Skip to content
Judgement 2

Judgement 2

Ncsct.Nz • September 25, 2026

State actors and their enablers are undertaking malicious cyber activity against New Zealand. The techniques they use are sophisticated and persistent, targeting both government and private sector organisations.

State actors are motivated by national priorities which may include diplomatic or military advantage, economic interests or suppression of dissent. In New Zealand the primary focus of state activity has been espionage, but internationally our partners have identified state actors using cyber tools to undertake intimidation, intellectual property theft, the disruption of networks and critical services, and in some cases, sabotage.

Changing strategic context

State- cyber activity is happening in the context of a changing threat environment driven by geostrategic competition, conflict and international tensions. In this environment the use of cyber as an offensive tool, or the threat of its employment, can be a mechanism states deploy when faced with a worsening political climate or a deterioration of international relations.

There is a concerning trend by state actors toward more aggressive and assertive activity in cyberspace. This is evidenced by the targeting of critical infrastructure such as energy and telecommunications networks, transport networks, water and financial systems. Actions such as the pre-positioning of offensive cyber capabilities on target systems or limited demonstrations of an attack capability, can be used as a deterrent, and if undetected can limit the warning time to identify and prevent a disruptive attack.

Taken together these actions are challenging the norms of responsible state behaviour in cyberspace. We anticipate that these trends are likely to continue, with AI enabling a significant increase in the volume of these types of operations. This trajectory is likely to create a more volatile and unpredictable environment during periods of conflict.

Why does this matter?

State- espionage against New Zealand government agencies, businesses and other organisations is a significant risk to our economy, long term security, and ability to shape the world toward our preference for a rules-based international system. Our location and distance from areas of conflict does not make New Zealand immune to the cascading impacts of cyber attacks. In a highly connected world, a cyber attack elsewhere could create direct or compounding impacts such as disruption of telecommunications and transport networks, interruption to supply chains (physical and digital), and the compromise of sensitive information.

The New Zealand and global context

In the past year the National Cyber Security Centre (NCSC) has identified activity, suspected of originating from foreign state actors, targeting New Zealand government agencies, organisations in the health and education sectors, and information technology managed service providers. The NCSC believes these incidents have exposed sensitive New Zealand information to risk. The NCSC has also joined other nations in identifying state- activity that targets critical national infrastructure.

Twenty three percent (23%) of the incidents of potential national significance dealt with in the 2025/26 year had suspected state- links. The NCSC has linked activity to suspected statesponsored actors from the People’s Republic of China, Russian Federation, Islamic Republic of Iran and the Democratic People’s Republic of Korea (North Korea). Of these nations the People’s Republic of China (PRC) is the most persistent and capable state actor undertaking cyber activity in New Zealand.

In April 2026 New Zealand joined nine other countries to warn against the large-scale use by China-affiliated actors of covert networks of compromised devices such as routers to hide their malicious activity. Also known as ‘botnets’, these networks enable malicious activity at scale and have been used by PRC affiliated groups known as Volt Typhoon and Flax Typhoon to target infrastructure networks.

In December 2025 New Zealand joined thirteen other nations and the European Union to warn against attacks on US and global critical infrastructure by pro-Russian hacktivist groups with links to the Russian state. These attacks target water and wastewater, energy and food and agriculture organisations.

In August 2025 New Zealand joined twelve other nations in identifying a campaign of malicious cyber activity being undertaken by a PRC state- group known as Salt Typhoon. The campaign targeted telecommunications, transport and government networks globally by using publicly known vulnerabilities and exposures in networks and edge devices to undertake espionage including the harvesting of data, phone calls, credentials and network information. Salt Typhoon activity was observed in New Zealand.

Increasing geo-strategic competition is being seen in the South Pacific where we are aware of statesponsored cyber espionage targeting governments and infrastructure.

New Zealand is a Pacific country with family, cultural, political and economic links to South Pacific nations with whom we a common interest in fostering regional stability and peace. It is concerning to see Pacific nations being targeted in ways that could impact citizens, businesses and civic institutions.

State- actors use a wide range of tools to achieve their objectives, and they constantly refine their techniques so their activity is difficult to detect and defend against. While some statesponsored activity can be defended against in the same way as other malicious cyber activity, at the extreme end of the spectrum state actors have access to tools and resources beyond the capability of most network defenders to detect and defend, even with third party support.

