What still works:

  • Stop relying on identifying the message and start making the credential insufficient. Assume a convincing message will arrive and be believed, and design so that believing it is survivable.
  • Phishing-resistant authentication is the control that still holds - see generation three, which is about why ordinary multi-factor is no longer enough.
  • Separate authority from persuasion: no single message, however convincing, should be able to move money, change bank details or grant access on its own.
  • Teach people that a well-written, contextually perfect message is NOT evidence of anything, and that the only safe response to a request for credentials or payment is to verify on a channel the requester did not choose.

Why the second one holds and the first did not. The control this generation defeated rested on a person noticing something. What still works rests on how you are organised - decided before the moment rather than in it.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleMEDIUMhas A1, A6; does not have A7
real estate, 1-10 peopleHIGHhas A1, A6, A7
real estate, franchise or multi-officeHIGHhas A1, A6, A7
retail or hospitality, 1-10 peopleMEDIUMhas A1, A7; does not have A6

A1 Accepts payment instructions or bank-account changes by email. A6 Distributed staff who transact by video or phone. A7 High turnover, casual or contract staff.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • NZ National Cyber Security Centre, Quarter Two Cyber Security Insights 2026 (April to June 2026): 1,129 reports received, and NZ$2.7 million in direct financial loss - a 52 per cent decrease on the NZ$5.6 million of Q1 2026. Scams and fraud was the most frequently reported category, with phishing and credential harvesting next, and unauthorised access accounted for NZ$1.3 million of the direct loss.
  • CAUTION ON ONE FIGURE, stated rather than resolved: the Q2 summary gives a count of 348 in a way that does not make clear whether it belongs to scams and fraud or to phishing and credential harvesting. This page therefore cites NO incident count for Q2 and uses the unambiguous Q1 2026 figure of 437 on the previous generation instead. A number we cannot attribute is not a number we will publish.
  • NOT marked reviewed, 3 September 2026: read from the NCSC website rather than the quarterly PDF. No specific New Zealand incident of an AI-written phishing message is cited here, because we have not verified one; the generation rests on the capability being general and on the collapse of the writing-quality signal, not on a case we can name.

Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.

The second factor is handed over too

Credential
Generation 3 · as at 2026-09-03

How this family has moved:

  1. Generation 1: The phishing email you could spot
  2. Generation 2: The message that reads like your colleague
  3. Generation 3: The second factor is handed over too ← this one

The control that survived generation two was multi-factor authentication: even a perfect message could not get past a code the attacker did not have. That is no longer generally true.

A relay site sits between the user and the real service. The victim types the password and then the code into a page that passes both straight through, in real time. The code is valid, the login succeeds, and the attacker keeps the session.

Where codes are not used, approval fatigue does the same job. CISA describes push bombing plainly: threat actors bombard a user with push notifications until they press the Accept button, thereby granting the threat actor access.

Text-message codes carry two further failures that have nothing to do with the user: SS7 interception, and SIM swap - which CISA describes as convincing cellular carriers to transfer control of the user's phone number to a threat actor-controlled SIM card.

This is the generation most likely to catch a careful organisation, because it defeats the control they were told to buy and did buy.

What used to work and no longer does:

  • We have MFA - true, and not sufficient. CISA classes SMS and voice as vulnerable to phishing, SS7 and SIM swap, and app push without number matching as vulnerable to push bombing and user error.
  • The code proves the person is present - it proves someone entered a code somewhere, which a relay can arrange.
  • They would not approve a prompt they did not trigger - under enough prompts, at the wrong hour, people do. That is the attack, not a lapse.
  • Any control that treats possession of a transmitted code as proof of who is logging in.

What still works:

  • Move the accounts that matter to PHISHING-RESISTANT authentication - FIDO/WebAuthn security keys or passkeys. CISA states these are resistant to phishing and that push bombing, SS7 and SIM swap attacks are not applicable to them.
  • The reason it holds is worth understanding rather than taking on trust: the check is done BY THE DEVICE AGAINST THE SITE'S ORIGIN, cryptographically, not by a person deciding whether a page looks right. A relay site is a different origin, so the credential simply does not work there. It is the first control in this family that does not depend on somebody noticing anything.
  • If you cannot move everything, move the accounts that can move money or reset other accounts first - email, banking, the practice management system, and any administrator account.
  • Where ordinary MFA must remain, turn on number matching, and treat an unexpected prompt as a report-it event rather than a decline-it event, because a declined prompt tells you the password is already gone.

Why the second one holds and the first did not. The control this generation defeated rested on a fact checked once and then relied on. What still works rests on cross-referencing data rather than on judgement in the moment.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleHIGHhas A2, A5, A6
real estate, 1-10 peopleHIGHhas A2, A5, A6
real estate, franchise or multi-officeHIGHhas A2, A5, A6
retail or hospitality, 1-10 peopleLOWhas A5; does not have A2, A6

A2 Handles client or third-party funds - deposits, settlement, a trust account. A5 Payments authorisable verbally, or by one person acting alone. A6 Distributed staff who transact by video or phone.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • CISA, Implementing Phishing-Resistant MFA fact sheet, read 3 September 2026: SMS and voice described as vulnerable to phishing, SS7 and SIM swap; app-based push without number matching vulnerable to push bombing and user error; FIDO/WebAuthn described as resistant to phishing with push bombing, SS7 and SIM swap not applicable; PKI-based MFA such as PIV comparable but requiring highly mature identity management.
  • Push bombing and SIM swap descriptions are CISA's own wording, quoted above.
  • NZ National Cyber Security Centre, Quarter One Cyber Security Insights 2026, which states that basic measures including multi-factor authentication could have prevented the quarter's incidents. That remains true and is not in tension with this pattern: ordinary MFA still stops the bulk of opportunistic attacks. This generation is about what defeats it when someone is trying.
  • NOT marked reviewed, 3 September 2026: the CISA fact sheet was read at source. No New Zealand case of a relay-based MFA bypass is cited, because we have not verified one - the mechanism is documented by CISA, the local frequency is not something we can evidence, and we will not imply it.

Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.

The forged document somebody could spot

Identity
Generation 1 · as at 2026-09-03

This describes the position as it stands until 1 July 2027. From 1 July 2027 the NZ Identity Verification Code of Practice permits electronic delivery of certified copies, with enhanced assurance required only where there are reasonable grounds to suspect a copy is not genuine. We have dated it because that change is already scheduled, and nothing on any vendor’s website will move when it happens.

How this family has moved:

  1. Generation 1: The forged document somebody could spot ← this one
  2. Generation 2: The document is generated, not altered
  3. Generation 3: The certified copy arrives without anyone meeting anyone

A passport or licence is altered, or a copy is doctored, and the business accepts it as proof of who someone is.

The control that made this workable was a person looking: compare the photograph to the face in front of you, notice the wrong font, the edge of a pasted photo, the laminate that has been lifted.

It worked because forging a document well was expensive and slow, so most forgeries were poor, and poor forgeries are visible to a trained person.

What still works:

  • Verify against the SOURCE rather than against the artefact. The Identity Verification Code of Practice 2026 sets out electronic pathways for exactly this: an accredited Digital Identity Services Trust Framework service (1.2), or one of the other electronic methods at 1.3.4 - a verified RealMe identity, the DIA Confirmation Service, a reliable overseas government source, a validated e-passport microchip, or the NZTA Driver Check.
  • Know which of those stands alone. A VERIFIED REALME IDENTITY is treated as a single source giving both information and binding assurance, so it needs no separate linking mechanism. The others (1.3.4(b) to (e)) MUST be combined with a separate linking mechanism under 1.3.5 - facial recognition with a liveness test, a first payment from an account in the customer's own name, or a subsequent in-person visit.
  • Treat a document as a claim to be checked, not as evidence in itself.
  • Where you do inspect a document in person, clause 1.1.4 requires the photograph to be visually compared to the customer presenting it. Do that deliberately rather than as a formality - the Code notes this should be part of your procedures.

Why the second one holds and the first did not. The control this generation defeated rested on a person noticing something. What still works rests on cross-referencing data rather than on judgement in the moment.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleHIGHhas A3, A8
real estate, 1-10 peopleHIGHhas A3, A8
real estate, franchise or multi-officeHIGHhas A3, A8
retail or hospitality, 1-10 peopleLOWhas ; does not have A3, A8

A3 Large, infrequent, deadline-driven transactions. A8 Holds identity documents under AML or KYC obligations.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • Identity Verification Code of Practice 2026 (New Zealand), READ IN FULL 3 September 2026. Approved by Gazette notice 28 May 2026 under section 64 of the AML/CFT Act 2009; commenced 1 July 2026; replaces the 2013 code.
  • Electronic pathways: subpart 1.2 (DISTF) and 1.3.4 options (a) to (e). Single-source status of a verified RealMe identity: 1.3.4(a) with footnote 13. Requirement to add a separate linking mechanism to options (b) to (e): 1.3.5, with examples at 1.3.6.
  • Face-to-face binding assurance: 1.1.4. Accepted documents: 1.1.1.
  • CORRECTION, 3 September 2026: an earlier version of this page said the Code allows government sources including RealMe to be used "without corroborating evidence". That was too loose. What the Code does is treat a VERIFIED REALME IDENTITY as a single source for both information and binding assurance, while the other electronic options still require a separate linking mechanism; separately, the version history records that the requirement to verify a name from a second reliable and independent source has been removed WHERE THE DIA CONFIRMATION SERVICE IS USED. Those are two different things and the earlier wording blurred them.

Every source behind this pattern has been read in full.

The document is generated, not altered

Identity
Generation 2 · as at 2026-09-03

This describes the position as it stands until 1 July 2027. From 1 July 2027 the NZ Identity Verification Code of Practice permits electronic delivery of certified copies, with enhanced assurance required only where there are reasonable grounds to suspect a copy is not genuine. We have dated it because that change is already scheduled, and nothing on any vendor’s website will move when it happens.

How this family has moved:

  1. Generation 1: The forged document somebody could spot
  2. Generation 2: The document is generated, not altered ← this one
  3. Generation 3: The certified copy arrives without anyone meeting anyone

The document was never a real one that somebody tampered with. It was produced from nothing, to order, and it is internally consistent because it was rendered rather than edited.

This defeats the whole family of checks aimed at finding the JOIN - the pasted photograph, the mismatched font, the altered digit. There is no join, because nothing was altered.

It also defeats the economics that made generation one survivable. A good forgery used to be expensive and slow, which is why most were poor. Generation is neither.

What it does NOT defeat is a source. A generated document can look perfect and still correspond to no record.

What used to work and no longer does:

  • Look for signs of tampering - there are none, because nothing was tampered with.
  • Check the document looks internally consistent - it was rendered as a whole, so it does.
  • Trust a clear, high-quality scan more than a poor one - quality is now evidence of nothing.
  • Any check performed on the artefact rather than against the issuing source.

What still works:

  • Check the identity against the issuer or an accredited service, not against the document. This is the whole point of the electronic pathways in the 2026 Code.
  • Where a document is the only route available, treat a clean, plausible document as neutral evidence rather than as reassurance.
  • Ask what would have to be true for this document to be real, and check ONE of those things independently.

