An iphone with a scammy message that reads 'Woops your bills are due now. Pay at notascam.co.nz now' sits on top of a colourful, digitally chaotic background.

PartnersMay 20, 2024

Scams are surging – this team blocked 1.3 million in a month

An iphone with a scammy message that reads 'Woops your bills are due now. Pay at notascam.co.nz now' sits on top of a colourful, digitally chaotic background.

After falling victim to a scam over the phone, Russell Brown spent the day with One NZ’s cyber defence and fraud prevention teams to see the work they do to stop millions of scam attempts every year.

The only windows in the Cyber Defence Centre at One NZ’s Auckland headquarters are windows on the internet. An array of large screens bearing the names of various security vendors and their products – Check Point, Darktrace, Mandiant – show some of the bad things happening on the internet right now.

More specifically, they’re highlighting bad things that could be a threat to One NZ and its customers. There are a lot of those. One screen tracks suspicious email traffic and shows a 49% increase in emails containing phishing links in the past month – and this isn’t even the worst month.

“In December, we blocked 1.31 million scam attempts,” says Cyber Defence Centre Team Leader Ash Das, explaining the risk.

“Let’s say you receive a phishing SMS that contains a suspicious link and says, ‘Hey, you have a payment overdue, log into your bank and make the payment’. Somebody clicks on the link, enters their credentials or their credit card information and it’s all stolen. So we have a dedicated team who can look at the email pattern, and who can pick up the suspicious text messages.”

What happens next is relatively new. Last July, One NZ was the first internet service provider (ISP) to  partner with the National Cyber Security Centre’s Malware-Free Networks service, a “threat intelligence” feed that reports suspicious URLs in scam emails and texts so that partners can block them – meaning that if you do click on a malicious link in a text, it won’t load. This cooperative approach, where government agencies, banks, security companies and ISPs like One NZ, share information in real time, is rapidly becoming the face of computer security in New Zealand.

“There are lots of threat feeds out there globally and most of the large security vendors will have their own,” says David Garrett, head of managed services at One NZ’s 60%-owned security partner DEFEND. “This one is new and New Zealand-specific. We’re seeing a lot more of the consumer-grade type phishing –  the NZ Post and banking scams – and when we do see it, Ash and his team are able to feed that back up to the NCSC, where they manually curate the feed to make sure that what they’re putting in is definitely malicious. So it’s New Zealand-specific intelligence and there is a threshold.”

“We’ve never had this much visibility before,” confirms Laura Ross, One NZ’s Chief Security Architecture Risk Officer. “We’re seeing the number of possible attacks or malicious activities out there. Now we know the enormity of the issue that we’re facing.”

It’s far from the only monitoring and blocking One NZ does every day. The scam texts, emails and calls that get through to you are a tiny fraction of the overall number of attempts made. But they do get through and it’s worth making a habit of thinking about security. Even if, like me, you think you’re a fairly sophisticated user.

They got me when I was vulnerable. I’d come back in bits from a particularly difficult visit to the hospital where my mother was dying. A text message arrived warning of an attempted login to my banking app, with an 0800 number to call immediately. On a better day, I’d have immediately noticed the first red flag. The text, I realised later, came from an ordinary 021 mobile number and not a shortcode – the three, four or five digit numbers assigned to banks, telcos and other large users.

“Shortcodes can’t be spoofed, or impersonated,” says Jack Tye, One NZ’s Risk and Compliance Manager. “So if you get a message from a shortcode, you can be really confident that that is from a dedicated provider. We won’t send messages from 021 numbers out to our customers with regards to marketing or general contact.”

When I dialled the number, stressed and alarmed, I got through to a man with a very smooth, soothing manner. (That was another red flag, by the way: I got straight through without the usual hoopla of identifying myself, answering challenge questions or entering a PIN.) I gave out information I shouldn’t have and even briefly allowed remote access to my computer for a “malware scan”. Yes, these are things I would normally regard as very dumb, but it wasn’t a normal day and these attacks are as much about psychology as technology. Crucially, it all happened very quickly.

“Scammers are usually really quick and good,” says Tye. “These are professionals and they do this for their job. They really want you to hurry. So just taking a second, it’s not rude. If the salesperson or whoever is calling you is genuine, they won’t mind you taking a little bit of time to think about it. Don’t feel bad about taking your time.”

In general, he says, be vigilant about giving out information, especially if it’s someone calling you.

