New Zealand’s National Cyber Security Centre (NCSC) has warned businesses and organisational leaders that artificial intelligence is changing the cyber threat landscape, giving criminals new ways to make attacks faster, more targeted and easier to scale.
The warning comes as cybercrime continues to evolve beyond conventional phishing and malware campaigns. According to the NCSC, artificial intelligence is increasingly being incorporated into criminal activity, potentially lowering the technical barriers for attackers while making fraudulent communications more convincing.
The agency has urged boards and senior executives to treat cyber security as a business and governance priority rather than an issue limited to IT departments.
AI Could Make Cyberattacks Faster and More Personalised
The NCSC said artificial intelligence can help malicious actors automate parts of an attack, identify potential weaknesses and tailor approaches to specific organisations or individuals.
AI-assisted phishing, scams and social-engineering campaigns can make fraudulent messages appear more credible, increasing the possibility that employees or individuals may be deceived.
The agency also warned that the threat could grow as increasingly capable AI systems become more widely accessible. Technologies that currently require advanced models could become easier for criminal groups to obtain and use in the near future.
New Zealand Recorded More Significant Cyber Incidents
The NCSC reported handling 369 incidents of potential national significance during 2025–26, representing a 16.2% increase from the preceding year.
Four incidents were classified as C2, or Highly Significant. According to the agency, that was equal to the combined number of C2 incidents recorded during the previous decade.
The figures indicate that the impact and severity of cyber incidents are becoming a growing concern for organisations operating in New Zealand.
The NCSC also highlighted the changing economics of cybercrime, with criminals increasingly pursuing organisations through extortion, data theft and other financially motivated methods.
Stolen Data Can Create Risks Beyond the Original Attack
Cyber incidents can have consequences that continue long after an organisation has restored its systems.
When personal or commercially sensitive information is stolen, affected individuals may face additional risks, while businesses can experience financial losses, operational disruption and reputational damage.
The NCSC's warning therefore extends beyond preventing an initial breach. Organisations also need processes for identifying suspicious activity, responding quickly and assessing the potential consequences of compromised information.
For businesses dealing with suspected fraud or suspicious financial activity, structured Financial Investigation can also help establish transaction patterns and identify potential financial exposure.
North Korean IT Worker Threat Also Highlighted
The NCSC separately raised concerns about North Korean operatives attempting to obtain remote IT employment with New Zealand businesses.
The agency said it had encountered the possibility of individuals secretly working for New Zealand companies while generating foreign currency for the North Korean state.
Such arrangements can create multiple risks for employers, including sanctions and compliance concerns as well as potential security, espionage and extortion threats.
The issue demonstrates that cyber risk can extend beyond technical vulnerabilities and may also involve recruitment, identity verification and organisational processes.
Basic Cybersecurity Measures Remain Important
Despite the increasing role of artificial intelligence in cybercrime, the NCSC said organisations should not overlook fundamental cybersecurity practices.
Strong access controls, appropriate security procedures, employee awareness and regular updates remain important elements of defence.
The agency has also stressed that businesses need to combine human judgement with technology-based security measures rather than assume that AI-driven threats require an entirely separate cybersecurity strategy.
In many cases, sophisticated attacks can still succeed because of weaknesses in basic security practices.
Cybersecurity Is Now a Board-Level Responsibility
NCSC Head Catriona Robinson said cybersecurity should receive attention from senior management and boards rather than being treated solely as an IT responsibility.
For company leaders, this means assessing whether the organisation has adequate staff, processes, technology and resources to respond to increasingly complex threats.
Boards and executives also need to understand how cyber incidents could affect business continuity, customer information, regulatory obligations and finances.
The NCSC emphasised that governments cannot protect every organisation from every cyber threat. Businesses therefore need to take responsibility for preparing their own systems and teams.
AI Changes the Threat Landscape, But Preparation Still Matters
Artificial intelligence is giving cybercriminals additional capabilities, but the New Zealand warning also underlines a broader point: organisations remain vulnerable when basic security controls and governance are neglected.
Businesses that regularly review their cyber risks, train employees, protect sensitive information and maintain an effective incident-response process may be better positioned to handle a rapidly changing threat environment.
As AI capabilities continue to develop, cybersecurity preparedness is likely to become an increasingly important part of corporate risk management.