Skip to content
Cybersecurity Incidents in New Zealand: Q1 and Q2 2026 Overview

Cybersecurity Incidents in New Zealand: Q1 and Q2 2026 Overview

First seen 22 Sep 2026, 21:58 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 22:55 UTC
  • Q1 2026 saw 1,164 cybersecurity incidents with losses of NZ$5.6 million.
  • Phishing and credential harvesting were the most common attack methods reported.
  • Q2 2026 recorded a decrease in incidents to 1,129, with losses dropping to NZ$2.7 million.

In the first quarter of 2026, New Zealand's NCSC recorded 1,164 cybersecurity incidents, resulting in direct financial losses of NZ$5.6 million, a 76% increase from the previous quarter. The most common incidents were phishing and credential harvesting, with scams and fraud causing significant losses. Three incidents were categorized as C2, impacting sensitive data and essential services. In the second quarter, incidents slightly decreased to 1,129, with reported losses dropping to NZ$2.7 million, a 52% decrease. Scams and fraud were the most common types reported, with unauthorized access causing a notable loss of NZ$1.3 million. The NCSC noted an increase in malware scams targeting New Zealanders, particularly through creative schemes to deceive users into downloading malicious software.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-01-01
Q1 2026 incident reports begin
NCSC recorded 1,164 cybersecurity incidents, marking a slight increase from Q4 2025.
NCSC
2026-03-31
Q1 2026 financial losses reported
Direct financial losses reached NZ$5.6 million, with individuals accounting for NZ$5.2 million.
NCSC
2026-04-01
Q2 2026 incident reports begin
NCSC responded to 1,129 incident reports, slightly fewer than Q1 2026.
NCSC
2026-06-30
Q2 2026 financial losses reported
Direct financial losses fell to NZ$2.7 million, with scams and fraud being the most common incidents.
NCSC

More articles in this cluster (2)