A practical companion to the September 2026 Virtus Group newsletter. Use it to define verification rules, staff reporting, and first-response actions for phishing, credential theft, business email compromise (BEC), invoice fraud, account-recovery abuse, and unsafe sharing.
| Scenario | Required Action | Who Verifies | Evidence to Keep |
|---|---|---|---|
| Supplier or customer bank details change | Verify using a trusted number already on record or independently sourced; do not rely on contact details in the change request. | Finance + second approver | Verifier, method, date/time, outcome |
| Urgent or unusual payment request | Use the normal approval path and confirm outside the originating message. | Manager/director + finance | Approval record and payment reference |
| Unexpected MFA prompt | Deny it. Do not approve to make prompts stop. Report immediately. | User + IT/security owner | Time, account, device, screenshots if available |
| Password or MFA reset request | Verify identity using the established recovery process before changing credentials or factors. | IT/helpdesk + authorised owner | Verification method, operator, change performed |
| Suspicious shared file or link | Do not continue interacting with it; report for review. | User + IT/security owner | Original message, sender, URL/file details |
| Request for password, MFA code, or recovery code | Do not share it. Stop the interaction and escalate. | User + IT/security owner | Original request and escalation note |
Report early: If an email, text, phone call, login prompt, file share, payment request, or account request feels unusual, report it.
Include: sender/caller, time, what you opened or clicked, whether credentials were entered, whether MFA was approved, and any payment action taken.
Preserve: keep the original message and screenshots where safe. Do not keep clicking links to test them.
Culture: early reporting is usefulβeven when the event turns out to be harmless.
| Incident | Immediate Actions | Follow-Up | Owner |
|---|---|---|---|
| Phishing link clicked, no credentials entered | Stop interacting; report; capture the URL/message. If anything downloaded or executed, isolate the device and escalate. | Review endpoint/email telemetry as appropriate and block malicious indicators where possible. | |
| Credentials entered into suspected phishing page | From a trusted device, reset the password and revoke active sessions/tokens where supported. Report immediately. | Review sign-in activity, MFA methods, mailbox rules, forwarding, admin changes, and other affected services. | |
| Unexpected MFA prompt approved | Report immediately; revoke sessions; reset credentials as appropriate; confirm registered MFA methods. | Investigate sign-in logs and determine whether account access occurred. | |
| Suspected mailbox compromise | Contain access, revoke sessions, reset credentials, and review authentication methods. | Inspect forwarding/inbox rules, sent/deleted items, OAuth/app access, and impacted contacts; preserve evidence. | |
| Suspected invoice/payment fraud | Stop pending payment where possible and contact the bank immediately if funds may have moved. Preserve the request. | Verify the genuine supplier/customer through a trusted channel, begin incident response, and report the incident as appropriate. | |
| Suspicious password/MFA reset request | Do not complete the reset until identity is independently verified. Escalate the failed verification. | Review related account activity and warn relevant helpdesk/admin staff. | |
| Unsafe external sharing | Remove inappropriate access where safe to do so and record what was exposed. | Review sensitivity, access logs, recipients, and whether notification/escalation is needed. |
Best habit: You do not need every employee to identify every scam. You need people to verify high-risk requests, protect credentials, and report uncertainty early.
For a cyber security issue affecting a New Zealand individual or business, the National Cyber Security Centre provides an online reporting service. Where fraudulent funds may have been transferred, contact the relevant bank immediately as well as starting your internal incident response.
NCSC β Report a cyber security issue