NZ small businesses warned: info-stealing malware has increased, putting logins, MFA and bank accounts at risk

Laura Bennett, Security Manager, NZFSG urges small business owners to act now as attackers use stolen browser data to bypass multi-factor authentication

NZ Financial Services Group (NZFSG) is warning its adviser network and the wider industry, as small businesses are being targeted by a rise of "info-stealing" malware - malicious software designed to harvest login details from a victim's browser and sell them on to cyber criminals. New Zealand's National Cyber Security Centre (NCSC) has observed an increase this quarter in reports from New Zealanders affected by malware scams, where criminals use deceptive tactics to convince victims to install malicious software that steals personal and sensitive information Malware incidents reported to NCSC rose 50% this quarter.

What this malware does

Info-stealers capture what's saved in your web browser - passwords, autofill details, saved credit cards, cryptocurrency wallets, and active login sessions for platforms like Microsoft 365, Google Workspace and other business tools. Because it can capture an already-logged-in session, it lets attackers bypass multi-factor authentication (MFA) entirely - no need to guess a password or intercept a one-time code. Small businesses in financial services sectors are particular targets, especially those relying on cloud (SaaS) and single sign-on logins.

How it gets in: fake "verify you're human" pop-ups

The NCSC has highlighted the growing creativity of these scams, which range from fraudulent Facebook groups offering "free" dance classes and fake job ads that direct users to WhatsApp before sending malicious app links, to impersonators posing as Microsoft or Spark tech support, and "friends" on Discord sharing links to game mods. Despite their varied approaches, they all rely on the same trick: persuading targets to click or install something before taking a moment to think it through.

Additionally, the NCSC has alerted the public to a technique known as ClickFix, which is actively spreading across everyday, compromised websites that businesses and staff regularly visit and trust. Visitors are presented with a fake CAPTCHA or "Verify You Are Human" pop-up that instructs them to run a brief command to resolve a non-existent error. Executing this command can silently install info-stealing malware on the device.

The NCSC is also warning of a rise in "quishing" (QR code phishing). In these schemes, tampered or swapped QR codes on posters, parking meters, or menus trick users into entering personal information or downloading malicious software. To stay safe, treat QR codes with the same caution as unfamiliar web links - always verify the destination URL before entering details or initiating a download.

Why this matters for insurance, too

Insurance industry reporting on the NCSC alert notes that standard cyber insurance policies often exclude or limit the downstream losses these credential-theft attacks cause - such as business email compromise and fraudulent funds transfers - unless a specific social-engineering or funds-transfer-fraud endorsement is in place. A business can do everything "right" technically, and still be caught out - both by the attack and by a coverage gap they didn't know existed.

Simple steps every small business should take now

  1. Remove and stop storing passwords in your browser. Browser-saved passwords are what today's leading info-stealers are built to steal. Move to a dedicated password manager instead - it encrypts your credentials and isn't a direct target the way browser storage is.

  2. Pause before you "click to fix." No legitimate website ever asks you to copy and run a command to pass a CAPTCHA. If a pop-up on any website asks you to do this, close the tab - don't click "fix".

  3. Run reputable antivirus/anti-malware software, and run it regularly. Set it to auto scan on a schedule (not just on-demand) so infections and credential exposure are caught early, rather than discovered after an attacker has already used stolen logins.

  4. Check your cyber insurance wording. Ask whether your policy responds to credential theft and the fraud that follows it - not only the initial breach.

  5. If you suspect a potential breach, contact a dedicated IT specialist immediately. Prompt action helps limit potential damage, secure your accounts, assess the extent of the compromise, and guide your response.

How NZFSG helps: Cyber education & training

At NZFSG, keeping our advisers network safe is central to protecting the clients they serve. We are dedicated to building a cyber-aware community by delivering proactive, practical education and continuous guidance. Through our regular webinars, cyber resilience assessments, and targeted training programmes, we empower advisers with the practical tools and actionable steps needed to protect themselves and their clients.

Next
Next

Think beyond the transaction