AFQY | A Few Quiet Yarns
← All newsSecurity

When the voice on the call is not your CFO

21 July 2026· AFQY News

When the voice on the call is not your CFO

The scam email with the clumsy grammar is now a museum piece. The 2026 version is a video call where the face and the voice both check out, and the only thing wrong is that the person on the screen does not exist. In one widely reported case, an employee at engineering firm Arup transferred around US$25 million after a video call with people who appeared to be senior colleagues, including the CFO.

That is the backdrop to the NCSC’s latest Cyber Threat Report here at home. In 2024/25 the agency received 5,995 incident reports, triaged 331 of them for specialist support because of their potential national significance, and recorded $26.9 million in direct financial loss, up sharply on the year before. In recent years it has been handling about one incident a day with the potential to cause harm at a national level. The report is blunt about why the pressure keeps building: cybercrime has been commercialised, criminals have more tools, and technologies such as AI are accelerating parts of the attack chain. One section heading sums up the agency’s view of AI risk in three words: amplification through automation.

The quarterly numbers show where that pressure lands. In the first quarter of 2025, phishing and credential harvesting reports rose 15 percent to 440, and of the $7.8 million lost in the quarter, around $5 million walked out the door through unauthorised money transfers and business email compromise. Separate reporting on the national picture found more than half of New Zealand’s small and medium businesses experienced at least one cyber threat during the year.

The global data says New Zealand is not an outlier. A Gartner survey of 302 cybersecurity leaders across North America, EMEA and Asia Pacific found 62 percent of organisations had experienced a deepfake attack in the previous 12 months, and 32 percent had seen prompt injection attacks on their AI applications. Research covered by CIO.com is starker still: AI-generated phishing now outperforms elite human red teams, with its edge over human attackers improving by more than 55 percent between 2023 and 2025. The lure that fools your sharpest people can now be produced at machine speed.

The UK’s NCSC, looking ahead to 2027, assesses that AI will almost certainly keep making cyber intrusion more effective and efficient, and notes the window between a vulnerability being disclosed and being exploited has already shrunk to days, with AI set to compress it further. It also warns of a growing digital divide between organisations that keep pace with AI-enabled threats and the large proportion that do not. Across the Tasman, the ASD’s latest annual report put the average cost of a cybercrime incident for a small business at A$56,600, up 14 percent.

So the boardroom conversation is changing shape. The question the NCSC’s leadership puts to directors is not about tooling, it is about readiness: if your organisation was targeted by a malicious cyber actor today, would you be ready? Its threat report now pairs case studies with questions leaders should be asking, a signal that cyber resilience is being framed as a governance duty rather than an IT line item.

The uncomfortable truth in the local data is that while deepfakes take the headlines, old weaknesses still do much of the damage. In one case last year, New Zealand Police identified 19 local organisations running a known vulnerable system; two had already been compromised before fixes were applied. For CIOs and CISOs, that is the story worth telling upstairs. AI has raised the tempo and polish of attacks, but the organisations that hold up are the ones where verification is cultural, recovery is rehearsed, and the board treats resilience as its business. The good news: that conversation is easier to start now than it has ever been. The data is doing half the talking.