How businesses can fight impersonation scams
Scammers don't always need to break into a company's systems to steal from its customers. More and more, they just pretend to be that company. They copy a logo, copy a colour scheme, copy the way a business writes its emails, and then use that borrowed trust to ask for money or personal details. It's a simple trick, but it works often enough to be worth billions of dollars a year worldwide, and New Zealand businesses and shoppers are firmly in the firing line.
The scale of the problem has been climbing steadily. Netsafe has tracked a sharp rise in money lost to impersonation scams, with reported losses jumping from $5000 in one month to $19,600 the next, an average of roughly $268 per scam. Numbers like that likely understate the real picture too, since most people who fall for a scam never report it. Text messages and emails remain the easiest way in for scammers, and the fake messages usually pretend to come from organisations people already trust and expect to hear from, such as transport agencies, courier companies, banks, or well-known tech brands. A common version simply claims the recipient owes a small toll or delivery fee, with a link attached that looks official but leads somewhere else entirely.
What consumers should look out for
The good news is that most impersonation scams share the same weak spots, once you know where to look. A message that creates urgency, an unpaid toll, a locked account, a parcel stuck in customs, is designed to make people click before they think. Genuine companies rarely demand instant action over text.
Checking where a message actually came from matters more than most people realise. One security expert put it simply: people should look out for misspelt email addresses or overseas phone numbers attached to organisations that are supposedly based in New Zealand. A bank or courier company based here has no reason to be texting from an international number.
It's also worth remembering that scammers are good at using relationships against people, not just brand names. Netsafe has described this directly, saying impersonation scams work because they exploit relationships and the perception of trust. That's why a message pretending to be from a company you already use, or even a friend or family member in a sudden emergency, can slip past someone's usual caution. The organisation's advice is to check any unusual request, even if it looks like it's from someone familiar.
A few habits go a long way here. Never click a link in an unexpected text or email, even if it looks legitimate; instead, open the company's official app or type its website address in manually. If a message claims to be from your bank, call the number printed on your card, not any number given in the message itself. Treat any request for a one-time code, password, or payment as suspicious until it's confirmed through a channel you know is real. And if a deal, invoice, or refund seems to have arrived out of nowhere, it's worth pausing and asking whether you were actually expecting it.
What it means for businesses being copied
For the businesses being impersonated, the damage is twofold. There's the financial harm to customers, but there's also the reputational cost of having your name dragged through a scam you didn't create. One government cyber security agency has pointed out how easily this happens in practice, noting that once scammers gain access to a company's email accounts, they can send fraudulent messages that customers have no way of telling apart from the real thing. Businesses using everyday cloud email platforms are especially exposed if login details aren't properly protected, so basic account security matters just as much as anything customer-facing.
Beyond locking down email accounts, businesses can take a more active role in getting ahead of scammers rather than just cleaning up after them. Telling customers clearly, on the website, in emails, and on social media, exactly what the business will and won't ever ask for by text or email removes a lot of the confusion scammers rely on. Regularly searching for copycat websites using a business's name, logo, or branding can catch fake sites before they start causing damage rather than after. Some organisations now use tools built specifically to hunt for these fake sites automatically; Netsafe's own detection tool was built with exactly that purpose, aiming to catch scam websites that copy real brands before customers ever land on them.
Reporting matters more than people think
One of the most useful things both individuals and businesses can do is simply report scams when they see them, even when no money has changed hands. Only a small fraction of scams are ever reported, which makes it easier for the same campaign to keep circulating and catching new victims. Reports can be made to Netsafe, to CERT NZ for anything involving a hacked account or compromised system, or to police for anything involving an actual financial loss.
None of this requires businesses or shoppers to become cyber security experts. Most impersonation scams rely on people being rushed, distracted, or simply unaware that copying a brand has become this easy. A little scepticism toward unexpected messages, some basic account hygiene, and a habit of reporting suspicious activity go a long way toward closing the gap that scammers are counting on.