Why the second one holds and the first did not. The control this generation defeated rested on a person noticing something. What still works rests on cross-referencing data rather than on judgement in the moment.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleHIGHhas A3, A6, A8
real estate, 1-10 peopleHIGHhas A3, A6, A8
real estate, franchise or multi-officeHIGHhas A3, A6, A8
retail or hospitality, 1-10 peopleLOWhas ; does not have A3, A6, A8

A3 Large, infrequent, deadline-driven transactions. A6 Distributed staff who transact by video or phone. A8 Holds identity documents under AML or KYC obligations.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • Identity Verification Code of Practice 2026 (New Zealand), READ IN FULL 3 September 2026, for the electronic verification pathways at subpart 1.2 and 1.3 and for the certified-copy requirements at 1.4.
  • The Code is a SAFE HARBOUR rather than a mandate (section V): compliance is not compulsory, but a reporting entity that opts out must satisfy the obligation by some other equally effective means AND give written notification to its AML/CFT supervisor. Reporting entities remain free to do MORE than the Code requires, which is the relevant point for this generation.
  • Clause 3.1 requires a process to check that no other person has presented the same identity information - one of the few checks a perfect forgery does not defeat, because it tests the claim against your own records rather than against the document.
  • NO SPECIFIC INCIDENT of a generated identity document is cited here, because we have not verified one. This generation rests on the capability being general and on the Code's own move toward source-based verification, not on a case we can name. Said plainly rather than implied.

Every source behind this pattern has been read in full.

The certified copy arrives without anyone meeting anyone

Identity
Generation 3 · first observed 2027-07-01 · as at 2026-09-03

This describes the position as it stands until 1 July 2027. From 1 July 2027 the NZ Identity Verification Code of Practice permits certified copies to be delivered electronically, and requires enhanced assurance only where a copy is already suspected. That is the control this pattern turns on. We have dated it because that change is already scheduled, and nothing on any vendor’s website will move when it happens.

How this family has moved:

  1. Generation 1: The forged document somebody could spot
  2. Generation 2: The document is generated, not altered
  3. Generation 3: The certified copy arrives without anyone meeting anyone ← this one

READ THE DATES CAREFULLY, because they are the whole point of this one. The Identity Verification Code of Practice 2026 commenced on 1 JULY 2026 and applies now. The provision described here is NOT yet in effect: paragraphs 1.4.3, 1.4.4 and 1.4.5 commence on 1 JULY 2027.

From that date, clause 1.4.3 reads: "A reporting entity may receive a certified copy in person, by post or other means of delivery, including electronically."

Set that beside generation two. A document that can be generated to order, delivered down a channel where nobody meets anybody, certified by a person the receiver also never meets. Each is manageable alone. Arriving together is what makes this a generation rather than an inconvenience.

THE CONTROL THE CODE ATTACHES IS CONDITIONAL, AND THAT IS THE FINDING. Clause 1.4.4 requires enhanced-assurance procedures only "where there are reasonable grounds for a concern that a copy may not be genuine", and 1.4.5 says such grounds "will likely arise in situations where a customer also presents as a high money laundering or terrorism financing risk".

So the safeguard triggers on SUSPICION. A well-made synthetic document is precisely one that does not create suspicion, and a patient attacker does not present as high risk. The control is available exactly where it is least needed and silent where a generated document is most likely to pass. That is not a drafting error - it is a risk-based design, and it is why the procedures have to be built before July 2027 rather than after.

The same subpart also allows a certification up to TWELVE MONTHS old at presentation (1.4.6(c)), so a copy may be a year stale when relied on.

One control does run the other way and is easy to miss: clause 1.4.7(b)(ii) requires that a certified copy provided by means other than face-to-face carry "a statement from the trusted referee to the effect that the document provided represents the identity of the named individual". The referee, not the channel, is doing the binding.

What used to work and no longer does:

  • Somebody physically handed it over, or it came through the post - from 1 July 2027 it may arrive by any means of delivery, including electronically.
  • A certifier saw the original - true, but you do not meet the certifier either, and you assess that claim through the same channel that carried the document.
  • We would notice something odd about a walk-in - there is no walk-in.
  • The Code will make us check - only where there are already reasonable grounds for concern. Absent suspicion, 1.4.4 does not bite.
  • Any control that depended on some part of this transaction happening in physical space.

What still works:

  • Design your enhanced-assurance procedures BEFORE July 2027, and do not scope them only to customers you already suspect. The Code sets a floor tied to reasonable grounds for concern; nothing stops you applying the check more widely, and the cases you should worry about are the ones that raise no concern.
  • The Code itself names the checks, at footnote 18: confirm the referee is entitled to act by checking a register, contact the referee to confirm they certified it, or require original wet-ink copies. Contact the referee through details YOU look up, never details supplied with the document.
  • Prefer the electronic verification pathways over certified copies wherever the customer can use them. A verified RealMe identity is treated as a single source providing both information and binding assurance (1.3.4(a)), so it needs no separate linking mechanism - verifying against a source beats assessing a document.
  • Use clause 3.1 deliberately rather than as paperwork: "A reporting entity must have a process in place to check that no other person has presented the same identity information." Duplicate detection is one of the few controls a perfect forgery does not defeat, because it tests the claim against your own records rather than against the artefact.
  • Remember the Code is a SAFE HARBOUR, not a mandate. Section V lets a reporting entity opt out and satisfy the obligation "by some other equally effective means", but only with written notification to its supervisor. Doing less than the Code without notifying is not an option, and doing MORE is always open to you.
  • Treat the twelve-month certification window as a risk you have accepted, and shorten it yourself for high-value or deadline-driven transactions.

