Dodgy payment email wants you to panic
A phishing email with the subject "Incoming Payment Rejected" is circulating and tries to push you into restoring supposed bank account access after a fake security alert.
You could receive an email with the subject "Incoming Payment Rejected" that reads like a bank security notice. It addresses you as a valued customer, claims your bank account has been restricted after an abnormality was detected, and pressures you to take action to restore access. It is designed to look routine and urgent, so you act before you think.
What gives it away is that the message comes from staging.tv2fly.com, which does not match the bank it is pretending to represent. Some of the technical checks passed, which can make the message look legitimate at first glance, but that only means the sending system accepted that domain, not that your bank actually sent it. The domain itself has history, but it is still unrelated to the organisation being impersonated, and that mismatch is the real warning sign.
The attacker is trying to get you to click, reply, or hand over sensitive information by making you think your payments or account access are at risk. If you engage, you could end up giving away banking details, login credentials, or other business information that can be used for fraud or follow-on attacks.
Because this campaign is being seen across multiple Microsoft 365 tenants, you should treat any unexpected payment failure or account restriction email with caution, even if it appears to pass normal email checks. If the message was not expected, verify directly with your bank using contact details you source yourself.
The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Check: Treat any email about rejected payments or restricted bank access as suspicious unless you were expecting it.
- Verify: Contact your bank using a phone number or website you find independently, not details in the email.
- Do not: Click links, reply, or provide login details, banking details, or verification codes from this message.
- Report: Send the email to your IT provider or security team so they can block the sender and check whether anyone interacted with it.
- Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.
See what a genuine Kiwibank message looks like, the real sender domain, the real link destination, and where to report a fake.

