New Zealand's National Cyber Security Centre identified China as the most persistent and capable state-backed cyber threat, according to its annual Cyber Threat Report. The agency linked suspected state-sponsored cyber activity to actors from China, Russia, Iran, and North Korea, with 86 of 369 cyber incidents of potential national significance having suspected links to state actors.
The assessment highlights the growing threat of state-sponsored cyber espionage in the South Pacific, potentially impacting New Zealand's critical infrastructure, public services, and sensitive information, with significant implications for its citizens and businesses.
New Zealand's cyber security agency has identified China as the country's most persistent and capable state-backed cyber threat, according to its annual Cyber Threat Report released on Thursday. The National Cyber Security Centre (NCSC), part of New Zealand's intelligence community, stated that foreign actors have targeted government agencies and organizations across various sectors, including health, education, and information technology.
The report linked suspected state-sponsored cyber activity to actors from China, Russia, Iran, and North Korea. Of the 369 cyber incidents deemed to be of potential national significance in the year to June 2026, 86 had suspected links to state-sponsored actors. These incidents included activity targeting government agencies, health and education organizations, and IT managed-service providers.
The NCSC warned that geopolitical competition is increasingly manifesting in the South Pacific, with state-backed cyber espionage targeting governments and infrastructure. Such activity could impact New Zealand's citizens, businesses, and civic institutions due to the country's close ties across the region. State-backed actors are likely to target organizations operating critical infrastructure, providing essential public services, or holding strategically advantageous information. The agency also cautioned that cyber espionage can be difficult to detect, with actors conducting reconnaissance and establishing access over extended periods before engaging in intelligence gathering or disruption, potentially leading to the compromise of operational technology and data loss.
Pick the topics you care about. Get only what matters, on your cadence.