“If you’re not expecting a call, if you’re not expecting any contact at all, don’t give out any personal information. Only do so if you know you’ve requested a callback from us, or if you’re expecting a call from us. I know it’s really difficult, but trying to be vigilant is key.”

It doesn’t help that some large organisations which should know better – including my bank two days after I was scammed – still do call and ask for identifying information when you answer.

“Personally,” says Tye, “despite it taking up my own time when my insurer or my bank calls me to verify or validate something, I politely explain that I’m going to call them back on their main number. I am hypervigilant, so I will do that even when I’m expecting the call. I’ll call them back and we’ll go through their process, get through to the right person and I know that I’m talking to the right people and give them my information that way.”

Similarly, if I had looked up my bank’s real helpdesk number and called that rather than dialling the one in the scam text, I wouldn’t have had the worst day of my life.

There are other things you can do, including using multi-factor authentication to login wherever it’s available. And get into the habit of scrutinising where your messages actually come from.

“The display name on an email might say One NZ but when you actually look at the return address, the email address that it’s come from, and it’s a Gmail address or something, that’s generally the giveaway,” says Garrett. “Same with any URL that’s made available for you to click on, look at the end of it. Is it One.NZ – or one-hyphen-nz.io or .com, or something else? I try and drill it into my parents that those are the key things to be looking for when you get those sorts of messages. And, again, as Jack said, if you’re not expecting it, then certainly give it a second look, go direct to your bank’s website, log in that way.”

One NZ and other organisations have had enough success in the past year fending off scattershot scam attempts that the criminal organisations behind them have begun to ramp up the number of more targeted attacks.

“This is what happens with the ‘hi mum’ scam,” says Tye. “Hi mum I’ve got a new mobile number overseas, I need to get access to my bank and I need $500, can you send it to me? It’s really easy to send out those messages and very hard not to respond when you think your son or daughter is in peril. Even when it’s family members, make sure you speak to them on the phone if you’re going to give them any information, especially any money.”

Another thing you can do is be part of the solution yourself. If you get a suspicious email or text, there’s a form for reporting it on the One NZ website.

“If you’ve received a message, say from a scam sender that’s on our network, we can take a look at that. And if it’s found to be a scam, we’ll block that sender. Reporting does really help.”

These consumer-level scams are far from the only threat the One NZ team has to detect and manage. Distributed Denial of Service (DDOS) attacks are still with us, they are often more sustained than in the past, and depending on where they’re targeted they can interrupt network function for thousands of small users, or – as was the case for the NZ Stock Exchange in 2020 – particularly large ones. There has been a rise in so-called supply chain attacks, where an apparent email from a vendor might ask a customer to pay into a different bank account.

“So the customer goes and pays money into the different bank account and the vendor says hey where’s the $100,000, you just paid us, it’s gone somewhere else,” says Tye.

Messages and emails may also contain attachments or links that place malware on user devices. That malware might in turn be controlled by DNS tunnelling, a technique that co-opts the domain name system, the internet’s internal address book, to send commands. The unusual pattern of DNS use that involves is yet another thing the Cyber Defence Centre at One NZ monitors for.

That’s a pretty sophisticated kind of attack – but a key factor in the growth of this kind of crime is that the necessary technical elements are increasingly available as a service to criminal actors who previously wouldn’t have possessed the expertise themselves.

In case you’re wondering, the worst didn’t happen for me – I realised quite quickly what had happened, after trying to call the malicious 0800 number again. But the wait for the callback from the bank’s fraud desk, thinking I’d potentially lost not just our money but my dying mother’s savings? I wouldn’t recommend that to anyone. Nor the hours afterwards of changing and re-changing passwords, running repeated malware scans on my devices, looking in every corner where a keylogger might have been left and reinstalling operating systems just in case. Or the fear and shame that lingered for months.

So take a breath, and be vigilant. Be most vigilant when you’re at your worst, because that’s when you’re most vulnerable. Maybe it’ll never happen. But you really don’t want it to happen, ever.

Each time a team like the One NZ cyber defence team stops a scam from getting through the network, a person is potentially saved from an incident like the one I went through – and those numbers add up. For those scams that slip through the cracks? Remember to be vigilant, check for warning signs and take a moment to think before you give out your personal information.

