5 connected screens in a cluster representing NZ phishing topics — phishing hub for NZ schools

Quick answer

This hub covers the full phishing lifecycle for NZ schools — from recognition through to incident response and reporting. Each section links to the dedicated resource, or start with the section that matches what you need right now.

  • How to recognise phishing — the decision rule for any message, any platform

  • NZ-specific phishing patterns — examples New Zealand schools actually see

  • Social engineering tactics for NZ students — phishing, smishing, vishing, and pretexting

  • When a student clicks a phishing link — immediate steps for parents and teachers

  • Reporting phishing in New Zealand — CERT NZ, Netsafe, and your school’s obligations

How to recognise phishing

Phishing messages try to make a normal action feel urgent — log in, open a file, pay a fee, share a code, or fix an account problem. In NZ schools, the same five warning signs apply whether the message arrives by email, text, or social media DM.

Use the NZ Red Flags check before acting on any unexpected message [1]:

  • Does the sender address match the service it claims to represent?

  • Does the link destination match the real domain, not just the button text?

  • Is the message asking for a password, MFA code, payment, or personal information?

  • Can you verify the request through a known website, app, phone number, teacher, or IT contact?

  • Does the message create urgency — a closing account, a missed delivery, an account hold — without giving you time to check?

If two or more of these flags appear together, treat the message as suspicious and verify it through a separate channel before acting.

Use the full recognition guide at How to Spot Phishing Emails, Scams, and Fake Messages when you need the complete decision path, including how to check OAuth prompts and what to do if you receive a message that appears to come from you.

NZ-specific phishing patterns

New Zealand schools see a recognisable set of phishing patterns that differ from generic global templates. The most common in NZ school contexts are covered in detail in Phishing Anatomy — NZ-Specific Examples, but the short version is:

  • Parcel delivery texts — “Your courier delivery is held, tap here to pay a fee.” NZ Post does not ask for payment via text message [1].

  • Bank login warnings — “Unusual sign-in activity detected, click here to verify.” NZ banks will never ask for a password or MFA code in an email or text [1].

  • School account alerts — “Your Office 365 / Google Workspace account will be suspended, update your password now.” Check the actual domain before entering credentials.

  • Shared document invitations — “You have been mentioned in a shared document, click to view.” Open the document platform directly rather than through the link.

  • IRD-style refund messages — “You are owed a tax refund, click here to claim.” IRD does not send refund links by email [1].

The pattern across all of these: they arrive when you are busy, invoke a consequence for not acting immediately, and direct you to a page that looks like the real thing but has a different domain.

Social engineering tactics used against NZ students

Phishing is one tactic within the broader category of social engineering — any approach that manipulates someone into giving up information or access. In NZ schools, the main social engineering vectors students encounter are covered in Social Engineering: What NZ Students Need to Know.

The tactics most common against NZ students in 2025–2026:

  • Phishing (email and SMS) — fake login pages, parcel fee demands, account suspension warnings [1]

  • Smishing (text message phishing) — courier, bank, and prize-won messages [1]

  • Vishing (phone call phishing) — callers claiming to be from the school, a tech company, or a government agency [1]

  • Pretexting — a believable fake scenario, such as a student receiving a message that appears to come from a classmate or teacher asking for their password

  • Baiting — fake free game credits, prize claims, or free downloads designed to capture login credentials

The consistent feature across all of these: they exploit trust, urgency, or emotion rather than technical hacking. No software can fully protect against a person being tricked into sharing their password willingly.

If a student has clicked a phishing link — with or without entering details — the steps below give parents and teachers a clear playbook. The full guide with a ready-to-use parent-letter template is at What To Do When a Student Clicks a Phishing Link.

Immediate steps (first 5 minutes):

  • Do not panic — the attacker has not necessarily captured usable information

  • If credentials were entered: change the password from a clean browser session immediately

  • Sign out of all other active sessions if the service allows it

  • Check account activity for anything unusual (new logins, changed recovery options, sent messages)

  • If the student uses the same password elsewhere, change those accounts too

Containment steps (first 24 hours):

  • Alert the school’s IT team or the person responsible for digital safety

  • If student data or personal information was entered, the school may have obligations under the Privacy Act 2020 — refer to the Privacy in Education resource

  • Report the phishing message to CERT NZ and Netsafe — your report helps protect other schools [1]

  • Monitor the affected accounts for any unusual activity over the following week

Talking to the student:

The click was predictable — phishing messages are designed to catch people when they are busy or worried. The goal is to close the incident, not to create shame. Focus on what to watch for next time rather than what went wrong this time.

Phishing hub for NZ Schools — Recognition, Response, and Reporting guide image

Reporting phishing in New Zealand

In New Zealand, there are three reporting channels that work together:

  • CERT NZ — for incidents affecting businesses, organisations, or individuals with significant impact. Report at cert.govt.nz/report [2].

  • Netsafe — for online harm including scams, harassment, and fraud affecting individuals. Report at netsafe.org.nz [1].

  • Your school’s IT team or IT provider — for incidents involving school systems, student data, or school-owned accounts.

School obligations under the Privacy Act 2020: if a phishing incident results in access to or exposure of student personal information, the school may have a notifiable privacy breach obligation to the Office of the Privacy Commissioner. The Privacy in Education resource covers what this means in practice.

Protecting the wider school community: reporting phishing incidents — even ones that did not result in a breach — helps CERT NZ and Netsafe warn other schools. A single report can trigger a broader advisory that protects dozens of other institutions.

Knowledge check

Q1A student receives a message saying their school account is locked and they must click a link to unlock it. What is the safest first move?tap to flip
Answer: Answer: Do not use the link. Go directly to the school's official portal or learning platform through a known bookmark or the school's website. Report the message to a teacher or IT support [4].
Q2A teacher discovers a student has already clicked a phishing link. What is the first thing they should do?tap to flip
Answer: Answer: Stay calm. Disconnect the device from the network if possible, then notify the school's IT support or designated cyber incident contact immediately. Do not try to undo the click yourself [4].
Q3A school receives a phishing email impersonating the principal. Where is the best place to report it in New Zealand?tap to flip
Answer: Answer: Report it to CERT NZ at cert.govt.nz and forward the email to Netsafe's phishing report address (0800 237 869). If personal information was shared, also notify the Office of the Privacy Commissioner [4][5].

Sources and references

[1] Netsafe New Zealand. (2025). Phishing. https://netsafe.org.nz/scams/phishing

[2] CERT NZ. (2025). Report a cyber security incident. https://www.cert.govt.nz/individuals/guides/top-11-cyber-security-tips/

[3] Google. (2025). Avoid and report phishing emails. https://support.google.com/mail/answer/8253

[4] New Zealand. Office of the Privacy Commissioner. (2025). Privacy tools for agencies. https://www.privacy.org.nz/responsibilities/privacy-tools-for-agencies/

What to do next