If you want your parcel, you better pay the redelivery fee.
A high-fidelity phishing campaign impersonating NZ Post is targeting New Zealand organisations with fraudulent 'Redelivery Fee' invoices via mass-hosting infrastructure.
A sophisticated phishing campaign has been detected impersonating NZ Post, specifically utilizing 'Redelivery Fee Invoice' lures. The messages originate from the infrastructure of a global mass-hosting platform (nxcli.io), which allows the campaign to bypass many traditional reputation-based security filters. Technical analysis indicates that the messages failed SPF, DKIM, and DMARC authentication, yet they are systematically reaching New Zealand inboxes due to the high reputation of the underlying hosting nodes.
The email body employs extremely high-fidelity NZ Post branding, including accurate color palettes, official logos, and a professional layout. The lure is designed to create a sense of operational urgency by notifying users of a pending NZD 8.50 fee for a second delivery attempt. This 'Micro-Transaction' technique is a deliberate social engineering tactic to bypass financial skepticism, as users are more likely to interact with low-value charges in the hope of resolving a simple delivery issue.
Attackers are using this wave to harvest both organisational login credentials and sensitive payment card data. The campaign specifically targets the common business workflow of managing international and domestic courier deliveries, relying on the high volume of legitimate logistics mail received by New Zealand organisations to remain undetected.
Organisations are advised to treat any unsolicited logistics notifications with clinical skepticism. Legitimate NZ Post tracking and payment updates should be verified strictly through the official nzpost.co.nz portal or the mobile application. Enforcing strict 'First Contact' safety tips and encouraging users to utilize the 'Report Phishing' mechanism remain the most effective methods for refining tenant-level security against these mass-hosting infrastructure abuses.

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Do not interact with links in unsolicited logistics or redelivery notifications.
- Verify parcel status strictly via the official NZ Post tracking portal or mobile application.
- Apply tenant-wide domain blocking for the *.nxcli.io infrastructure to prevent further delivery.
- Educate staff on the risks of 'Micro-Transaction' social engineering lures.
See what a genuine NZ Post message looks like, the real sender domain, the real link destination, and where to report a fake.


