Phishing and scam terms, and where to report them in New Zealand

Many of the problems people hope antivirus software will prevent are not malware at all. They are deceptions aimed at the person rather than the device. This page defines the common terms, explains where security software helps and where it does not, and lists the New Zealand organisations that take reports.

Quick answer. Phishing is a message pretending to be from someone you trust; smishing is the text-message version and vishing the phone version. Security software can block some known phishing websites and harmful attachments, but it cannot stop you from choosing to share a password or make a payment. Checking a request through a contact method you already trust is the habit that matters most.

Scams delivered by message

Phishing
An email that imitates a bank, government agency, courier, streaming service or employer in order to get you to click a link, open an attachment, enter a password or pay money. The link usually leads to a convincing copy of the real sign-in page.
Spear phishing
Phishing tailored to a particular person or organisation, using details such as names, job titles or recent transactions to seem credible. It is harder to spot because it lacks the generic tone of mass phishing.
Smishing
Phishing by text message (SMS). Common themes include missed deliveries, unpaid tolls or fines, and account problems. Messages are short, often urgent, and include a link.
Vishing
Phishing by voice call. The caller may claim to be from a bank's fraud team, an internet provider, a government department or a well-known software company. Caller ID can be faked, so a familiar number on screen proves nothing.
Spoofing
Falsifying the apparent sender of an email, text or call. A spoofed message can show a real organisation's name or number in the "from" field.
Business email compromise
A scam in which an attacker gains access to, or imitates, a business email account, and uses it to redirect payments, typically by sending "updated bank details" for a genuine invoice. Households can meet this when paying a tradesperson or a property settlement.

Worked example. A text says a parcel could not be delivered and asks for a small redelivery fee through a link. The link leads to a page styled like a courier's site asking for card details. Nothing is installed on the phone, so there is nothing for security software to detect on the device itself; at most, a web protection feature might recognise the page if it has already been reported. The reliable defence is to check the parcel's status through the courier's own app or website, reached without using the link.

Scareware and fake security alerts

Scareware deserves its own section on a site about antivirus, because it imitates the very software it sells. A web page, pop-up or advert displays what looks like a system warning — a scan in progress, a list of "threats", a red banner claiming your device is compromised — and urges you to install a product or call a number at once.

A web page cannot scan your device. Any page that claims to have done so is not telling the truth, whatever brand names or logos it displays. Genuine notifications from security software you have installed appear through your operating system's own notification system, not inside a browser tab. If a page like this appears, closing the browser tab, or the whole browser, is the right response. If it will not close, restarting the device is safe and does not need any special tool.

Some scareware pages use the names of real security companies to seem credible. Legitimate vendors do not sell this way, and a reputable product page will set out its terms calmly, as described on the subscription terms page.

Remote access and tech support scams

In a remote access scam, the scammer contacts you — or gets you to contact them through a fake alert — and claims there is a problem with your computer, your internet connection or your bank account. They then ask you to install a remote access tool so they can "fix" it. Once connected, they may show you fabricated evidence of a problem, ask for payment, or use their access to reach your online banking.

Remote access tools are legitimate software with genuine uses, so security products often do not block them. The protection here is a simple rule: do not let anyone who contacted you unexpectedly connect to your device. If you are unsure whether a call is genuine, hang up and call the organisation back on a number from its official website or a bill.

Attacks on accounts rather than devices

Credential stuffing
Automated attempts to sign in to many services using usernames and passwords leaked from another breach. Defeated by using a different password for every important account.
Account takeover
An attacker gaining control of an email, social media or shopping account, often by phishing or credential stuffing, and then using it to reach further accounts or to scam the owner's contacts.
SIM swap
Persuading a mobile provider to move your phone number to a SIM card the scammer controls, so that text-message sign-in codes go to them. An authenticator app or security key is harder to redirect.

The National Cyber Security Centre's Own Your Online guides explain how to set up unique passwords, a password manager and two-step verification in practical, step-by-step terms. Those three measures address most account attacks, and none of them depends on antivirus software.

Where security software helps, and where it cannot

Scam types and the role of security software
SituationCan security software help?What protects you most
Phishing email with a harmful attachmentOften: the attachment may be detected when openedNot opening unexpected attachments
Phishing link to a fake sign-in pageSometimes: if the page is already known, web protection may block itGoing to sites directly, not through links; two-step verification
Text message asking for a paymentRarely: nothing is installedChecking through the organisation's own app or website
Phone call from "tech support"NoHanging up and calling back on a known number
Scareware page in the browserSometimes: the page may be blockedClosing the tab; never calling the number shown
Reused password leaked elsewhereNoUnique passwords and two-step verification

A short checklist for unexpected requests

  • Did this message or call arrive without my asking for it?
  • Is it asking me to act quickly, or warning of a consequence if I do not?
  • Is it asking for a password, a code, card details, a payment or access to my device?
  • Can I check it by going to the organisation directly, without using any link or number in the message?
  • If it claims to be from someone I know, can I confirm with them another way?

If the first three answers are yes, treat the request as suspicious until checked. Legitimate organisations accept that you will want to verify them.

Where to report in New Zealand

Reporting helps the agencies warn others, and in some cases recover money. The right place depends on what happened:

  • Cyber security incidents, including scams, malware and compromised accounts, can be reported to the National Cyber Security Centre, which also runs the Own Your Online advice site for households.
  • Online harm and scams can be raised with Netsafe, New Zealand's independent online safety organisation.
  • Spam and scam messages by email or text fall within the work of the Department of Internal Affairs, whose spam page explains how to report them.
  • Information about current scams is published on Consumer Protection's Scamwatch.
  • Misleading conduct by a business, such as false claims made to sell a product, falls under the Fair Trading Act and can be raised with the Commerce Commission.
  • Money lost or card details shared: contact your bank straight away using a number you already have, such as the one on the back of your card.
  • A privacy breach by an organisation holding your information can be raised with the Office of the Privacy Commissioner if the organisation does not resolve it.