Just happened to check an email account that I use for my business at home and found an email supposedly from IRD regarding a refund.
Clicking the link in the email to "confirm the refund" took me to a very good rip of the IRD website - only in looks though - soon as you click any menu links you get taken to the actual domain the scam is being run from "balibuilders.com".
The ripped site contains a bunch of icons from various banks in NZ (ANZ, KiwiBank etc) in the middle which you are expected to click onto to choose your bank that you want your refund put into. Clicking one of these then takes you to a very good rip from the banks login screen - entering any details here return an error saying wrong password, but obviously its recording everything you type.
Nothing new ?
No not really, except this :
1) They used the correct email address that I gave IRD for contact.
2) I am waiting for a refund from IRD.
3) The amount is very close (or may even be the same, have to check paperwork at home) as what Im awaiting to be refunded.
Tried calling IRD but their phone system is overloaded........ (sigh)
I am aware of the other recent scams similar to this but the timing and amount mentioned in the email is too close to home for my liking...
Update : Emailed 'phishing@ird.govt.nz'