Case Library / Vishing (Voice Phishing) / NZ Bank-Impersonation Spoofed-Callback Vishing Scam: $30,000 Banking Ombudsman Case

NZ Bank-Impersonation Spoofed-Callback Vishing Scam: $30,000 Banking Ombudsman Case

A scammer spoofed a New Zealand bank's real phone number, posed as its fraud team, and talked a customer into reading out authentication codes for a fake "safe account" transfer, stealing NZD 30,000 before the Banking Ombudsman recommended the bank reimburse her in full plus costs.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In late 2024, a New Zealand bank customer referred to as "Greer" in the Banking Ombudsman Scheme's published case note received a phone call from a man claiming to work for her bank's fraud team, who said he had identified unusual transactions on her account. The call displayed a caller ID matching the bank's genuine, published phone number; the number had been spoofed. He told her she would receive codes to suspend her internet banking and cancel the suspicious payments, and instructed her to read the codes back to him; she complied because the number appeared legitimate. She grew suspicious only when he then said she needed to move her money to a "safe account," at which point she hung up and called the bank directly, learning it had been a scam. By then the scammer had already executed a $30,000 transaction on her credit card account (used to purchase goods at an Auckland merchant, picked up roughly 15 minutes before recovery could be attempted) and had attempted a second, larger payment that the bank's fraud-detection system blocked. The bank initially refused full reimbursement, arguing she had breached its terms of service by sharing the codes, and offered only half the loss. The Banking Ombudsman Scheme (case note 87834, published December 2024) ruled in her favor and recommended full reimbursement plus compensation for handling delays. RNZ reported the decision on 12 January 2025.

How the Attack Worked

The scammer called the victim ("Greer") using a spoofed caller ID that displayed the bank's genuine published phone number, so it matched the number on the bank's own website when she checked it. He claimed to be a bank fraud-team staff member who had spotted unusual transactions, and said he would suspend her internet banking and cancel the suspicious payments, actions for which she would receive verification codes that she needed to read back to him. The codes were, in reality, one-time authorization/2FA codes; reading them out let the scammer approve fraudulent actions on her account. He "skilfully mimicked" genuine bank call-centre procedure throughout. She only became suspicious when he then told her she needed to move her money into a "safe account" (a classic red flag phase of TOAD/safe-account scams), at which point she hung up and called the bank directly, discovering the fraud. By then the scammer had already used the credit card account to make a $30,000 purchase at an Auckland merchant and had attempted a second, larger payment that the bank's automated fraud detection blocked.

The Lure & the Tell

The lure: a call that displayed the bank's real, publicly listed phone number (via caller-ID spoofing), combined with a script that closely mirrored genuine bank fraud-team language: flagging "unusual transactions" and framing the codes as necessary to suspend banking and cancel payments, which was "sufficiently close to their true purpose to trick a reasonable person" per the Ombudsman. The tell: the pivot to asking her to move money into a "safe account," a request no legitimate bank fraud team makes, which triggered her suspicion and prompted her to hang up and call the bank independently.

Outcome

The scammer completed a $30,000 unauthorized transaction on the victim's credit card account (used to buy goods at an Auckland merchant, collected roughly 15 minutes before she could intervene) and attempted a second, larger payment that the bank's security system blocked. The victim reported the fraud immediately, but the merchant would not return funds since the goods were already released. The bank initially denied full reimbursement, citing a terms-of-service clause against sharing verification codes, and offered only 50% ($15,000). The customer escalated to the Banking Ombudsman Scheme (case note 87834, published December 2024), which found she had acted reasonably: noting the number was convincingly spoofed, the scam script closely mimicked real bank procedure, the bank's own SMS codes carried no anti-sharing warning, and the bank itself had separately asked her husband to read out a 2FA code, undermining its own rule. The Ombudsman also faulted the bank's fraud-response handling. It recommended the bank reimburse the full $30,000 plus NZD 1,000 for delays. Banking Ombudsman Nicola Sladden characterized it as "a sophisticated bank impersonation case" and noted bank-impersonation scams made up almost a quarter of all fraud/scam cases the Scheme received that financial year. RNZ reported the ruling on 12 January 2025.

