Internet safety tips for business.

  • Keep operating systems and software up to date on all devices.
  • Keep data safe by implementing backup procedures.
  • Implement strong access and password controls.
  • Implement processes for verifying payments.
  • Regularly review procedures and controls to ensure they remain effective.
  • Educate your staff on the latest scams.
  • Have a response plan for cybersecurity incidents.

Common fraud and scams affecting businesses.

Business email compromise (BEC)

These involve a hacker gaining access to a business email account and all its information. From there, they can use the email account to carry out a range of fraud, scams and cyberattacks.

Learn how to protect your business from BEC


Scammers use social engineering to gain information from businesses that will allow them to commit fraud against the business and their clients. It’s important that staff stop and consider all requests before actioning them. 

Learn how to protect your business from impersonations


This is the sending of fake emails and text messages with embedded links or attachments that take the user to malicious sites or prompt malware to be installed. Criminals use phishing to steal personal information and/or banking details and commit fraud.

Learn how to protect your business from phishing

Counterfeit currency

New Zealand bank notes have unique features that can help identify them as genuine currency.  Counterfeit currency may be presented to or unknowingly accepted by a business. Ensure employees who handle cash are familiar with the features of genuine notes.

Visit the RBNZ website for further information

Merchant fraud

Businesses can be targeted by fraudsters wanting to use credit cards to get cash or buy high value items. There are a few simple ways you can ensure your merchant facilities are only used for genuine activity and to help protect your business from fraud.

Visit our Merchant risk hub for more information on Merchant fraud

Cybersecurity for businesses

Criminals use an array of online or electronic means to access, acquire or modify restricted data. Most fraud and scams these days have a cyber component to them. See Cyber Response Playbook

Visit CERT NZ for more information on protecting your business from cybercrime.

Learn how to keep your computer and devices safe

Report a scam.

Email us

If you believe you have received a suspicious email, you can forward it to us. 


Talk to us

Need further help?

Call 0800 400 600

Report to other agencies

Once you have spoken to us, you should report scams to other agencies so that they can take steps to prevent other people being targeted by them and losing money. 

Things you should know.

Payments that you authorise yourself are generally not considered fraudulent. It’s likely that you will be liable for any losses incurred and it can be difficult to recover the money once the payment has been made. Take care when making payments and ensure you take steps to protect yourself from scams.  If you believe you have been targeted by a scam, contact your bank immediately.