Short answer: Treat unexpected authority, supplier, bank, payment, crypto, or client-verification requests as workflow events. Staff should know how to pause, verify through an independent channel, record the request, and escalate before acting.
What this helps you check
Use this as a practical technology and process review, not as legal, financial, or regulatory advice.
- Whether staff have a clear callback process for unexpected calls and emails
- How Microsoft 365, Teams, and mailbox controls reduce impersonation risk
- What happens if someone is asked to share credentials, seed phrases, identity documents, payment details, client files, or device access
On 21 July 2026, New Zealand Police warned that scammers were impersonating Police and cryptocurrency company representatives to target people with cryptocurrency wallets and accounts. Police said victims had suffered millions of dollars in losses over recent weeks, and warned that scammers can spoof legitimate Police phone numbers and email addresses.
The National Cyber Security Centre published a related alert on 17 July 2026. It said criminals were impersonating New Zealand Police, spoofing the official Police National Headquarters phone number, and directing victims towards malicious websites where they were asked to provide cryptocurrency wallet details and seed phrases.
On 29 July 2026, NCSC also listed a current alert about scammers impersonating the NCSC. The useful lesson for firms is broader than any one agency name: a familiar logo, caller ID, email display name, or urgent security language should not replace an independent verification workflow.
For legal, financial, accounting, and advisory firms, this is not only a cryptocurrency story. It is a useful prompt to check the wider verification habits that sit around sensitive client work, payments, onboarding, remote support, identity checks, and access to confidential systems.
The current NZ signal
Police and NCSC both point to the same practical pattern: the scam starts with trust. A caller sounds authoritative, claims there is an urgent issue, and asks the target to move quickly through a channel the scammer controls.
That pattern is familiar in professional services technology risk. It can appear as a fake client, fake supplier, fake bank, fake regulator, fake executive, fake IT support request, or fake platform login. The control is not asking staff to be perfect. The control is giving them a clear workflow when something feels unusual.
1. Make independent callback normal
Caller ID, email display names, and message threads are not enough. If a request is unexpected or sensitive, staff should pause and contact the organisation or person through a trusted channel already known to the firm.
For a client, that might mean a known number from the client record. For a bank, supplier, government agency, or technology provider, it should be the official number or portal already held in the firm's records, not the number supplied in the suspicious message.
2. Decide which requests must be escalated
Not every odd request needs a partner-level incident meeting. But some requests should always be escalated before action is taken.
Set clear triggers for payment detail changes, requests for identity documents, requests for client files, urgent transfers, remote-access software, password resets, MFA changes, new external sharing links, crypto wallet details, seed phrases, or any request to bypass a normal approval step.
3. Check Microsoft 365 settings that reduce the blast radius
Many impersonation attempts arrive through email, Teams, calendar invitations, shared files, or supplier accounts. Microsoft 365 controls will not remove every scam, but they can reduce how far one mistake spreads.
Review MFA coverage, legacy authentication, mailbox forwarding rules, suspicious inbox rules, external sender labelling, admin roles, conditional access, guest access, sharing links, and audit log availability. These controls matter because impersonation often becomes more damaging when an attacker also has access to a mailbox or file store.
4. Keep device access requests tightly controlled
Scammers often ask people to install remote-access tools, change device settings, or enter details into a fake website. In a professional services firm, that can put client files, passwords, browser sessions, accounting systems, and email accounts at risk.
Staff should know which remote-support tools are approved, who is allowed to request remote access, and what the user should see before a session starts. If a caller pressures a staff member to install software or share a screen, the default response should be to stop and escalate.
5. Protect payment and client-verification workflows
Professional services firms often handle payment instructions, trust-sensitive conversations, identity information, settlement steps, invoices, onboarding forms, and client matter details. Scammers target these workflows because they carry authority and urgency.
Use dual approval for payment changes, keep known bank-account details in controlled systems, record verification steps, and separate client identity collection from informal email threads where possible. The aim is to make the safe path easier than an improvised workaround.
6. Make first-hour response practical
If a staff member shares information, installs software, clicks a fake link, or grants access, the firm needs a first-hour response that is calm and specific.
Useful first steps usually include preserving the message or call details, disconnecting a potentially affected device, changing passwords through a trusted device, checking mailbox rules and recent sign-ins, reviewing file-sharing changes, contacting the relevant bank or platform if payments are involved, and reporting the incident through the appropriate official channel.
What should firm leaders ask this week?
Use these questions to start a focused conversation with your internal team, IT provider, and practice-management leaders:
- Which requests must staff independently verify before acting?
- Where are trusted callback numbers and supplier contacts recorded?
- Do payment changes, identity requests, and client-file requests have a second approval step?
- Are staff clear that caller ID, email display names, and supplied links are not proof?
- Are Microsoft 365 mailbox rules, sign-ins, external sharing, and admin roles reviewed regularly?
- Which remote-support tools are approved, and how do staff verify a legitimate support session?
- What is the first-hour response if someone shares credentials, grants access, or follows a suspicious instruction?
If the answers are uneven, start with one page of rules and one short staff briefing. A good verification workflow is simple, repeatable, and easy to follow when someone is under pressure.
Common questions
Is this article legal, financial, regulatory, privacy, or compliance advice?
No. It is general technology-risk information for professional services firms. Firms should take appropriate professional advice for their own legal, financial, regulatory, privacy, or compliance obligations.
Why is caller ID not enough?
NZ Police warn that scammers can spoof legitimate Police phone numbers and email addresses. A safer workflow uses independent callback details from trusted records, not the details supplied in the unexpected message.
Does this only matter to firms handling cryptocurrency?
No. The same pattern can apply to payment changes, supplier requests, client identity documents, remote-support sessions, fake login pages, and urgent file-sharing requests.
Source note
This article is based on official and verifiable sources: NCSC, Scammers impersonating the NCSC, published 29 July 2026; New Zealand Police, Police warn of scammers impersonating NZ Police targeting cryptocurrency wallet holders, published 21 July 2026; NCSC, Scammers impersonating police to target victims for cryptocurrency theft, published 17 July 2026; and Financial Markets Authority, fake news stories and deepfake videos warning, first published 6 August 2024 and updated 22 May 2026. Sources checked on 30 July 2026.
Compliance note: This article is general information only. It is technology-risk and cybersecurity governance guidance, not legal advice, not financial advice, not regulatory advice, not privacy advice, not product assurance, and not compliance advice. Firms should take appropriate professional advice for their own obligations and circumstances.
