Auckland | Waikato | Bay of Plenty
Invoice Fraud Protection

Would your team spot a fake invoice?

It won't look fake. It will come from a supplier you know, on a thread you recognise, with the bank details changed. Invoice fraud is one of the largest sources of cybercrime losses for New Zealand businesses, and it works because there is nothing to spot.
IT strategy and support discussion around digital roadmap
Business server rack setup for SMB IT infrastructure in Auckland
Our Approach

Invoice fraud protection for NZ businesses

We close the gaps this scam relies on, so it never comes down to one person in accounts making a judgement call.

How it actually happens

  1. A mailbox is accessed, usually with a password reused on a site that was breached and an account without multi-factor authentication.
  2. Nothing happens. The attacker reads the payment threads and learns how your business writes.
  3. A quiet mailbox rule is added so certain replies never reach the real owner.
  4. An invoice goes out from the right person, on the right thread, with new bank details and a reasonable explanation.
  5. Nobody notices until the real supplier follows up on their overdue invoice, often weeks later.

What we do about it

It always starts with someone getting into a mailbox. Sometimes it's yours. Sometimes it's your supplier's, and the two need different answers.

If it's yours, that is ours to prevent and to catch. We make the mailbox hard to get into and quick to notice when somebody does, so your customers never receive anything at all.

If it's your supplier's, no technology of ours stops the email arriving, because it genuinely came from them. What protects you then is a payment process that doesn't take email at its word, and a team who recognise the pattern. We help with both.

$12.4 million

Direct financial losses reported to New Zealand's National Cyber Security Centre in the third quarter of 2025, up 118 percent on the previous quarter and driven largely by fraudulent fund transfers. The NCSC has said only a small proportion of losses are ever reported to them, so the true figure is higher.
What Our Clients Say
“We trust Elite with our businesses technology needs because they have experienced people, and products that we know we can rely on.”
Mason Elliot
IT Manager, Fairview Ford & Mazda
What's included

Six layers, so it never comes down to one person noticing

These sit inside our managed agreements rather than being quoted separately as extras.

Identity hardening

Multi-factor authentication applied everywhere rather than mostly, older sign-in methods switched off, and conditional access so an unexpected login has to work harder. A stolen password stops being enough on its own.

Managed detection and response

A compromised mailbox leaves fingerprints long before money moves. New forwarding rules, sign-ins from two countries an hour apart, a login session being used from somewhere it shouldn't be. Your Microsoft 365 accounts and your devices are watched around the clock by people, not only by software.

Human risk management

Short cybersecurity training that fits around real work, phishing simulations so the real attempt feels familiar, and monitoring for your team's credentials turning up in breaches elsewhere. Risk is scored per person, so the effort goes where it's actually needed instead of everyone sitting the same annual module.

Penetration testing

Controls drift. Someone gets an exemption, a setting changes, an account gets missed. Regular testing looks for the weak or reused passwords, exposed services and misconfigurations that give somebody a way in, so you have evidence rather than an assumption.

Protecting your name in transit

Email authentication records tell the world which servers are allowed to send as you. Configured properly they stop most lookalike emails reaching your customers at all, which protects your reputation as much as your bank balance.

Shutting it down, not just flagging it

Finding a compromise is only half the job. When an account shows the signs, access is cut immediately rather than after somebody reads an alert and decides what to do. Most businesses learn they were compromised when a customer tells them. This is how you learn it from us first.

One reliable recommendation

Make it a rule that any change to bank details is confirmed by phone, on a number you already held, never one supplied in the email asking for the change.

That one is your process rather than ours, and how you run your finance team is your call. But it is the only thing that protects you when the compromised mailbox belongs to somebody else, and it costs nothing.
The bit that gets left out

It doesn't have to be your money that goes

Most businesses picture themselves paying a fake invoice. The other direction gets far less attention and is arguably worse, because it's your mailbox that is compromised and your customers who pay the fraudster.

Your customers get the email

Sent from your real account, on your real thread, with your real invoice attached and one line changed. There is nothing for them to spot either.

You may not know for weeks

From your side the invoice simply hasn't been paid yet. The conversation usually starts when you chase it, which is the worst possible way to find out.

The damage is the relationship

Your customer is out of pocket, you are still owed, and someone has to decide who wears it. Whatever the answer, the trust takes longer to repair than the balance sheet.
This is why we look at what leaves your business as closely as what arrives.

How it works

01

Schedule an appointment

A short conversation about how payments get approved in your business today, and what happens when a supplier says their bank account has changed.
02

Evaluate your environment

We check where multi-factor authentication is actually applied, look for mailbox rules that shouldn't be there, review your email authentication records, and find the points where the process trusts email.
03

Develop a growth plan

You get a prioritised list. What is urgent, what costs nothing, what can wait, and what you already pay for but haven't switched on.

Find out where the gaps are

A short review of how your business would fare against this, and a plain list of what to fix first.

Schedule an Appointment

We have offices in Auckland, Hamilton and Tauranga.
FAQ

Need more info? We’re here to help

Most often through a password that was used somewhere else and turned up in a breach of that other site. No hacking is involved. They simply try the password on your email, and if multi-factor authentication isn't switched on, they're in. The second most common route is a convincing sign-in page that captures the password as it's typed.

You're in a much better position, but it depends on where it's applied and how. We regularly find it enabled for most staff and quietly missing for a handful, often long-serving accounts set up years ago that belong to exactly the people with payment authority. It's also worth checking whether older sign-in methods are still permitted, because those can bypass it entirely.

There is also a newer approach where an attacker sits between you and the real sign-in page, lets you approve the prompt as normal, then reuses the session that follows. Multi-factor authentication on its own does not stop that, which is why watching for sessions being used from unexpected places matters as much as having it switched on.

Ring your bank immediately, before anything else, and ask them to attempt a recall. Then change the password and sign out all sessions on the affected mailbox, check for forwarding rules the attacker may have left, and report it to the National Cyber Security Centre. Tell the supplier as well, because their mailbox may be the compromised one. Hours matter more than anything else at that point.

Sometimes, if you move quickly enough that the funds are still sitting in the receiving account. Once they've been moved on, which often happens within hours, recovery becomes unlikely. It's worth reporting regardless, because banks do freeze accounts already under investigation, but nobody should plan on the money coming back.

Check rather than assume. This is a type of loss where no system is technically broken into and the payment is authorised by your own staff, which is exactly the gap where cyber and crime policies often diverge. Cover for funds transfer fraud is frequently excluded, capped at a much lower sublimit, or only available as a specific extension. Worth a conversation with your broker either way.

Make it a rule that bank account changes are verified by phone, on a number you already had on file, never one from the email requesting the change. It costs nothing, requires no technology, and defeats the scam on its own. Everything else we do is there to catch the times someone is in a hurry.

Schedule an appointment

We have offices in