Why the second one holds and the first did not. The control this generation defeated rested on how things were arranged, and the arrangement stopped holding. What still works rests on how you are organised - decided before the moment rather than in it.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleMEDIUMhas A6, A8; does not have A9
real estate, 1-10 peopleMEDIUMhas A6, A8; does not have A9
real estate, franchise or multi-officeHIGHhas A6, A8, A9
retail or hospitality, 1-10 peopleLOWhas ; does not have A6, A8, A9

A6 Distributed staff who transact by video or phone. A8 Holds identity documents under AML or KYC obligations. A9 Layered authority, where staff have not met the people who authorise.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • Identity Verification Code of Practice 2026 (New Zealand), approved by notice in the New Zealand Gazette on 28 May 2026 by the Minister of Internal Affairs under section 64 of the AML/CFT Act 2009. READ IN FULL 3 September 2026. It replaces the Amended Identity Verification Code of Practice 2013.
  • Commencement, clause as written: "This code commences on 1 July 2026, excluding paragraphs 1.4.3 to 1.4.5 (inclusive) which commence on 1 July 2027." Restated at 1.4.1.
  • Delivery, 1.4.3: "A reporting entity may receive a certified copy in person, by post or other means of delivery, including electronically."
  • Conditional enhanced assurance, 1.4.4 and 1.4.5, quoted in full above.
  • Twelve-month certification window, 1.4.6(c). Referee statement for non-face-to-face copies, 1.4.7(b)(ii). Photograph clearly visible, 1.4.7(a). Duplicate-identity check, 3.1. Safe-harbour effect and opt-out, section V.
  • CORRECTION TO OUR OWN EARLIER VERSION, 3 September 2026: this page previously described the 2027 provision as subject to enhanced-assurance procedures without qualification. That overstated the safeguard. The requirement is CONDITIONAL on reasonable grounds for concern, and the qualification is the most important thing on this page. The earlier version was built from two law-firm summaries because the Code itself was unreachable to us; the Code has now been read and this page rests on it.

Every source behind this pattern has been read in full.

The obvious fake of your business

Impersonation
Generation 1 · as at 2026-09-03

How this family has moved:

  1. Generation 1: The obvious fake of your business ← this one
  2. Generation 2: The clone that is indistinguishable
  3. Generation 3: The impersonation that answers back

Somebody sets up an account, a page or an email that pretends to be your firm, and approaches your customers with it.

Note the direction, because it is what separates this family from the others. Elsewhere on this page someone impersonates a CLIENT to YOU. Here they impersonate YOU to your clients, and the person who loses money is not you - it is somebody who trusted you.

The control that made this survivable was that the fake was poor. Wrong logo, odd address, clumsy wording; your customers noticed, and often told you.

It worked because producing a convincing version of an entire business was slow. Netsafe records the impacts of impersonation scams as both reputational damage and financial loss - and the reputational half lands on you whether or not anyone was paid.

What still works:

  • Tell clients AT THE START how you will contact them and what you will never do, while they still trust the channel. A rule agreed at engagement is worth more than a warning sent during an incident, because during an incident they cannot tell which message is yours.
  • For anyone handling client money, the single most useful sentence is that your bank account details WILL NOT CHANGE, and that any message saying they have is fraudulent and should be verified by phone on the number in the signed agreement.
  • Give clients one number, held from the beginning, that is not on any email or website.

Why the second one holds and the first did not. The control this generation defeated rested on a person noticing something. What still works rests on a fact you hold in advance, and holds only for as long as that fact stays true.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleHIGHhas A3, A4
real estate, 1-10 peopleHIGHhas A3, A4
real estate, franchise or multi-officeHIGHhas A3, A4
retail or hospitality, 1-10 peopleLOWhas ; does not have A3, A4

A3 Large, infrequent, deadline-driven transactions. A4 Principals whose voice or likeness is publicly available in volume.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • Netsafe (New Zealand), Impersonation Scams, read 3 September 2026: impersonation is described as someone pretending to be a trusted organisation, business or individual to steal personal or financial information, with impacts including reputational damage and financial loss.
  • NOT marked reviewed, 3 September 2026: read as a web page. Netsafe publishes no figures on this page and none are claimed here.

Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.

The clone that is indistinguishable

Impersonation
Generation 2 · as at 2026-09-03

How this family has moved:

  1. Generation 1: The obvious fake of your business
  2. Generation 2: The clone that is indistinguishable ← this one
  3. Generation 3: The impersonation that answers back

The site is your site. The wording is your wording, because it was copied and rewritten fluently. The photographs are your staff, because they are on your website. The listing is real, because they took it from you.

Netsafe names this directly as branding impersonation: scammers misusing the branding of a legitimate business, creating convincing fake websites or emails, with a link that goes to a fake site requesting login and credit card details.

What generation two removes is the cost. Producing a whole convincing business - copy, images, tone, a plausible person to correspond with - used to be the expensive part, and expense is what kept generation one poor.

The control this defeats is your customer's judgement, which is the one control you cannot train, supervise or audit, because it is not yours.

What used to work and no longer does:

  • Our customers would spot a fake - not when the fake is a copy of the real thing.
  • Look for the padlock, check it looks professional - both now argue FOR the fake rather than against it.
  • We would hear about it quickly - you hear about it after somebody pays.
  • Anything that relies on a customer telling a good copy from an original by looking at it.

What still works:

  • Move the check off the artefact and onto something the client already holds: the number in the signed agreement, the account details confirmed at engagement, the person they have met.
  • Say plainly, in writing, at the start: we will never email you new bank account details. Then never do it, so the rule stays true and usable.
  • Monitor for impersonation rather than waiting to be told - search your own business name and your principals' names periodically, and register the obvious look-alike domains yourself if the cost is trivial next to a deposit.
  • Give staff a route to report a suspected clone that does not require them to be certain, and act on it the same day. The window that matters is short.

Why the second one holds and the first did not. The control this generation defeated rested on a person noticing something. What still works rests on a fact you hold in advance, and holds only for as long as that fact stays true.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleHIGHhas A2, A3, A4
real estate, 1-10 peopleHIGHhas A2, A3, A4
real estate, franchise or multi-officeHIGHhas A2, A3, A4
retail or hospitality, 1-10 peopleLOWhas ; does not have A2, A3, A4

A2 Handles client or third-party funds - deposits, settlement, a trust account. A3 Large, infrequent, deadline-driven transactions. A4 Principals whose voice or likeness is publicly available in volume.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • Netsafe (New Zealand), Impersonation Scams, read 3 September 2026, for branding impersonation and the fake-site-requesting-credentials mechanism, quoted above.
  • NOT marked reviewed, 3 September 2026: read as a web page. NO SPECIFIC New Zealand case of an AI-generated clone of a named business is cited here, because we have not verified one. This generation rests on the collapse of the production cost, not on an incident we can name, and says so rather than implying otherwise.

Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.

The impersonation that answers back

Impersonation
Generation 3 · first observed 2024-01-01 · as at 2026-09-03

How this family has moved:

  1. Generation 1: The obvious fake of your business
  2. Generation 2: The clone that is indistinguishable
  3. Generation 3: The impersonation that answers back ← this one

The control that survived generation two was to stop looking and start ASKING - ring the agent, email the firm, speak to a person. Generation three answers.

A cloned site can now be paired with something that holds a conversation in your firm's voice: a chat that replies instantly and correctly, an email thread that answers follow-up questions, a phone voice that sounds like the person whose name is on the listing.

The voice half is not speculative. In January 2024 an employee of the engineering firm Arup joined a video call on which the chief financial officer and several colleagues were all synthetic, and sent HK$200 million. That is the same capability pointed the other way: at Arup it impersonated colleagues to an employee; here it impersonates your firm to your client.

What this defeats is the last control your customer has. Every piece of advice given to consumers ends with "contact the company directly to check" - and generation three is a version of your company that is happy to be contacted.

What used to work and no longer does:

  • Contact the company to verify - if the contact route came from the fake, it reaches the fake.
  • Speak to a real person - a voice is no longer evidence that there is one.
  • They could not answer detailed questions about my file - they can, if they have read the thread they are impersonating.
  • Anything that treats responsiveness, fluency or plausibility as proof of identity.

What still works:

  • The verification route must be one the CLIENT ALREADY HELD, not one supplied during the interaction. A number from the signed engagement letter beats a number on a website, an email or a call, because the attacker did not choose it.
  • Agree the rule before there is anything to verify: at engagement, tell the client your bank details will never change and give them the one number to ring if anyone says otherwise. That is a structural control - it is decided in advance and does not depend on anyone judging anything in the moment.
  • Two people, one of whom did not receive the request, on any change to payment details or any unusual instruction. This survives every generation in this family because it does not ask anyone to detect a fake.
  • Tell staff plainly that a fluent, responsive, well-informed counterparty is not evidence of anything, and that they will never be criticised for slowing a transaction to check on a channel they chose themselves.

Why the second one holds and the first did not. The control this generation defeated rested on a person noticing something. What still works rests on how you are organised - decided before the moment rather than in it.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleHIGHhas A4, A5, A6
real estate, 1-10 peopleHIGHhas A4, A5, A6
real estate, franchise or multi-officeHIGHhas A4, A5, A6
retail or hospitality, 1-10 peopleLOWhas A5; does not have A4, A6

A4 Principals whose voice or likeness is publicly available in volume. A5 Payments authorisable verbally, or by one person acting alone. A6 Distributed staff who transact by video or phone.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • Arup deepfake video-conference fraud, Hong Kong, January 2024: HK$200 million (about US$25 million) transferred after a video call on which the CFO and other colleagues were AI-generated; Arup confirmed to the Financial Times that false voices and images were used. Cited here for the CAPABILITY, in the opposite direction to the payment-family pattern that cites it for the attack.
  • Netsafe (New Zealand), Impersonation Scams, read 3 September 2026, for branding impersonation of businesses.
  • NOT marked reviewed, 3 September 2026: the Arup account comes from contemporaneous reporting rather than any primary document, and Arup's confirmation was given to the Financial Times which we have not read in the original. MORE IMPORTANTLY: we cite NO verified case of an interactive AI impersonation of a New Zealand business to its own customers. The components are each documented - cloned sites by Netsafe, synthetic voice and video by Arup - and the combination is the claim. We say that plainly rather than implying an incident we cannot name.
  • CNN Business, 'British engineering giant Arup revealed as $25 million deepfake scam victim', by Kathleen Magramo, published 16 May 2024 and updated 17 May 2024. READ AT SOURCE 8 September 2026 in a browser, not via summary. Gives the figure as HK$200 million, about US$25.6 million, and records that a spokesperson for London-based Arup told CNN it notified Hong Kong police in January 2024. This corroborates both the amount and the January timing INDEPENDENTLY of the Financial Times account, which remains unread. Note one discrepancy recorded rather than smoothed: CNN's wording is 'Hong Kong employees' plural paying out, where this pattern says an employee. The singular is the widely reported account; we have not resolved which is right and have not changed the pattern on the strength of one phrase.

Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.

The invoice that is not from who it says

Payment
Generation 1 · as at 2026-09-03

How this family has moved:

  1. Generation 1: The invoice that is not from who it says ← this one
  2. Generation 2: The request really is from their account
  3. Generation 3: The voice on the call is theirs too

An invoice arrives that looks like a supplier you know, and the bank account on it is the attacker's. The email address is subtly wrong, or the display name is right and the address behind it is not.

The control that made this survivable was a person looking carefully: check the sender, notice the odd domain, notice that the account number changed.

It worked because the fake was imperfect and the imperfection was visible to someone paying attention.

What still works:

  • Check payment details against something you held BEFORE the request arrived - the signed engagement, the contract, the supplier record you already had.
  • Never take new bank details from the document that is asking to be paid. That is the one source an attacker controls completely.
  • Treat any change of bank account as an event that needs verifying, not as an administrative update.

