New Zealand organisations are continuing to see a mix of brand impersonation, typosquatting and phishing activity, with online retailers and well-known NZ brands being used to make fraudulent websites and emails appear legitimate.
Brand Impersonation
Recent activity has included fake online stores impersonating New Zealand retailers.
Bose NZ, the audio equipment retailer operating at bose.co.nz, has been impersonated through the domain:
bosenewzealand-nz[.]com
Real Page |
![]() Fake store bosenewzealand-nz[.]com |
The site appears to have been configured as a New Zealand-focused fake retail store, using WordPress, WooCommerce and the Sober WordPress theme.
Another example this week involved Cactus Outdoor, with the domain:
cactusoutdoorstore[.]shop
![]() Real Page |
![]() Fake Page cactusourdootstore[.]shop |
The Cactus Outdoor impersonation does not currently appear to be connected to the same actor behind the Bose impersonation.
These incidents highlight how relatively simple it can be for threat actors to create convincing copies of legitimate retail websites and use established brands to build trust with potential victims.
What can organisations do?
One of the easiest steps organisations can take is to ensure brand impersonation and typosquatting monitoring is included within their security or IT support arrangements.
Monitoring should look for:
- Newly registered domains resembling the organisation’s brand.
- Fake websites using company logos and branding.
- Lookalike domains targeting customers.
- Fraudulent social media profiles.
- Domains hosting fake login or payment pages.
Early identification can allow an organisation to take action before a fraudulent site gains significant visibility.
Phishing Activity
Alongside the retail impersonation activity, New Zealand businesses continue to receive the usual waves of IRD-related phishing emails, as well as phishing activity referencing Air New Zealand and airports.

These campaigns continue to rely heavily on familiar New Zealand brands and services to encourage recipients to click links, provide credentials or make payments.
Indicators of Compromise
The following domains have been observed in recent activity:
| IOC |
|---|
app.getbeamer[.]com |
bosenewzealand-nz[.]com |
cactusoutdoorstore[.]shop |
ammpxxppcliicks[.]us[.]cc |
studiocasini[.]eu |
www.powerscawebly[.]com |
airssrewzersteamworc0f93[.]myclickfunnels[.]com |
aispointsteamworkspace[.]myclickfunnels[.]com |
myirds[.]theshoppe[.]com |
inland[.]theshoppe[.]com |
cmc[.]nextinsolutions[.]com |
linehair[.]fr |
kakao[.]com |
Of particular interest are the domains associated with infrastructure repeatedly appearing in the observed phishing activity.
Organisations should consider blocking or monitoring traffic to if your business allows it:
myclickfunnels[.]comtheshoppe[.]comnextinsolutions[.]com
Takeaway
Brand impersonation is not limited to large international companies. New Zealand retailers and locally recognised brands can also be attractive targets, particularly where a convincing fake online store can be established quickly.
For NZ organisations, combining domain monitoring, email security, DNS/web filtering and user awareness provides a practical layer of defence against these campaigns.


