Back to The Local Vocal
The Local VocalMedium
Phishing
Email
Medium risk PhishingEncountered ViaEMAIL 28 July 2026
RegionNew Zealand

Identifying High-Value Investment Scams in Your Inbox

Threat actors are targeting NZ staff with fraudulent $300M investment opportunities using a "politically exposed principal" lure to harvest data.

A persistent investment-themed phishing campaign has been identified targeting New Zealand organisations, utilizing a high-value lure from a sender claiming to represent a "politically exposed" principal. The email, appearing to originate from an individual named Mr. Kamarul Kasim, offers a fraudulent partnership opportunity involving the management of $300 Million USD in assets. The social engineering strategy relies on a premise of extreme confidentiality and the need for a "proxy partner" to manage wealth without technical traces, a tactic designed to bypass standard corporate procurement and financial oversight protocols.

The lure is framed to exploit the desire for significant capital injection and professional prestige. By listing a wide array of sectors — including healthcare, real estate, and commodity trading — the threat actors maximize the probability that the message will resonate with recipients across diverse New Zealand industries. The request for a "profit-oriented" proposal from the recipient is a deliberate manipulation intended to shift the burden of proof onto the target, encouraging them to divulge sensitive organisational or financial data to prove their "capacity" to handle the transaction.

Technical analysis reveals that the campaign utilizes the domain ashtique.com, a sender address with no legitimate association with global financial or investment bodies. While the domain may pass basic technical authentication checks like SPF, the complete lack of verifiable corporate branding or professional digital footprint is a critical indicator of malicious intent. This "low-fidelity" delivery method is characteristic of long-tail financial scams where the objective is to initiate a one-on-one dialogue that eventually leads to advanced fee fraud or business email compromise.

Organisations are advised to maintain a clinical skepticism toward unsolicited financial solicitations, particularly those involving multi-million dollar figures and "politically exposed" narratives. Staff should be instructed that legitimate international investment leads are never conducted through cold, generic emails from unaffiliated domains. All high-value financial leads should be verified through established institutional channels and reported to the internal security team for investigation and domain-level blocking.

Email authorisation
SPF
pass
DKIM
none
DMARC
none
COMPAUTH
fail
Sender Domain Intelligence

The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.

Sender domainashtique.com
Age15 daysNewly registered
Email Sample
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

Audit the Sender. Verify the sender domain (ashtique.com). Multi-million dollar investment offers will not originate from unrelated third-party domains.\n• Identify Scarcity Lures. Treat narratives involving "politically exposed" persons or the need for "untraceable proxy" partners as high-suspicion red flags.\n• Verify Independently. Never engage with high-value financial leads via unsolicited email. Conduct due diligence through verified institutional channels only.\n• Report Phishing. Forward the message to your security team and report it to CERT NZ (report@phishing.cert.govt.nz).