Keep going!
Several images of New Zealanders in their garages.
Garages around the country (Photos: Nancy Zhou and Ralph Brown)

PartnersMay 14, 2024

Behind the roller door: How people are using their garages for much more than storage

Several images of New Zealanders in their garages.
Garages around the country (Photos: Nancy Zhou and Ralph Brown)

Research from AA Insurance reveals more and more people are taking pride in their garage. Meet three New Zealanders using their space in creative ways.

If you think of a garage, you might picture a dark room with a parked car. There might be some tools on the wall, or boxes of miscellaneous homewares that were never unpacked. You’re probably not picturing a space you want to spend a lot of time in. 

Or maybe you are? Because new national research* commissioned by AA Insurance has revealed that more and more people are taking pride in their garage, using the traditionally dingy space for a myriad of far more interesting – and creative – activities. 

Shaun Rees, AA Insurance chief product and marketing officer, says that as a metaphorical representation of the everyday New Zealand home, the garage often reflects different life stages, uniqueness and passions. “We know that there is a lot of living done in the garage, and it’s a truly versatile space that can be anything you want it to be. We wanted to get in behind the garage door, and find out how Kiwis were really using them.” This study was the first of its kind in New Zealand to look into how garages are actually being used. 

It led to some interesting – and surprising – findings. “We knew there would be a lot of functional use, but were surprised to find that almost half – 46% – of people surveyed said they had an emotional connection with their garage as well. They saw it as a place to relax and unwind, but also a place of creativity,” Rees explains. 

Craig Herron fills a bottle up with home brewed beer in his garage.
One Christchurch garage is also an award winning home brewery and still has room for cars (Photo: Nancy Zhou)

The research also revealed 30% use their garages as a workshop, while 20% use it as a space to socialise or entertain. “It was good to see that traditional Kiwi garage parties are still popular,” laughs Rees. “Through our research we also found that Kiwis who are lucky enough to have a garage, really take pride in using a space well and not wasting it”, states Rees. “For some people, the busier, messier or more disorganised their garage was – the prouder they were.”

But how else could you be making the most of your garage? Three people who use their garage in different and interesting ways opened up their roller doors and let The Spinoff in for a visit.

Isaac Grigor (‘Woodworker’, Auckland) 

Isaac Grigor was described to me as a “woodworker”, but that’s not how you’d ever hear him refer to himself. “I think woodworkers would be insulted if I was to describe myself as a woodworker,” he laughs. 

Having visited his East Auckland home, I doubt that’s true. But there’s certainly a lot more going on inside the mechanical engineer’s immense four-car garage than just woodwork. It’s a place, says Grigor, to do “anything and everything”, most of it embodying the classic New Zealand mindset of “I reckon I can figure this out”.

Isaac Grigor outside his four car garage poses with a red car parked just inside.
Isaac Grigor fits several hobbies and several cars in the garage (Photo: Ralph Brown)

“Whenever there is something to be done around the house or for friends, it’s done in here,” he says. “My job is often heavily analytical and I don’t have creative outlets at work. I like to have those creative outlets at home.”

The garage still has all the “traditional shit”, says Grigor, pointing out some stashed camping gear, power tools and a cupboard filled with family Christmas decorations. “You’ve got to have the cupboard where your family’s Christmas decorations that you keep getting given every year can go,” he laughs.

Isaac Grigor stands at a work station in his garage making a wooden chopping board.
Grigor at his chopping board making station (Photo: Ralph Brown)

Among the things in the garage right now: a trio of cars (not working), a motorbike (working), homebrewed beer and equipment for making soap, resin art, and wooden chopping boards – often gifted to friends and family. “I make all my own soap, not for any reason other than it’s quite fun,” he says. Most of Grigor’s resin art is done on old chopping boards from op shops which make great gifts. Next on his to-do list: “I’d love to get a potters’ wheel.”

He’s moving out in a couple of months, and everything will have to go. But until the reality of clearing everything out kicks in, Grigor’s proud that his garage has been used to the fullest, rather than just filled with stuff. “The New Zealand garage is almost like a tradition. If there’s anything to do with a number eight mentality in New Zealand it usually has to do with a shed… but garages are the urban version of a shed,” he says. 

Craig Herron (Home brewer, Christchurch)

I pictured a plastic white tub that wouldn’t have looked out of place in a student flat, but in reality, Craig Herron’s Christchurch garage is decked out with an incredibly impressive micro-brewery.

Driving into the double garage doors, you’re greeted by a trio of large 70 litre brewers, along with a fermentation area and a fridge. It is, says Herron, just a smaller version of what any commercial brewery would have. 