Why the second one holds and the first did not. The control this generation defeated rested on a person noticing something. What still works rests on a fact you hold in advance, and holds only for as long as that fact stays true.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleHIGHhas A1, A3, A5
real estate, 1-10 peopleHIGHhas A1, A3, A5
real estate, franchise or multi-officeHIGHhas A1, A3, A5
retail or hospitality, 1-10 peopleMEDIUMhas A1, A5; does not have A3

A1 Accepts payment instructions or bank-account changes by email. A3 Large, infrequent, deadline-driven transactions. A5 Payments authorisable verbally, or by one person acting alone.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • NZ National Cyber Security Centre, Rise in financial losses reported to the NCSC, published 13 June 2025: NZ$7.8 million in direct financial losses reported for 1 January to 31 March 2025, up 14.7 per cent on the previous quarter, with more than half of reported losses affecting businesses.
  • The NCSC names the targets in terms that matter here: organisations that manage large financial transactions, like law firms and real estate agencies.
  • The NCSC also states that only a small proportion of losses are reported to it, so every figure on this page is a floor rather than a measure.
  • NOT marked reviewed, 3 September 2026: the NCSC page was read directly. Quarterly figures cited on later generations of this pattern come partly through a trade report of the NCSC release rather than the release itself.

Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.

The request really is from their account

Payment
Generation 2 · as at 2026-09-03

How this family has moved:

  1. Generation 1: The invoice that is not from who it says
  2. Generation 2: The request really is from their account ← this one
  3. Generation 3: The voice on the call is theirs too

The attacker is inside the mailbox. The email asking you to change the bank details genuinely comes from your supplier, your client, or your own finance lead - correct address, correct signature, often replying beneath a real conversation.

New Zealand's National Cyber Security Centre describes exactly this: a bad actor gains access to email accounts and then sends fake invoices or changes payment details to redirect payments to their bank account.

This defeats every control aimed at spotting a fake, because there is no longer anything fake to spot. The message is genuine. Only the instruction is not.

Reported direct financial losses in New Zealand rose to NZ$12.4 million in the third quarter of 2025, from NZ$5.7 million the quarter before - an increase of 118 per cent, which the NCSC attributed substantially to business email compromise.

What used to work and no longer does:

  • Check the sender address - it is correct, because the account is theirs.
  • Look for the tell-tale signs of a phishing email - there are none, because it is not a phishing email.
  • Confirm by replying to the thread - the reply goes to the attacker, who is reading the mailbox.
  • Anything that treats a genuine channel as evidence of a genuine instruction.

What still works:

  • Make a change of bank details a process rather than a message: requested in writing, verified on a channel the requester did not choose, and authorised by a second person.
  • Verify by a call YOU place to a number you already held. Not a number in the email, not a number given during the call, not a number on the new invoice.
  • Assume the mailbox may be read. Do not discuss the verification inside the thread you are verifying.
  • For firms holding client funds - law, conveyancing, real estate - treat an account change as the highest-risk transaction you handle, because the NCSC says that is who is being targeted.

Why the second one holds and the first did not. The control this generation defeated rested on a fact checked once and then relied on. What still works rests on how you are organised - decided before the moment rather than in it.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleHIGHhas A1, A2, A5, A6
real estate, 1-10 peopleHIGHhas A1, A2, A5, A6
real estate, franchise or multi-officeHIGHhas A1, A2, A5, A6
retail or hospitality, 1-10 peopleMEDIUMhas A1, A5; does not have A2, A6

A1 Accepts payment instructions or bank-account changes by email. A2 Handles client or third-party funds - deposits, settlement, a trust account. A5 Payments authorisable verbally, or by one person acting alone. A6 Distributed staff who transact by video or phone.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • NZ National Cyber Security Centre, Q3 2025 quarterly report covering 1 July to 30 September 2025: NZ$12.4 million in direct financial losses, up 118 per cent from NZ$5.7 million in Q2 2025.
  • Mike Jagusch, NCSC Chief Operating Officer, quoted on business email compromise: this is where a bad actor gains access to email accounts and then sends fake invoices or changes payment details to redirect payments to their bank account.
  • NZ NCSC, Rise in financial losses reported to the NCSC, 13 June 2025, for the targeting of law firms and real estate agencies and for the statement that only a small proportion of losses are reported.
  • NOT marked reviewed, 3 September 2026: the Q3 2025 figures and the Jagusch quotation were read through a trade report of the NCSC release, not the release itself. The June 2025 NCSC page was read directly. The quotation should be checked against the NCSC original before this pattern loses its draft label.

Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.

The voice on the call is theirs too

Payment
Generation 3 · first observed 2024-01-01 · as at 2026-09-03

How this family has moved:

  1. Generation 1: The invoice that is not from who it says
  2. Generation 2: The request really is from their account
  3. Generation 3: The voice on the call is theirs too ← this one

The control that survived generation two was to stop replying and pick up the phone. Generation three answers the phone.

In January 2024 an employee of the engineering firm Arup, in Hong Kong, joined a video conference with what appeared to be the company's chief financial officer and several colleagues. Every other participant was synthetic. Over multiple transactions the employee sent HK$200 million, about US$25 million, to five Hong Kong bank accounts. Arup confirmed to the Financial Times that false voices and images were used.

What matters for a small firm is not the amount. It is that the meeting looked and sounded like the people it claimed to be, to someone who knew them - and that the fraud was found by contacting head office separately afterwards, not by anything noticed during the call.

Voice cloning needs seconds of audio. Anyone whose principals appear in a webinar, a podcast, a property listing video or a conference recording has supplied it already.

What used to work and no longer does:

  • Call them and check - the voice that answers, or that calls you, may be generated.
  • Get them on video so you can see them - the Arup employee was on a video call with several fabricated colleagues.
  • I would recognise my own CFO - recognition is the thing being defeated, and recognising someone correctly is not the same as verifying them.
  • Ask a personal question - a caller who has read the mailbox may know the answer.

