
The original title is "How to Spot Phishing Emails — The NZ-Specific Guide for 2026"
Original: How to Spot Phishing Emails — The NZ-Specific Guide for 2026
Short summary
A practical New Zealand-focused phishing identification guide covering real local scam patterns including fake IRD rebate emails, Spark/Vodafone billing scams, and NZ Post delivery notices. It details how modern phishing uses credential harvesting, MFA relay attacks, and business email compromise as stepping stones to ransomware, with actionable steps for verifying sender domains and responding to suspected compromise. The guide emphasizes that phishing is fundamentally a psychology problem exploiting cognitive load, authority, and trust rather than a technology problem.
- •CERT NZ received 2,300+ phishing-related incident reports in 2024; phishing is the primary initial access vector for ransomware in NZ
- •Key indicators: verify sending domain not display name, watch for urgency pressure tactics, and never trust email links for NZ government, bank, or telco logins
- •Modern phishing bypasses MFA via real-time relay tools like EvilGinx and Muraena; response speed and password managers are critical mitigations
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



