Bank impersonation scams reached their highest monthly level of 2026 in August, according to Netsafe – and the data lands at a moment when the gap between what banks will reimburse and what insurance policies will cover has become a practical question for brokers.
Of scam reports received by Netsafe in August where a scammer was impersonating another party, 34% involved someone posing as a bank or financial institution. Between April and July, that figure averaged 20%.
In raw terms, reports of bank impersonation rose from 21 in July to 46 in August – the highest monthly figure Netsafe has recorded this year.
Reports of scammers posing as government agencies moved in the opposite direction, dropping from an average of 37 per month between April and July to just 11 in August.
Netsafe chief online safety officer Sean Lyons said the shift looks less like a change of method and more like a change of mask. “That may indicate a change in disguise rather than a change in tactics. Scammers know that people are more likely to engage when they believe they are dealing with an organisation they know and trust – and their bank is an obvious choice,” Lyons said.
Netsafe notes its figures capture reports made to the organisation, not the full scale of scam activity in New Zealand, and that month-to-month movements should be read as indicative.
The Netsafe data sits within a significantly larger picture of financial harm. Payments NZ’s first Reported Fraud Monitor, aggregating data from 12 banks, recorded $265 million in gross fraud losses over the 12 months to November 2025. Of that total, approximately $126 million involved authorised payment scams – cases where individuals were manipulated into approving transactions themselves, according to MBIE.
That $126 million figure is the category most directly relevant to bank impersonation fraud, where a caller convinces someone to make a transfer or hand over credentials.
The Banking Ombudsman Scheme’s 2024-25 annual report recorded that while scam-related complaints fell 17% to 694 cases, the average reported loss per case rose 10% to $88,000. By November 2025, the Banking Ombudsman separately noted the average loss for cases it formally considered had risen to more than $100,000.
Banking Ombudsman Nicola Sladden warned against reading the complaints drop as progress. “Scams remain a serious concern, especially given their increasing sophistication and impact,” she said.
The compensation framework changed on November 30, 2025, when the New Zealand Banking Association’s (NZBA) updated Code of Banking Practice introduced five scam-protection commitments for member banks. Eligible customers can receive compensation for authorised payment scam losses where the applicable commitments are not met, subject to the Code’s eligibility criteria and a combined compensation cap of $500,000.
The framework does not make banks fully liable for all scam losses. NZBA has said banks cannot take responsibility for losses beyond their control, citing examples such as scams originating from fake advertisements, social-media chats, or fake search-engine results. The Code also contains specific eligibility exclusions, including payments made when buying goods or services through social-media or equivalent online marketplaces.
A phone call from someone posing as a bank – the scenario Netsafe is flagging – may or may not fall within what a bank will reimburse, depending on whether the bank met its commitments and whether the customer took reasonable care. When bank reimbursement does not apply, the question of insurance coverage follows.
That question does not have a uniform answer. According to New Zealand cybersecurity firm NSP, business email compromise and funds transfer fraud are typically excluded from standard cyber policies or subject to a much lower sublimit, with a specific social engineering or funds transfer fraud endorsement required for full coverage.
NSP identifies this as a particular gap for professional services, legal, and real estate businesses – sectors where payment diversion is a frequent attack type. The same dynamic applies to any client who handles sensitive financial instructions by phone or email.
Whether a bank impersonation loss is covered at all can come down to the specific policy wording, the applicable sublimit, and the internal controls an insurer requires the client to have had in place.
For brokers, two conversations follow from the August data. The first is about client procedures. Lyons’ advice to the public applies equally to businesses: stop, end the call, and contact the bank independently using a number from the official website – not from the incoming communication.
“If someone contacts you claiming to be from your bank, don’t feel pressured to continue the conversation just because they know some of your details or sound convincing. Hang up, delete the message, and contact your bank yourself using a trusted number. A genuine bank will never mind you taking that extra step to make sure you’re speaking to them,” Lyons said.
The second is about policy design. Reviewing whether a client’s cyber or financial lines coverage responds to a social engineering loss – and under what conditions – is a more useful exercise before a claim arrives than after.
The National Cyber Security Centre’s (NCSC) Cyber Threat Report 2025 recorded $26.9 million in direct financial losses reported to the agency in 2024-25, up from $21.6 million the year before, noting those figures are indicative only and the full impact is likely much greater.
With fraud losses running at $265 million across the banking system and the regulatory framework still developing, the question of what a policy actually covers in a bank impersonation scenario is one clients are unlikely to have thought through themselves.