There are known links between state actors and cybercriminal networks, with an exchange of tools, information and techniques. For example, credentials stolen as part of a criminal exploit may be purchased or transferred to a state actor who then uses them to undertake espionage or other malicious activity. State actors are also known to use criminal groups as proxies to obfuscate their activities and avoid direct state-level retaliation or international sanctions.

Example: Russia-linked attack on Polish energy infrastructure

On December 29, 2025, a cyber actor undertook a coordinated attack on Polish energy infrastructure, targeting renewable energy systems including windfarms, solar farms and combined energy power plant supplying around 500,000 consumers.

Poland’s Computer Emergency Response Team and other experts linked the attack to Russian state actors based on similarities between the December attack and activity linked to Russian government organisations. In July 2026 the UK and EU publicly attributed the attack to the Russian state.

Fortunately, the attack did not disrupt the wider Polish energy network, however it is regarded as a significant escalation in cyber attacks with the intent being disruption and sabotage of critical national infrastructure.

A wide range of New Zealand businesses and organisations are potential targets for state- cyber espionage or other malicious cyber activity. These include businesses or organisations that operate infrastructure or networks, provide essential services to the public, or hold sensitive information that could provide strategic advantage.

State actors are stealthy and play the long game. Malicious activity can include reconnaissance of systems and the pre-positioning of cyber assets for the purposes of espionage or disruption. The compromise of sensitive information through long-term espionage efforts that are undetected for months or years can have real harm such as compromise of operational technology and the loss of corporate and personal information.

However, even the most sophisticated actors can be foiled by good solid controls. Organisations and businesses, particularly in the infrastructure or network sectors, should regularly review their cyber security settings and be familiar with advice provided by the NCSC on how to identify and tackle counterespionage and state- activity.

Questions leaders should be asking:

Have we considered the risk of intrusion by a sophisticated actor, and the actions we would take to defend against or mitigate such an attack?

Are we confident we can detect unusual activity in our environments, including persistent activity over long time frame?

Can we identify our mission-critical information assets that need to be protected against statesponsored threats?

Have we reviewed our critical controls recently to understand where we need to put effort to prevent intrusions or compromise of our systems?

China-Nexus covert networks - April 2026

In April 2026 the National Cyber Security Centre joined industry and international partners to advise on how to defend against multiple covert networks which have been created and are being constantly updated by Chinese cyber actors.

Pro-Russia hacktivists conduct opportunistic attacks against US and global critical infrastructure - December 2025

In December 2025 the NCSC joined international partners in identifying pro-Russia hacktivist groups conducting cyber operations against numerous organizations and critical infrastructure sectors worldwide. Among the increasing number of groups, some appear to have associations with the Russian state through direct or indirect support.

Salt Typhoon – August 2025

In August 2025 the NCSC joined international partners in drawing global attention to a campaign of malicious activity being undertaken by PRC state- cyber threat actors targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks.

For further information, refer to the following guidance:

New Zealand Information Security Manual External Link

Government Information Security Framework and Policies External Link

Key cyber security terms and their definitions can be found in our glossary:

Glossary | Rarangi kupu

Case Study 1: North Korean IT workers in New Zealand

During the year a large New Zealand business became suspicious of the identity details of an IT contractor working remotely.

The business contacted the NCSC and New Zealand Police, and investigation identified the worker as being from North Korea (Democratic People’s Republic of Korea or DPRK). To gain employment the North Korean worker used a false persona including fake identity documents, a New Zealand address as a point and recruited a New Zealand citizen to receive and operate the company’s laptop.

The New Zealand business immediately terminated the employment of the North Korean worker and refused to pay for their services. The worker then claimed to have obtained commercially sensitive information and threatened to release this if not paid.

The North Korean state operates a coordinated programme of using remote IT workers to generate revenue for the regime, including the funding of sanctioned weapons programmes. In some cases, the workers also undertake malicious cyber operations. These workers often operate under front companies overseen by the North Korean state apparatus. The IT workers use identity masking technology to hide their North Korean identity when securing contracts for remote work.

North Korea is currently subject to UN sanctions which have effect in New Zealand law. These sanctions impose various restrictions and prohibitions including a prohibition on granting work visas to North Korean nationals, and a prohibition on the export of data and software to, for use in, or for the benefit of North Korea.

To mitigate the risk of employing North Korean IT workers organisations should consider interviewing potential staff face-to-face and require new staff to pick up IT equipment personally. Other risk factors to be aware of include requests to be paid in cryptocurrency, refusal to participate in video-conference meetings and the recording of unusual working hours.

Cybercrime and extortion are escalating in severity