A large New Zealand business recently grew suspicious of a remote IT contractor's identity. When it contacted the National Cyber Security Centre (NCSC) and New Zealand Police, investigators determined the contractor was a North Korean operative who had used identity masking technology to secure the work. The case appears in the NCSC's Cyber Threat Report 2026, and it shows how far identity deception has moved beyond the phishing email. The person behind a contract, an invoice or a video call may not be who the paperwork says.
The timing matters. Cyber Smart Week runs from 5 to 11 October under the message "Find the scam before it finds you", with a focus on how AI is changing the threat. The NCSC's leading judgement in its new report is that frontier AI will accelerate the threat environment, with advanced capabilities potentially in malicious hands by early 2027. NCSC deputy director-general Catriona Robinson has made clear that managing cyber security sits with chief executives and senior leaders. For finance leaders, that responsibility becomes most concrete at the moment money leaves the organisation.
Financially motivated attacks are rising
The NCSC handled 369 incidents of potential national significance in 2025/26. Of those, 162 showed links to criminal or financially motivated actors, an 18% increase on the previous year, and four were classified as highly significant, the same number as the previous decade combined. Pressure is also building as businesses grow: in the NCSC's SME research, 76% of businesses with 20 to 49 staff reported a cyber threat or attack in the previous six months.
Building on Cyber Smart Week
This year's campaign asks New Zealanders to look closer and question what they see, backed by webinars, a scam quick-check tool and practical guidance for businesses. The NCSC has also released guidance for businesses that use third-party providers to collect and store information. Together they're a strong foundation, and a starting point finance teams can build on.
The next layer is the supplier relationship itself. Long-standing supplier relationships can make a well-timed request to update bank details convincing. If a supplier's genuine inbox is compromised, the request can come from a real address and reference a real invoice, and your own controls can be working as designed while the risk sits in someone else's systems.
Stop assuming trust at the point of payment
The contractor case and a compromised supplier inbox share the same weakness: trust established at one point and assumed from then on. Planning for compromise, applied to payments, means no payment is trusted by default, however familiar the supplier.
In practice, bank details are confirmed against an independent source rather than the contact details in the request. Any change to a supplier's account triggers verification before the next payment run, and approvals no longer rest on a familiar voice, a video call or a senior name. Responsibility for each step sits with a named owner, so it doesn't fall between IT and finance.
Find the fraud before it reaches your payment run
Cyber Smart Week asks New Zealanders to find the scam before it finds them. For finance teams, the practical place to do that is before a payment is released. These steps are a good place to start:
- Apply the identity checks you use for new employees to contractors and new suppliers before their first payment.
- Recheck long-standing suppliers whenever their bank details change, however familiar the relationship.
- Confirm any change to payment details through a contact you already hold, never the one supplied in the request.
- Ask your third-party providers how they would tell you about a breach, using the NCSC's third-party guidance as a starting point.
- Make sure no single email, call or video meeting can approve an urgent payment on its own.
- Name who in finance calls the bank first if money goes to the wrong account, and add that step to your incident response plan.
Cyber Smart Week lasts seven days, but the NCSC's message is that responsibility for cyber risk sits with leadership. For finance leaders, that responsibility lands at the supplier record, where every identity and every bank detail change can be checked before money leaves the organisation.