Back to The Local Vocal
The Local VocalMedium
Phishing
Email
Medium risk PhishingEncountered ViaEMAIL 23 June 2026
RegionNew Zealand

A Vague Business Enquiry From the UK Is Targeting Your Inbox

A vague raw-material enquiry from a UK sender designed to draw staff into a fraudulent dialogue.

If your staff respond to this message, they risk being drawn into a business email compromise or advance-fee fraud chain. These campaigns are designed to open a dialogue, after which the threat actor will attempt to extract payment, sensitive commercial information, or banking details under the guise of a legitimate supplier relationship. The reputational and financial harm to your organisation can be substantial, particularly if procurement or accounts staff are engaged before the deception is identified.

This campaign was detected moving across multiple local organisations within a narrow window, with messages arriving in a concentrated burst over several hours. The pattern is consistent with an automated or semi-automated distribution effort, and the spread across organisations suggests a broad targeting approach rather than anything specific to your sector or size.

What makes this message deceptive is its studied vagueness. It presents as a routine commercial enquiry — no brand, no attachment, no link — making it difficult for standard filtering to flag as malicious. The sender domain passes SPF and DKIM checks, lending a surface appearance of legitimacy, yet DMARC returns no policy and composite authentication fails, indicating the domain's configuration does not meet the standards expected of a genuine business correspondent.

Notably, the complete absence of body content beyond a brief, generic introduction is a deliberate technique. By providing no specifics about the raw material, the production line, or the company itself, the sender compels the recipient to reply in order to learn more — shifting the conversation to a channel the threat actor controls. The name and UK origin claim are unverifiable and likely fabricated, and the sending domain shows no credible commercial footprint consistent with the claimed business identity.

Email authorisation
SPF
pass
DKIM
pass
DMARC
none
COMPAUTH
fail
Sender Domain Intelligence

The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.

Sender domainsivelga.com
Age1685 daysEstablished
Registered10/12/2021
Email Sample
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

Exercise caution with vague enquiries. Treat unsolicited business enquiries requesting supplier details or price lists with suspicion, especially when originating from unknown external domains.

Verify through official channels. Before engaging with a new international contact, verify their identity via an independent search of the organisation they claim to represent and attempt to contact them via an official office phone number.

Report suspicious correspondence. Report the incident to your internal security team and forward the email to CERT NZ (report@phishing.cert.govt.nz) for analysis.

Enable External Sender Alerts. Ensure your mail system is configured to provide clear visual warnings for messages originating from outside the organisation.