A scammer spoofed a New Zealand bank's real phone number, posed as its fraud team, and talked a customer into reading out authentication codes for a fake "safe account" transfer, stealing NZD 30,000 before the Banking Ombudsman recommended the bank reimburse her in full plus costs.
Reviewed by the Social Engineering Examples team.
In late 2024, a New Zealand bank customer referred to as "Greer" in the Banking Ombudsman Scheme's published case note received a phone call from a man claiming to work for her bank's fraud team, who said he had identified unusual transactions on her account. The call displayed a caller ID matching the bank's genuine, published phone number; the number had been spoofed. He told her she would receive codes to suspend her internet banking and cancel the suspicious payments, and instructed her to read the codes back to him; she complied because the number appeared legitimate. She grew suspicious only when he then said she needed to move her money to a "safe account," at which point she hung up and called the bank directly, learning it had been a scam. By then the scammer had already executed a $30,000 transaction on her credit card account (used to purchase goods at an Auckland merchant, picked up roughly 15 minutes before recovery could be attempted) and had attempted a second, larger payment that the bank's fraud-detection system blocked. The bank initially refused full reimbursement, arguing she had breached its terms of service by sharing the codes, and offered only half the loss. The Banking Ombudsman Scheme (case note 87834, published December 2024) ruled in her favor and recommended full reimbursement plus compensation for handling delays. RNZ reported the decision on 12 January 2025.
The scammer called the victim ("Greer") using a spoofed caller ID that displayed the bank's genuine published phone number, so it matched the number on the bank's own website when she checked it. He claimed to be a bank fraud-team staff member who had spotted unusual transactions, and said he would suspend her internet banking and cancel the suspicious payments, actions for which she would receive verification codes that she needed to read back to him. The codes were, in reality, one-time authorization/2FA codes; reading them out let the scammer approve fraudulent actions on her account. He "skilfully mimicked" genuine bank call-centre procedure throughout. She only became suspicious when he then told her she needed to move her money into a "safe account" (a classic red flag phase of TOAD/safe-account scams), at which point she hung up and called the bank directly, discovering the fraud. By then the scammer had already used the credit card account to make a $30,000 purchase at an Auckland merchant and had attempted a second, larger payment that the bank's automated fraud detection blocked.
The lure: a call that displayed the bank's real, publicly listed phone number (via caller-ID spoofing), combined with a script that closely mirrored genuine bank fraud-team language: flagging "unusual transactions" and framing the codes as necessary to suspend banking and cancel payments, which was "sufficiently close to their true purpose to trick a reasonable person" per the Ombudsman. The tell: the pivot to asking her to move money into a "safe account," a request no legitimate bank fraud team makes, which triggered her suspicion and prompted her to hang up and call the bank independently.
The scammer completed a $30,000 unauthorized transaction on the victim's credit card account (used to buy goods at an Auckland merchant, collected roughly 15 minutes before she could intervene) and attempted a second, larger payment that the bank's security system blocked. The victim reported the fraud immediately, but the merchant would not return funds since the goods were already released. The bank initially denied full reimbursement, citing a terms-of-service clause against sharing verification codes, and offered only 50% ($15,000). The customer escalated to the Banking Ombudsman Scheme (case note 87834, published December 2024), which found she had acted reasonably: noting the number was convincingly spoofed, the scam script closely mimicked real bank procedure, the bank's own SMS codes carried no anti-sharing warning, and the bank itself had separately asked her husband to read out a 2FA code, undermining its own rule. The Ombudsman also faulted the bank's fraud-response handling. It recommended the bank reimburse the full $30,000 plus NZD 1,000 for delays. Banking Ombudsman Nicola Sladden characterized it as "a sophisticated bank impersonation case" and noted bank-impersonation scams made up almost a quarter of all fraud/scam cases the Scheme received that financial year. RNZ reported the ruling on 12 January 2025.
This case is a well-documented regulatory precedent showing that (1) caller-ID spoofing of a bank's real number defeats the standard consumer advice to "check the number before trusting a caller," and (2) banks cannot rely on blanket "never share your code" contract clauses to deny reimbursement if their own operational practices (e.g., asking customers to read codes aloud during legitimate setup calls) are inconsistent with that rule. It also quantifies scale: the Banking Ombudsman noted bank-impersonation scams made up nearly a quarter of all fraud/scam complaints the Scheme received that financial year, underscoring that spoofed-callback ("TOAD," short for telephone-oriented attack delivery) vishing against bank customers is a systemic, not isolated, threat pattern in New Zealand.
Banking Ombudsman's ruling effectively pushed for: (1) SMS/OTP messages that explicitly warn customers never to share the code, since the bank's messages carried no such warning; (2) consistency in bank practice, since staff themselves had asked the customer's husband to read out a 2FA code during account setup, undermining the "never share codes" T&C the bank tried to enforce against the victim; (3) faster, more coordinated fraud-report handling, since the Ombudsman found the bank's own delays may have let the loss happen; (4) broader telecom/bank work (flagged in CERT NZ's Q2 2022 report) to block caller-ID spoofing of bank numbers. For consumers, the case underscores that a matching caller ID is not proof of authenticity when numbers can be spoofed, and that a legitimate-sounding request to read out a "cancellation" or "suspension" code is functionally identical to handing over the code that authorizes a fraudulent transaction.
A Singaporean finance professional in her 50s lost S$1.2 million (~US$900,000) over two months after scammers impersonating an Anti-Scam Centre…
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…