What still works:

  • Never action a change of payment details during the interaction that requests it, whoever appears to be asking. The request and the authorisation are separated by design, not by suspicion.
  • Two people, one of whom did not receive the request, authorise any change to bank details or any unusual transfer.
  • Verify against the mandate you already hold - the account on the signed engagement - rather than against anything said in a meeting.
  • Where you do call to verify, YOU place the call, to a number you held before the request existed. Cloning does not help an attacker on a line they did not choose.
  • Tell your staff plainly that a convincing voice or face is no longer evidence of anything, and that they will never be criticised for delaying a payment to check.

Why the second one holds and the first did not. The control this generation defeated rested on a person noticing something. What still works rests on how you are organised - decided before the moment rather than in it.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleHIGHhas A4, A5, A6; does not have A9
real estate, 1-10 peopleHIGHhas A4, A5, A6; does not have A9
real estate, franchise or multi-officeHIGHhas A4, A5, A6, A9
retail or hospitality, 1-10 peopleLOWhas A5; does not have A4, A6, A9

A4 Principals whose voice or likeness is publicly available in volume. A5 Payments authorisable verbally, or by one person acting alone. A6 Distributed staff who transact by video or phone. A9 Layered authority, where staff have not met the people who authorise.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • Arup deepfake video-conference fraud, Hong Kong, January 2024: HK$200 million (about US$25 million) transferred across multiple transactions to five bank accounts after a video call on which the CFO and other colleagues were AI-generated. Arup confirmed to the Financial Times that false voices and images were used, and reported the matter to Hong Kong police.
  • NZ National Cyber Security Centre, Rise in financial losses reported to the NCSC, 13 June 2025, for the targeting of organisations that manage large financial transactions such as law firms and real estate agencies.
  • NOT marked reviewed, 3 September 2026: the Arup account here comes from contemporaneous trade and news reporting of the incident, read 3 September 2026. Arup's own confirmation was given to the Financial Times and has NOT been read in the original, nor has any court or police document. Nothing here is alleged against any named individual.
  • CNN Business, 'British engineering giant Arup revealed as $25 million deepfake scam victim', by Kathleen Magramo, published 16 May 2024 and updated 17 May 2024. READ AT SOURCE 8 September 2026 in a browser, not via summary. Gives the figure as HK$200 million, about US$25.6 million, and records that a spokesperson for London-based Arup told CNN it notified Hong Kong police in January 2024. This corroborates both the amount and the January timing INDEPENDENTLY of the Financial Times account, which remains unread. Note one discrepancy recorded rather than smoothed: CNN's wording is 'Hong Kong employees' plural paying out, where this pattern says an employee. The singular is the widely reported account; we have not resolved which is right and have not changed the pattern on the strength of one phrase.

Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.

You changed the password

Takeover
Generation 1 · as at 2026-09-03

How this family has moved:

  1. Generation 1: You changed the password ← this one
  2. Generation 2: They left something behind
  3. Generation 3: The session never needed the password again

Someone got into an account. You reset the password, and that was the end of it.

This family is not about how they got in - that is the credential-theft patterns. It is about GETTING THEM OUT, which turns out to be a different problem with a different answer.

The control worked while access meant knowing a secret. Change the secret and the access ends, because the secret WAS the access.

Every generation below is a way in which that stopped being true.

What still works:

  • Treat a compromised account as an INCIDENT WITH A CHECKLIST, not as a password to change. Write the checklist before you need it; nobody composes one calmly at 4pm on a settlement day.
  • Assume the attacker read everything the account could reach while they had it, and act on that separately from closing the access.
  • Tell the people who might be contacted in your name. New Zealand's NCSC advises alerting clients about potentially suspicious messages received from your firm.

Why the second one holds and the first did not. The control this generation defeated rested on a fact checked once and then relied on. What still works rests on how you are organised - decided before the moment rather than in it.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleHIGHhas A1, A6
real estate, 1-10 peopleHIGHhas A1, A6
real estate, franchise or multi-officeHIGHhas A1, A6
retail or hospitality, 1-10 peopleMEDIUMhas A1; does not have A6

A1 Accepts payment instructions or bank-account changes by email. A6 Distributed staff who transact by video or phone.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • NZ National Cyber Security Centre via Own Your Online, Law firms: check your email systems, dated 3 March 2025, read 3 September 2026.
  • NZ NCSC, Quarter Two Cyber Security Insights 2026: unauthorised access accounted for NZ$1.3 million of direct financial loss in the quarter.
  • NOT marked reviewed, 3 September 2026: read from the Own Your Online and NCSC websites rather than from the underlying reports.

Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.

They left something behind

Takeover
Generation 2 · first observed 2025-03-03 · as at 2026-09-03

How this family has moved:

  1. Generation 1: You changed the password
  2. Generation 2: They left something behind ← this one
  3. Generation 3: The session never needed the password again

The attacker no longer needs the account. Before you locked them out they created a mail rule, and the rule is not a credential - so changing the password does nothing to it.

A forwarding rule quietly copies everything to them. A filtering rule silently moves your supplier's emails to a folder you never open, so the conversation you think you are having is one they are having.

This is not hypothetical in New Zealand and it is not generic. The NCSC issued an alert to LAW FIRMS about a surge in exactly this, and named the reason plainly: "Cybercriminals are targeting law firms because transactions usually involve large sums of money." It describes the outcome in one line: "If an attacker gains access to your email account, they can send invoices to your clients with altered invoice account numbers."

Note where that lands. The victim of the payment is your CLIENT, and the instrument is your genuine mailbox. This is where account takeover joins the payment family from the other end.

What used to work and no longer does:

  • We changed the password, so they are out - a rule they left behind is not protected by the password and does not care that it changed.
  • We would have noticed unusual emails - a filtering rule exists precisely so you do not see them.
  • Our email looks normal - it is normal. That is the point.

