A scammer spoofed a New Zealand bank's real phone number, posed as its fraud team.
Social Engineering Examples·3 sources
In late 2024, a New Zealand bank customer referred to as "Greer" in the Banking Ombudsman Scheme's published case note received a phone call from a man claiming to work for her bank's fraud team, who said he had identified unusual transactions on her account. The call displayed a caller ID matching the bank's genuine, published phone number; the number had been spoofed.
He told her she would receive codes to suspend her internet banking and cancel the suspicious payments, and instructed her to read the codes back to him; she complied because the number appeared legitimate. She grew suspicious only when he then said she needed to move her money to a "safe account," at which point she hung up and called the bank directly, learning it had been a scam.
By then the scammer had already executed a $30,000 transaction on her credit card account (used to purchase goods at an Auckland merchant, picked up roughly 15 minutes before recovery could be attempted) and had attempted a second, larger payment that the bank's fraud-detection system blocked. The bank initially refused full reimbursement, arguing she had breached its terms of service by sharing the codes, and offered only half the loss.
The Banking Ombudsman Scheme (case note 87834, published December 2024) ruled in her favor and recommended full reimbursement plus compensation for handling delays. RNZ reported the decision on 12 January 2025.
The scammer called the victim ("Greer") using a spoofed caller ID that displayed the bank's genuine published phone number, so it matched the number on the bank's own website when she checked it. He claimed to be a bank fraud-team staff member who had spotted unusual transactions, and said he would suspend her internet banking and cancel the suspicious payments, actions for which she would receive verification codes that she needed to read back to him.
The codes were, in reality, one-time authorization/2FA codes; reading them out let the scammer approve fraudulent actions on her account. He "skilfully mimicked" genuine bank call-centre procedure throughout. She only became suspicious when he then told her she needed to move her money into a "safe account" (a classic red flag phase of TOAD/safe-account scams), at which point she hung up and called the bank directly, discovering the fraud.
By then the scammer had already used the credit card account to make a $30,000 purchase at an Auckland merchant and had attempted a second, larger payment that the bank's automated fraud detection blocked.
The lure: a call that displayed the bank's real, publicly listed phone number (via caller-ID spoofing), combined with a script that closely mirrored genuine bank fraud-team language: flagging "unusual transactions" and framing the codes as necessary to suspend banking and cancel payments, which was "sufficiently close to their true purpose to trick a reasonable person" per the Ombudsman.
The tell: the pivot to asking her to move money into a "safe account," a request no legitimate bank fraud team makes, which triggered her suspicion and prompted her to hang up and call the bank independently.
The scammer completed a $30,000 unauthorized transaction on the victim's credit card account (used to buy goods at an Auckland merchant, collected roughly 15 minutes before she could intervene) and attempted a second, larger payment that the bank's security system blocked. The victim reported the fraud immediately, but the merchant would not return funds since the goods were already released.
The bank initially denied full reimbursement, citing a terms-of-service clause against sharing verification codes, and offered only 50% ($15,000). The customer escalated to the Banking Ombudsman Scheme (case note 87834, published December 2024), which found she had acted reasonably: noting the number was convincingly spoofed, the scam script closely mimicked real bank procedure, the bank's own SMS codes carried no anti-sharing warning, and the bank itself had separately asked her husband to read out a 2FA code, undermining its own rule.
The Ombudsman also faulted the bank's fraud-response handling. It recommended the bank reimburse the full $30,000 plus NZD 1,000 for delays. Banking Ombudsman Nicola Sladden characterized it as "a sophisticated bank impersonation case" and noted bank-impersonation scams made up almost a quarter of all fraud/scam cases the Scheme received that financial year.
RNZ reported the ruling on 12 January 2025.
This case is a well-documented regulatory precedent showing that (1) caller-ID spoofing of a bank's real number defeats the standard consumer advice to "check the number before trusting a caller," and (2) banks cannot rely on blanket "never share your code" contract clauses to deny reimbursement if their own operational practices (e.g., asking customers to read codes aloud during legitimate setup calls) are inconsistent with that rule.
It also quantifies scale: the Banking Ombudsman noted bank-impersonation scams made up nearly a quarter of all fraud/scam complaints the Scheme received that financial year, underscoring that spoofed-callback ("TOAD," short for telephone-oriented attack delivery) vishing against bank customers is a systemic, not isolated, threat pattern in New Zealand.
