
Why an Unsolicited Purchase Order Enquiry from Colombian Officials Warrants Suspicion
A suspicious business enquiry impersonating Colombian officials is targeting New Zealand staff with fake Purchase Order (PO) lures.
A highly targeted "Reply-Chain Hijack" campaign is currently targeting New Zealand organisations, utilizing a business enquiry regarding a missing Purchase Order (PO). Scammers are impersonating government officials from the La Guajira region of Colombia to deliver malicious attachments or links by appearing as part of a prior transaction thread. The social engineering technique relies on a short, professional-sounding request for confirmation, a tactic designed to trigger a routine response from administrative or accounts-payable staff.
There is a major technical contradiction in the lure: while the sending domain (laguajira.gov.co) is a verified government address that passes standard authentication checks, the "Reply-To" address is routed to a suspicious, privately registered domain (m-tesorer.com). Legitimate government communications never redirect replies to unverified third-party infrastructure. This mismatch is the primary indicator of account compromise or external impersonation.
The campaign typically arrives in a professionally formatted HTML style, designed to mimic a legitimate business thread. However, the context — a business PO from a regional South American government to a New Zealand organisation — is highly anomalous. Legitimate international government business is not conducted through unsolicited "Re" subject lines from individual official mailboxes without prior established context or procurement history.
Organisations are advised to treat any unsolicited business or transaction-themed emails from foreign government domains as high-suspicion, regardless of technical legitimacy. Staff awareness training should emphasise the importance of verifying the professional context of an enquiry and checking the "Reply-To" header before engaging. Suspicious emails should be reported to the internal security team for investigation and domain-level blocking.
The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.
Where a reply to this message would actually be delivered. When it differs from the visible From address, an unsuspecting reply lands with the attacker instead.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
• Verify Business Context. Independent of technical authentication, assess whether your organisation has legitimate business dealings with the La Guajira regional government.\n• Audit Sender Identity. Check the sender address (irina.garcia@laguajira.gov.co) against the claimed name (Antonio Gonzalez Flores).\n• Check the Reply-To. Verify the "Reply-To" address (m-tesorer.com) against the "From" domain.\n• Report to IT. Alert your internal security team so they can block the laguajira.gov.co domain at the organisation level.


