Tender trap in your inbox
A phishing email posing as MAZ Building Group is circulating across NZ, using a tender invitation and document access button to lure you into clicking.
You might receive an email with the subject line "Invitation to Tender (MAZ GROUP)", presented in a plain corporate style and appearing to come from MAZ Building Group. It invites you to take part in a project tender and pushes you to click an "ACCESS DOCUMENTATION" button. If it lands in your inbox, it is designed to look routine and businesslike enough to catch anyone who deals with quotes, projects, or procurement.
What gives it away is that the technical trust signals do not line up cleanly. The sending domain, syndasus.com, is not the brand being presented to you, and while some authentication checks passed, SPF failed, which means the message was not fully authorised to send on behalf of the domain it claimed to use. That is a common sign of sender abuse. The domain also has little established history as a legitimate business sender, which makes it a poor fit for a real construction tender approach.
The attacker is trying to get you to click through and engage with whatever sits behind the document button. That can lead to credential theft, malware delivery, or follow-up social engineering if you reply or provide business details. If you or a staff member use Microsoft 365 or shared mailboxes for tenders and supplier work, one click could hand over access to your email, contacts, and internal conversations.
The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Check: Treat unsolicited tender or procurement emails with caution, especially if the sender domain does not match the organisation being presented.
- Check: Verify any tender invitation by contacting the organisation through its official website or a known phone number before clicking document links.
- Do not: Click the documentation button, download files, or enter your Microsoft 365 or email credentials from this message.
- Report: Flag the email to your IT provider or internal security team so similar messages can be blocked and reviewed.
- Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.