Why It Matters

This case is a well-documented regulatory precedent showing that (1) caller-ID spoofing of a bank's real number defeats the standard consumer advice to "check the number before trusting a caller," and (2) banks cannot rely on blanket "never share your code" contract clauses to deny reimbursement if their own operational practices (e.g., asking customers to read codes aloud during legitimate setup calls) are inconsistent with that rule. It also quantifies scale: the Banking Ombudsman noted bank-impersonation scams made up nearly a quarter of all fraud/scam complaints the Scheme received that financial year, underscoring that spoofed-callback ("TOAD," short for telephone-oriented attack delivery) vishing against bank customers is a systemic, not isolated, threat pattern in New Zealand.

Defenses

Banking Ombudsman's ruling effectively pushed for: (1) SMS/OTP messages that explicitly warn customers never to share the code, since the bank's messages carried no such warning; (2) consistency in bank practice, since staff themselves had asked the customer's husband to read out a 2FA code during account setup, undermining the "never share codes" T&C the bank tried to enforce against the victim; (3) faster, more coordinated fraud-report handling, since the Ombudsman found the bank's own delays may have let the loss happen; (4) broader telecom/bank work (flagged in CERT NZ's Q2 2022 report) to block caller-ID spoofing of bank numbers. For consumers, the case underscores that a matching caller ID is not proof of authenticity when numbers can be spoofed, and that a legitimate-sounding request to read out a "cancellation" or "suspension" code is functionally identical to handing over the code that authorizes a fraudulent transaction.

