Written for the situation where a payment has been made to bank details that turned out to be an attacker’s. Settlement funds, a supplier invoice, a deposit.
Speed is the whole thing. Consumer Protection puts it plainly: “contact your bank immediately. The sooner your bank knows about it the greater the likelihood of getting the money back.”
Right now — the first five minutes
1. Phone your bank’s fraud line. Not internet banking, not email, not a branch visit. Phone.
| Bank | Fraud line | From overseas |
|---|---|---|
| ANZ | 0800 269 348 | +64 4 470 3142 |
| ASB | 0800 272 372 | +64 9 303 0332 |
| BNZ | 0800 735 901 | +64 4 473 5901 |
| Kiwibank | 0800 113 355 | +64 4 473 1133 |
| Westpac | 0800 400 600 | +64 9 912 8000 |
2. If you know which bank received it, phone them too. You do not need to be their customer to report that a payment into one of their accounts is fraudulent. Tell them the amount, the date and time, the account number it went to, and that you believe it was fraud rather than a mistake. Those are different things to a bank and they are handled differently.
The thing almost nobody is told
Do not email the person you thought you were dealing with.
If this started with a compromised mailbox — and most of these do — the attacker is reading that mailbox. An email asking “have you changed your bank details?” tells them they have been caught, while they still have time to move the money.
Phone instead, on a number you already had. Not a number from the email.
Within the hour
3. Report it to Police. Call 105 for money lost in a scam, or use police.govt.nz/105support. A report matters even when recovery looks unlikely — it is often required by insurers, and it is how patterns get seen.
4. Report the cyber incident at ncsc.govt.nz/report/. This is the National Cyber Security Centre. (If you are looking for CERT NZ — it has been folded into the NCSC, and this is where its reporting now goes.)
5. Do not touch the mailbox. Do not delete the emails, do not tidy up, do not change anything in the compromised account before someone has looked at it. That mailbox is the evidence, and it is also the only way to find out how long the attacker was in there and what else they saw.
Then — the question most people miss
Was personal information exposed as well as money?
If an attacker had access to a mailbox containing other people’s personal information, that may be a notifiable privacy breach under the Privacy Act 2020 — separate from the money, and with its own obligation.
There is no 72-hour rule in New Zealand, despite how often you will hear one. The Privacy Commissioner’s actual wording is that you must notify “as soon as you practically can”, and that its expectation of 72 hours is “a guide only.” The test is whether the breach has caused, or is likely to cause, serious harm.
Notify at privacy.org.nz → NotifyUs. If you are unsure whether it qualifies, that uncertainty is not a reason to wait — the Office of the Privacy Commissioner accepts incremental updates as you learn more.
What not to do
- Do not pay anyone who offers to recover the funds for a fee. Recovery scams follow payment scams, and they often reach the victim first
- Do not make another payment to “correct” the first one until your bank has confirmed what happened
- Do not assume it is over because the money is gone. The mailbox access usually matters more than the single payment
We publish this because the advice exists in five places and nobody has put it in one. Bank numbers checked 8 September 2026 against each bank’s own page; next review due 4 March 2027. If something here is out of date, tell us: quentin@aileakage.com.
