NCSC NZ's Q1 2026 Cyber Security Insights Report was released today.
While overall incident volumes remained relatively stable, the quarter saw a notable increase in both the severity of incidents and the financial losses experienced by New Zealanders.
🟣 By the numbers
▪️1,164 cyber security incidents reported (+3% from Q4 2025).
▪️77 incidents required specialist NCSC technical support.
▪️3 incidents categorised as C2 ("Highly Significant") – the first C2 incidents reported since 2021/22.
▪️$5.6 million in direct financial losses reported (+76% from Q4 2025).
▪️Individuals accounted for $5.2 million of reported losses.
▪️42 incidents caused losses exceeding $10,000, representing 97% of all reported financial loss.
🟣 Threat signals
▪️Phishing and credential harvesting remained the most common incident type with 437 reported incidents.
▪️Scams and fraud were the second most reported category, accounting for approximately $3.8 million in losses.
▪️Several significant incidents involved unauthorised access to sensitive customer and patient information.
▪️Thousands of New Zealanders were impacted by the three highly significant C2 incidents.
🟣 Key observations
▪️The concentration of financial losses in a small number of incidents highlights the importance of early detection and rapid response.
▪️Sensitive data remains a prime target for cyber criminals and nation-state actors alike.
▪️Credential theft continues to be one of the most effective pathways for compromise.
▪️ The impact of cyber incidents increasingly extends beyond IT systems to operational disruption, privacy obligations, regulatory scrutiny, and reputational damage.
🟣 Priorities for resilience
▪️ Strengthen identity and access management controls.
▪️ Improve phishing resistance through technical controls and user awareness.
▪️ Protect sensitive data through classification, access controls, monitoring, and encryption.
▪️ Maintain tested incident response and crisis management plans.
▪️ Focus on operational resilience, not just compliance.
The report also includes an interesting discussion on the implications of emerging Frontier AI models and the opportunities and risks they may present for cyber defenders and threat actors alike.
🔗 Read the full report here:
https://lnkd.in/eN5zXJhV