Sources
  • Customer acted reasonably despite sharing codes with scammer (Case note 87834). Banking Ombudsman Scheme (New Zealand) Primary. Official published case note detailing the facts, the bank's position, the Ombudsman's investigation and reasoning, and the reimbursement outcome. Verified by direct fetch: content matches all attributed facts exactly, including quotes.
  • CERT NZ Q2 2022 Cyber Security Insights report. CERT NZ / National Cyber Security Centre (NCSC) Primary. Government report documenting the broader NZ scam pattern of bank-impersonation phone-number spoofing and scammers asking victims to read out SMS verification codes; provides background context, not specific to this individual case. Verified by direct fetch: PDF loads and its 'Banking on a disguise' section matches the claimed content.
  • Bank told to reimburse $30,000 after scammer impersonates staff. RNZ (Radio New Zealand) Secondary. News report summarizing the Ombudsman case, including direct quotes from Banking Ombudsman Nicola Sladden and the statistic that bank-impersonation cases made up nearly a quarter of the Scheme's fraud/scam caseload that financial year. Verified by direct fetch: article loads, dated 12 January 2025, content matches exactly.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: The scammer likely obtained the victim's phone number and confirmed which bank she used before calling, consistent with the target selection typical of telephone-oriented attack delivery (TOAD) campaigns; the published sources do not confirm the specific method used in this case.
Countering Stage 1: Consumer-side exposure of phone numbers and banking relationships is very hard to close at a population scale given data broker records, prior breaches, and social media; the realistic control assumes attackers can already identify a real customer of a given bank and focuses defenses on the later stages of the call itself.
2
Caller ID spoofing setup: The scammer used caller ID spoofing (documented by CERT NZ as a recurring pattern in New Zealand bank-impersonation scams, sometimes via commercial phone-spoofing services) to display the bank's genuine, publicly listed phone number on the victim's phone when he called.
Countering Stage 2: Telecom-and-bank collaboration to authenticate or block spoofed calls impersonating registered bank numbers, the approach CERT NZ and New Zealand banks pursued with the Telecommunications Forum, directly targets this stage, though scammers can adapt by using closely-imitating numbers instead of exact spoofs.
3
Pretext call and authority establishment: The scammer called posing as bank fraud-team staff, claimed to have identified unusual transactions on the account, and used a script and manner the Banking Ombudsman found had "skilfully mimicked" genuine bank call-centre procedure.
Countering Stage 3: Customer education and in-app or statement messaging stating plainly that the bank will never call and ask a customer to read out a verification code reduces the odds a scripted "fraud team" call is believed, regardless of what the caller ID shows.
4
Real-time OTP relay to defeat two-factor authentication: While the victim was on the line, the scammer triggered genuine bank-generated one-time SMS codes tied to real account actions, described them as "cancellation" or "suspension" codes, and had the victim read them back to him, using her as an unwitting relay to authorize actions that actually benefited him.
Countering Stage 4: This is the highest-leverage control point. SMS/OTP messages should explicitly warn "do not share this code with anyone, including bank staff" (a warning the Ombudsman found missing here), and banks should never have their own staff ask customers to read codes aloud, since that practice is exactly what made the scammer's request sound normal to the victim.
5
Unauthorized transaction execution: Using the relayed codes, the scammer authorized a $30,000 purchase on the victim's credit card account at an Auckland merchant and attempted a second, larger payment that the bank's automated fraud-detection system blocked.
Countering Stage 5: Transaction-level anomaly detection and step-up verification for high-value or first-time-merchant purchases is what stopped the second, larger payment attempt in this case, and is the realistic backstop once a code has already been shared.
6
Escalation to a fake "safe account" transfer: The scammer pivoted to instructing the victim to move her remaining funds into a supposed "safe account," the classic follow-on stage of safe-account social engineering scams intended to capture additional funds beyond the initial unauthorized transaction.
Countering Stage 6: Front-line staff and automated fraud rules should treat any instruction to move funds into a new "safe account" as a near-certain scam indicator, since no legitimate bank fraud process asks a customer to transfer money to a separate account for safekeeping.
7
Cash-out via rapid goods pickup: The purchased goods were collected from the Auckland merchant within roughly 15 minutes, converting the stolen credit line into resellable physical goods before the victim or bank could intervene, completing the theft.
Countering Stage 7: Faster bank-to-merchant fraud alerts immediately after a report, and merchant or card-network holds on high-value purchases pending fraud confirmation, could narrow the window between purchase and pickup; in this case the bank's contact to the merchant came just after the roughly 15-minute pickup window had already closed.
Quick Facts
Victim
"Greer" (pseudonym used in the published case note), a customer of an unnamed New Zealand retail bank; her husband "Anton" is also referenced
Location
New Zealand (purchase made via an Auckland-based merchant); Banking Ombudsman Scheme is a national NZ dispute-resolution body
Date
December 2024 (Ombudsman case note published; underlying scam call occurred shortly before; RNZ reported it 12 January 2025)
Impact
NZD 30,000 stolen (used to buy goods at an Auckland merchant via the victim's credit card account); a second, larger fraudulent payment was blocked by the bank's security system. The bank initially offered to reimburse only half ($15,000); the Banking Ombudsman Scheme recommended full reimbursement of the $30,000 loss plus an additional NZD 1,000 for delays in handling the fraud case (total ~NZD 31,000 recommended).
Status
Confirmed
Case Type
Real-World Incident
Sector
Financial Services & Insurance
Related

Related Cases

Singapore Anti-Scam Centre / Police Impersonation Scam: "Jane" Loses S$1.2 Million (2024-2025)

A Singaporean finance professional in her 50s lost S$1.2 million (~US$900,000) over two months after scammers impersonating an Anti-Scam Centre…

Incident 2024Read →

Jeffrey Maas PNC Bank Gold-Conversion Vishing Fraud (West Orange, NJ, 2024)

A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…

Incident 2024Read →

Arup Hong Kong Deepfake CFO Video-Call Fraud (HK$200M / US$25.6M)

A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…

Incident 2024Read →