What still works:

  • After any compromise, READ THE CONFIGURATION, not just the credentials. The NCSC names three checks: auto-forwarding rules, especially those relating to accounts receivable; auto-filtering rules you did not set up; and email access logs for unusual login times, patterns or IP addresses.
  • This is a control that does not depend on anyone noticing anything in the moment - it is a comparison of what the account SAYS it is configured to do against what you intended. Do it on a schedule, not only after an incident, because the rule outlives the intrusion that created it.
  • Where your provider allows it, alert on rule creation. A new forwarding rule is a rare, high-signal event and it is one of the few reliable tells this family leaves.

Why the second one holds and the first did not. The control this generation defeated rested on how things were arranged, and the arrangement stopped holding. What still works rests on cross-referencing data rather than on judgement in the moment.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleHIGHhas A1, A2, A6
real estate, 1-10 peopleHIGHhas A1, A2, A6
real estate, franchise or multi-officeHIGHhas A1, A2, A6
retail or hospitality, 1-10 peopleLOWhas A1; does not have A2, A6

A1 Accepts payment instructions or bank-account changes by email. A2 Handles client or third-party funds - deposits, settlement, a trust account. A6 Distributed staff who transact by video or phone.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • NZ National Cyber Security Centre via Own Your Online, Law firms: check your email systems, dated 3 March 2025, read 3 September 2026 - for the surge in law firm compromise, the targeting rationale, the altered-invoice outcome and all three named checks.
  • Own Your Online, Protect your business against email compromise, read 3 September 2026, for the auto-forwarding and auto-filtering rule checks.
  • NOT marked reviewed, 3 September 2026: both were read as web pages, and the March 2025 alert may have been updated since. No New Zealand incident is named here beyond the NCSC's own description of the pattern.

Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.

The session never needed the password again

Takeover
Generation 3 · as at 2026-09-03

How this family has moved:

  1. Generation 1: You changed the password
  2. Generation 2: They left something behind
  3. Generation 3: The session never needed the password again ← this one

Once you are signed in, your device holds a session - a token that says the login already happened. The password is not re-checked on every action, which is the whole point of staying signed in.

A relay-phishing attack (see the credential-theft patterns) steals that session rather than the password. And a session is not a secret you can change. CHANGING THE PASSWORD DOES NOT NECESSARILY END IT.

The same is true of anything else granted alongside the account: a connected third-party application, a delegated mailbox, a recovery method the attacker added, an app password. Each is a separate grant of access, and each survives a password reset on its own terms.

So the eviction step everyone knows - change the password - closes the door the attacker is no longer using.

What used to work and no longer does:

  • Change the password and set up 2FA - necessary, and not sufficient on its own to end an active session.
  • They will need to log in again - not if they never logged out, and a stolen session means they never had to log in at all.
  • We turned on MFA afterwards - MFA gates the creation of a session, not the life of one that already exists.
  • Any eviction step that treats the credential as the only thing granting access.

What still works:

  • Add three steps to your compromise checklist that the common advice does not include: REVOKE ALL ACTIVE SESSIONS (sign out everywhere), REVIEW AND REMOVE CONNECTED APPLICATIONS AND DELEGATED ACCESS, and CHECK RECOVERY METHODS - phone numbers, alternate addresses, app passwords - for anything the attacker added.
  • Do them in order: revoke sessions AFTER changing the password, or the live session can simply set a new one.
  • Then do the generation-two checks - forwarding rules, filtering rules, access logs - because the configuration outlives the access.
  • Ask your IT provider to confirm each of these was done, by name. "We secured the account" is not an answer; "we reset the password, revoked sessions, removed two OAuth grants and found no rules" is.

Why the second one holds and the first did not. The control this generation defeated rested on how things were arranged, and the arrangement stopped holding. What still works rests on how you are organised - decided before the moment rather than in it.

Who this lands on hardest

BusinessRelevanceWhy
legal, 1-10 peopleHIGHhas A2, A5, A6
real estate, 1-10 peopleHIGHhas A2, A5, A6
real estate, franchise or multi-officeHIGHhas A2, A5, A6
retail or hospitality, 1-10 peopleLOWhas A5; does not have A2, A6

A2 Handles client or third-party funds - deposits, settlement, a trust account. A5 Payments authorisable verbally, or by one person acting alone. A6 Distributed staff who transact by video or phone.

Relevance is computed from the traits above, not assigned by hand: how many of this pattern's traits your business has, out of how many it has in total. The industry profiles behind it are our editorial judgement, published so you can disagree with a specific line rather than with a number. Formula version 1.0.

Sources:

  • CISA, Implementing Phishing-Resistant MFA fact sheet, read 3 September 2026, for the relay-phishing mechanism by which a session is captured rather than a password. See the credential-theft family, generation three.
  • Own Your Online (NZ government), Protect your business against email compromise, READ 3 SEPTEMBER 2026. Its post-compromise advice lists four steps: change the passwords on all affected email accounts immediately; set up 2FA; tell your IT provider; and ask your IT provider to check the system for installed malware.
  • OBSERVATION, STATED CAREFULLY BECAUSE IT CONCERNS OFFICIAL GUIDANCE. Signing out active sessions and reviewing connected applications did not appear in that four-step list on the day we read it. That is not a claim the guidance is wrong - every step it gives is correct and necessary, and the companion NCSC alert to law firms DOES tell firms to check access logs and mail rules. It is a narrower point: a control set built around changing a credential does not by itself end a session that no longer depends on that credential. We record it because a reader following the four steps exactly could believe the account is closed while it is not.
  • This page may be out of date the moment the guidance is updated. Anyone relying on it should re-read the source and, if it now covers session revocation, tell us and we will correct this.
  • NOT marked reviewed, 3 September 2026: read as web pages rather than underlying documents, and no New Zealand case of session-token persistence after a password reset is cited, because we have not verified one.

Not every source behind this pattern has been read in full. Where a court order or filing is cited, we have relied on independent reports of it rather than the document itself, and say so here rather than let the citation imply otherwise.