Locked card email is trying it on
A phishing email from info.net is posing as American Express and pressuring you to update your account after claiming your card has been limited or locked.
You could receive an email from info.net with the subject "Your Card has been locked due to non-compliance concerns". It presents itself as an American Express message, using familiar blue and white branding and a warning that your card use has been limited. The email pushes you to click through and "Update your account", creating urgency around an apparent card problem.
What gives it away is that the sending domain does not line up with the brand being shown, and the mail systems could not verify who really sent it. In plain terms, the message failed the usual checks that help confirm an email is genuine, and there was no verified signing or policy backing it up. Even though info.net is an old domain with a long registration history, that age does not make this message trustworthy when the sender cannot be authenticated and the branding does not match the source.
The attacker is likely after your card details, login credentials, or other account information through a fake update page. If you click and enter anything, you could hand over access to payment information or linked business accounts. If the email invites a reply, any response may also be redirected away from the apparent sender and into the attacker's hands.
This campaign has been seen circulating across multiple NZ organisations in the last day, so treat it as active rather than theoretical. If anyone in your business receives it, assume the goal is account theft and act quickly to contain it.
The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Check: Warn your team to watch for messages claiming to be from American Express about a locked or limited card, especially if they ask you to update account details.
- Check: Verify the real sender address and any linked website before taking action. If the domain does not match the brand, treat it as suspicious.
- Do not: Click the link, open attachments, reply, or enter card or login details from the email.
- Report: Flag the message to your IT provider or security contact, then remove it from inboxes if confirmed malicious.
- Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.
See what a genuine American Express message looks like, the real sender domain, the real link destination, and where to report a fake.