Banking Ombudsman's ruling effectively pushed for: (1) SMS/OTP messages that explicitly warn customers never to share the code, since the bank's messages carried no such warning; (2) consistency in bank practice, since staff themselves had asked the customer's husband to read out a 2FA code during account setup, undermining the "never share codes" T&C the bank tried to enforce against the victim; (3) faster, more coordinated fraud-report handling, since the Ombudsman found the bank's own delays may have let the loss happen; (4) broader telecom/bank work (flagged in CERT NZ's Q2 2022 report) to block caller-ID spoofing of bank numbers.
For consumers, the case underscores that a matching caller ID is not proof of authenticity when numbers can be spoofed, and that a legitimate-sounding request to read out a "cancellation" or "suspension" code is functionally identical to handing over the code that authorizes a fraudulent transaction.
Social Engineering Examples. “NZ Bank-Impersonation Spoofed-Callback Vishing Scam: $30,000 Banking Ombudsman Case”. Accessed 19 September 2026. https://socialengineeringexamples.com/nz-bank-impersonation-spoofed-callback-vishing-2024
The scammer likely obtained the victim's phone number and confirmed which bank she used before calling, consistent with the target selection typical of telephone-oriented attack delivery (TOAD) campaigns; the published sources do not confirm the specific method used in this case.
Consumer-side exposure of phone numbers and banking relationships is very hard to close at a population scale given data broker records, prior breaches, and social media; the realistic control assumes attackers can already identify a real customer of a given bank and focuses defenses on the later stages of the call itself.
The scammer used caller ID spoofing (documented by CERT NZ as a recurring pattern in New Zealand bank-impersonation scams, sometimes via commercial phone-spoofing services) to display the bank's genuine, publicly listed phone number on the victim's phone when he called.
Telecom-and-bank collaboration to authenticate or block spoofed calls impersonating registered bank numbers, the approach CERT NZ and New Zealand banks pursued with the Telecommunications Forum, directly targets this stage, though scammers can adapt by using closely-imitating numbers instead of exact spoofs.
The scammer called posing as bank fraud-team staff, claimed to have identified unusual transactions on the account, and used a script and manner the Banking Ombudsman found had "skilfully mimicked" genuine bank call-centre procedure.
Customer education and in-app or statement messaging stating plainly that the bank will never call and ask a customer to read out a verification code reduces the odds a scripted "fraud team" call is believed, regardless of what the caller ID shows.
While the victim was on the line, the scammer triggered genuine bank-generated one-time SMS codes tied to real account actions, described them as "cancellation" or "suspension" codes, and had the victim read them back to him, using her as an unwitting relay to authorize actions that actually benefited him.
This is the highest-leverage control point. SMS/OTP messages should explicitly warn "do not share this code with anyone, including bank staff" (a warning the Ombudsman found missing here), and banks should never have their own staff ask customers to read codes aloud, since that practice is exactly what made the scammer's request sound normal to the victim.
Using the relayed codes, the scammer authorized a $30,000 purchase on the victim's credit card account at an Auckland merchant and attempted a second, larger payment that the bank's automated fraud-detection system blocked.
Transaction-level anomaly detection and step-up verification for high-value or first-time-merchant purchases is what stopped the second, larger payment attempt in this case, and is the realistic backstop once a code has already been shared.
The scammer pivoted to instructing the victim to move her remaining funds into a supposed "safe account," the classic follow-on stage of safe-account social engineering scams intended to capture additional funds beyond the initial unauthorized transaction.
Front-line staff and automated fraud rules should treat any instruction to move funds into a new "safe account" as a near-certain scam indicator, since no legitimate bank fraud process asks a customer to transfer money to a separate account for safekeeping.
The purchased goods were collected from the Auckland merchant within roughly 15 minutes, converting the stolen credit line into resellable physical goods before the victim or bank could intervene, completing the theft.
Faster bank-to-merchant fraud alerts immediately after a report, and merchant or card-network holds on high-value purchases pending fraud confirmation, could narrow the window between purchase and pickup; in this case the bank's contact to the merchant came just after the roughly 15-minute pickup window had already closed.
Browse by what this case has in common with others in the library.
A Singaporean finance professional in her 50s lost S$1.2 million.
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers.
In June 2025 the DOJ filed a civil forfeiture complaint against more than $225.3M in Tether (USDT) traced to a…
A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over…
GootLoader operators hijacked Google search rankings for legal-agreement phrases.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
The FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.