Craig Herron sits on a stool in his garage surrounded by home brew equipment.
Craig Herron in his garage/home brewery (Photo: Nancy Zhou)

“It’s a relatively new house, we built it six years ago, and I got into brewing at the same stage so I planned an area for the brewery with all the bits and pieces that need to go with that,” he tells me. It’s become something between a  meeting place, a home brewery and, occasionally, somewhere “the car gets parked when it needs to be”.  

A panel beater by trade, Herron now works a desk job and says he was looking for a creative hands-on outlet. “I’ve always enjoyed beer, as most Kiwi blokes do, and I came across a couple of YouTube channels and started doing a bit of research,” he says. His hobby has since seen him pick up awards, including the best IPA in the country at a nationwide homebrewing competition last year. He also scored a gold for his Hazy IPA – “the one that gets the guys around for a beer” – and a bronze for a pilsner. 

A blue show ribbon that Craig Herron won in a home brewing competition.
One of Herron’s home brewing awards (Photo: Nancy Zhou)

The garage still manages to fit his car (somehow), but two walls are fully dedicated to his craft. While he’s considered taking his love of brewing professional, Herron says it’s already a lot of work. “It takes about five hours to brew a beer. If you talk to most brewers, they’d say it’s about 80% cleaning and 20% brewing,” he explains. 

It might be a lot of work, but it certainly comes with its benefits (and his mates certainly aren’t complaining).

Whitney Barnes (Seamstress, Auckland)

If Whitney Barnes was stranded on a desert island, you can bet on the one item she’d choose to bring: her sewing machine. “I think if I redid my life, I probably would have just… gone and worked as a machinist somewhere. I love it so much, it’s kind of relaxing, like how some people might come home and read a book, I like to come home and sit in my garage at the sewing machine.”

Whitney Barnes sits in the centre of her garage surrounded by sewing machinery and fabrics.
Whitney Barnes in her garage (Photo: Ralph Brown)

It was while studying textiles in high school that Barnes discovered her love of sewing, first making herself a dress she used to wear “all the time”. She now works in the fashion industry, but says everything she does in her Auckland garage is a hobby. “I don’t do anything here that makes me money. If I want a new piece of clothing, I would never go and look to buy it, I would look to make it,” Barnes says. 

“After I moved out [of home], I brought everything with me. One day I’d love to buy my own house, and a garage is my non-negotiable must-have.” She gestures around at the equipment, patterns and fabrics. “I couldn’t not have ‘this’ – and where else to put it but a garage?”

Right now, she’s making a shirt for a friend and says she makes practically all of her own clothes as well. “I think pants are the easiest, shirts are sort of a step up,” she says. “I try to be sustainable about it, I shouldn’t really just sew things because I can – I always think ‘do I really need that shirt’, ‘should I be buying this fabric?’”

Whitney Barnes sits at her sewing machine making clothes in her garage.
Barnes working away in the garage (Photo: Ralph Brown)

Last year’s floods threatened to damage some of Barnes’ most prized possessions, meaning everything is now raised above the ground and she’s invested in contents insurance (“mostly because of stuff in the garage”). It’s not just the sewing equipment, there’s also an old upright piano that was in Barnes’ family home as a child. “As soon as we moved into this house my mum was like, ‘you’ve got a garage, you’re taking the piano’.” From sewing gear to family heirloom pianolas, the contents of humble Kiwi garages know no bounds. 

Along with her sewing machine, it’s her cutting table that Barnes is most attached to. “I got this off Trade Me maybe 10 or 12 years ago for about 60 bucks and I look at it now and I’m like, wow, that’s a really decent table that would cost me more than 60 bucks to rebuild – I don’t wanna lose that.”

Whitney Barnes works at her cutting table to cut out bits of fabric in her garage.
The beloved cutting table (Photo: Ralph Brown)

Barnes says she feels lucky to have a space like this, one that she can “leave in a mess” if she wants and not have to worry about. “I like that it’s away from the house so I can separate myself and be like ‘bye, I’m going to the garage’,” she says. While there are many benefits to parking your car in the garage, Barnes is quite happy to let hers “chill in the driveway.”

*AA Insurance research conducted by Kantar. A nationally representative sample of over 1000 New Zealanders (aged 18+) completed an online survey in February 2024 (margin of error 3.1%)