What the Kiwi pilot tells us
NZ Herald has reported that a Static Technologies pilot prevented $23.8 million in consumer scam losses, working with banks, telecommunications companies and Trade Me. The company looks for the systems criminals use to run scams so its partners can intervene sooner.
The report also cites Static Technologies’ analysis that 80% of phishing damage happens within the first 90 minutes of a fraud event. That is the company’s finding, rather than a rule for every scam. For a small business owner, the useful lesson is straightforward: put checks in place before money moves, and act promptly when something seems wrong.
What does phishing mean?
Phishing is a message designed to trick you into giving away information or taking an unsafe action. It might pretend to be your bank, a supplier or a courier. The aim could be to steal your password, persuade you to make a payment or get you to open a harmful attachment.
A familiar logo or sender name is not enough to prove a message is genuine. Some invoice scams even come from a real business email account that a criminal has taken over.
A simple example for a busy owner
Imagine you receive an email from a regular supplier saying their bank account has changed. An invoice is attached, and payment is urgent. You are on site, the accounts person is busy and the message looks familiar.
Before paying, call the supplier using the number already in your records. Confirm the account change with someone you know. Do not use a new number supplied in the suspicious email. That independent check can interrupt the scam, even when the invoice looks convincing.
This approach follows Own Your Online’s guidance on invoice scams.
Five practical checks to put in place
- Verify new payment details. Make an independent phone check before changing a supplier’s bank account. Record who confirmed the change and when.
- Protect your email login. Use a unique password and turn on multi-factor authentication, which adds another check when you sign in. Ask your IT provider to help if you are unsure.
- Use a second payment check. Choose an amount above which another authorised person checks the invoice, recipient and account details. Agree a process for times when that person is away.
- Make it easy to raise a concern. Tell staff who to contact about suspicious messages. Thank them for checking, even when it turns out to be a genuine request.
- Keep response contacts ready. Save your bank’s fraud contact and your IT provider’s number somewhere you can reach if business email is unavailable.
If you think a scam has got through
If money or banking details are involved, contact your bank immediately through its official channels. Ask whether a payment can be stopped or recovered. Recovery is not guaranteed, but early contact gives the bank a chance to act.
If you entered a password on a suspicious website, change it through the genuine service from a trusted device and contact your IT provider. Have them check account access and secure the affected account. Keep the messages and payment records so you can explain what happened.
Report the incident to NCSC and warn affected customers or suppliers if your business is being impersonated. Own Your Online’s business help page explains where to report and what to do next. Do not wait for the next staff meeting to raise a suspected scam.
Start with one change this week
Ask your team: “If a supplier changes their bank account today, how do we check it?” Write down the agreed process and make sure the person paying invoices can use it.
Then try Cybertool’s free ten-question starter check to identify gaps in your business’s basic cyber protections. You submit contact details to view your detailed result. For help turning those gaps into a practical plan, contact Cybertool about a consultant-led review.
Cybertool provides readiness checks and practical guidance. It does not provide Static Technologies’ scam-detection platform, and the reported pilot savings are not a Cybertool result.