Scammers are borrowing the NCSC's name - and cyber policies don't all respond the same way

NZI treats social engineering as an optional extension with its own sublimit. QBE doesn't. That gap is worth checking before the next impersonation call lands

Scammers are borrowing the NCSC's name - and cyber policies don't all respond the same way

Cyber

By Mav Rodriguez

New Zealand insurance brokers have another social engineering risk to raise with clients after the National Cyber Security Centre (NCSC) warned that scammers are making phone calls while posing as representatives of the government cyber security agency.

For brokers, the more significant issue is not simply that the NCSC is being impersonated, but that fraudsters are using trusted institutions to make social engineering attempts more convincing. That creates a practical reason to review whether clients have adequate verification controls in place and whether their insurance programmes would respond if an employee were deceived.

The NCSC said on July 29 that people had received calls from individuals claiming to represent the agency. It said it does not generally initiate unsolicited contact by phone and advised recipients not to answer or return unexpected calls, or follow any instructions if they do pick up.

Social engineering risks

The warning puts a particular focus on social engineering, where fraudsters manipulate people into taking actions that can bypass technical security controls. For brokers, that raises questions about both clients' procedures for verifying unexpected requests and how their insurance programmes respond if an employee is deceived into transferring money or disclosing information.

Social-engineering protection is not necessarily treated in the same way across cyber policies, making the distinction particularly relevant when brokers review clients' cover. An NZI Cyber Ultra wording available on the insurer's website, for example, treats social-engineering fraud as an optional extension, subject to a separate sublimit and specified internal controls. QBE's current New Zealand cyber offering also lists social engineering among the risks it can cover. The extent of protection ultimately depends on the individual policy wording, limits and conditions. A practical starting point is asking what verification steps a client's own controls require before money moves or information is shared, such as requiring a callback to a known number or dual sign-off on unusual payment requests, since insurers are increasingly likely to scrutinise exactly this when a social engineering claim is made.

Phishing concerns

The NCSC alert comes as fraud and phishing remain prominent sources of reported cyber incidents in New Zealand. The agency received 1,164 incident reports in the first quarter of 2026, with phishing and credential harvesting the most common category at 437 reports. Scams and fraud accounted for a further 340 reports and approximately NZ$3.8 million of direct financial losses during the quarter. Total reported cyber losses reached NZ$5.6 million, up 76% from the previous quarter.

The coverage issue is also emerging against relatively competitive cyber insurance conditions. Aon classified New Zealand's cyber market as soft in the first quarter of 2026, with abundant capacity and broader coverage available across the country's insurance market. Marsh separately reported in February that cyber premiums had stabilised but insurers continued to expect strong cyber security controls from insureds.

For brokers, the scam therefore provides a practical reason to test social-engineering cover and client verification procedures together. Limits, exclusions and conditions can determine whether an impersonation-related loss is covered, while insurers may also scrutinise the controls clients use to authenticate unusual requests.

The NCSC advised anyone who receives an unexpected call claiming to come from the agency to end the call and submit a report through its official reporting portal. Reporters receive a reference number, which the NCSC said it will be able to provide if it subsequently makes legitimate contact.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!