New Zealand’s National Cyber Security Centre (NCSC) issued an alert on September 2, 2026, warning website owners about a social engineering technique called ClickFix. For insurance brokers, the advisory is more than an IT bulletin – it is a concrete, government-backed prompt to test whether their SME clients’ cyber policies actually respond to the type of loss ClickFix is designed to produce.
ClickFix presents visitors to compromised websites with fake CAPTCHA or Cloudflare verification pages. Users who follow the prompts unknowingly execute malicious commands on their own devices, installing infostealers or other malware. The NCSC noted that WordPress-based sites are the primary delivery vehicle – relevant context given that WordPress powers an estimated 43.4% of all websites globally as of 2025, meaning a significant share of SME clients are running infrastructure that ClickFix campaigns actively target.
The technique’s commercial significance lies in what it bypasses. The Verizon 2025 Data Breach Investigations Report found the human element was a contributing factor in approximately 60% of breaches. ClickFix is a direct application of that dynamic: a client’s systems can be fully patched, their software current, and their controls documented – and the attack still succeeds because it depends on a user following an on-screen instruction rather than exploiting a technical vulnerability.
The downstream consequence of a successful ClickFix infection – credential theft via infostealer malware – is already a documented problem in New Zealand. In December 2025, the NCSC contacted around 26,000 email addresses after identifying potential Lumma Stealer infections. The malware typically affects devices running Microsoft Windows and is designed to steal sensitive information, including email addresses and passwords, potentially for fraud or identity theft. The NCSC described the outreach as the first time it had conducted such a large-scale public campaign. “There has been a real commercialisation of the cybercrime industry, meaning that malware like this can be purchased by anyone, anywhere in the world,” NCSC chief operating officer Michael Jagusch said at the time, as reported by RNZ.
The NCSC’s Cyber Threat Report 2025 recorded $26.9 million in direct financial losses reported to the agency in 2024-25, up from $21.6 million the previous year. In the first quarter of 2026, the NCSC responded to 1,164 incident reports, with phishing and credential harvesting the most common category at 437 incidents. Direct financial losses in Q1 2026 reached $5.6 million – a 76% increase from the $3.2 million recorded in the previous quarter.
This is where the NCSC alert becomes a broker conversation. Business email compromise and funds transfer fraud – the typical downstream consequence of stolen credentials – are frequently excluded from standard cyber policies or subject to a much lower sublimit, with a specific social engineering or funds transfer fraud endorsement required for full coverage, according to New Zealand cyber security firm NSP. That gap is not uniform across the market, but the differences matter in practice. NZI’s Cyber Ultra wording treats social engineering fraud as an optional extension, subject to a separate sublimit and specified internal controls. QBE’s New Zealand cyber offering lists social engineering among the risks it can cover, though the extent of protection depends on the individual policy wording, limits, and conditions.
A practical starting point is asking what verification steps a client’s own controls require before money moves or information is shared – such as a callback to a known number or dual sign-off on unusual payment requests – since insurers are increasingly likely to scrutinise exactly those controls when a social engineering claim is made. New Zealand insurers reported that the highest frequency of claims in 2025 was due to human error, mainly in the form of business email compromise – including social engineering losses in which an employee transfers money to a cybercriminal posing as a supplier, customer, or executive, according to Adelphi Insurance Brokers’ 2026 cyber market review. Geordie Stewart, CISO at NSP, addressing an Insurance Brokers Association of New Zealand (IBANZ) webinar on cyber insurance in 2026, identified what makes these claims fail: “Having a control isn’t the same as having an effective control. That’s the most common reason cyber claims fail.”
New Zealand’s cyber insurance market was classified as soft by Aon in Q1 2026, with abundant capacity and broader coverage available to buyers. The conditions give brokers an opportunity to revisit cyber protection with SME clients as the threat environment evolves, particularly where policies need to address the boundary between cyber incidents, credential theft, and social engineering losses.
For brokers working to close that gap, confidence in the cyber conversation remains a barrier. Fraser Walker, country head for Emergence Insurance in New Zealand, noted from his conversations across broking firms that the challenge is not product complexity but broker readiness. “Most brokerages and brokers within will admit to us very quickly, we’re not confident talking about cyber, we’re not confident having the conversation with our clients, our customers,” Walker told Insurance Business New Zealand.
The NCSC alert changes the starting point of that conversation. A government-issued warning, tied to infrastructure many SME clients are already running, producing the type of loss that existing policies may not fully cover, hands brokers something concrete to open with – at a moment when lower premiums and broader available coverage remove the two most common client objections.
The alert outlined key indicators of website compromise: fake Cloudflare “Verify You Are Human” pages, fake CAPTCHA or browser update prompts, and JavaScript that copies PowerShell or shell commands to a visitor’s clipboard. Malicious content is deliberately hidden from automated scanners, so the NCSC recommended testing from normal and incognito browser sessions, different IP addresses, and both mobile and desktop devices.
For affected site owners, removing the visible prompt is not sufficient. The NCSC was direct: owners must identify the original vector of compromise and eliminate any persistence mechanisms that could reinfect the site. “Remediating an infected website requires some technical knowledge. If you do not feel comfortable taking these actions yourself, we recommend you immediately take the site offline, reset your WordPress credentials, and then contact a local IT service provider to assist you,” the NCSC stated. The NCSC has published a dedicated ClickFix mitigation document and encouraged organisations requiring further support to submit an incident report through its website.