New Zealand cyber agency warns AI is reshaping threats
Mon, 5th Oct 2026 (Today)
The National Cyber Security Centre has warned New Zealand business and organisational leaders to prepare for cyber threats reshaped by artificial intelligence, alongside the release of its annual Cyber Threat Report.
The agency said AI is changing the cyber risk environment at increasing speed, adding to pressure from cybercriminal groups and state-backed actors. It urged leaders to assess whether their organisations have the people, processes and resources needed to respond to a faster-moving threat landscape.
The report's central judgement is that AI is rapidly reshaping cyber security risks and that frontier models could sharply increase both risks and opportunities. Newer systems could help malicious actors automate attacks, identify weaknesses and tailor targeting more closely to organisations and individuals.
It also warns that, as development accelerates, advanced AI tools now largely limited to leading frontier models could become available to malicious actors by early 2027. That, the report says, could allow disruptive incidents to occur with little warning.
Catriona Robinson, Head of the National Cyber Security Centre, said the issue now sits squarely with senior management and boards.
"Cyber security is now a critically important consideration for every New Zealand business and organisation," Robinson said.
She said the established mix of cybercrime and espionage risks is being altered by a new factor: artificial intelligence.
"The cyber threat landscape is changing faster than ever. Alongside familiar threats from cybercriminals and state actors, businesses and organisations face a powerful new disruptor in the form of frontier artificial intelligence," Robinson said.
Criminal activity
The report also points to a rise in the severity of cybercrime cases handled by the centre. In 2025/26, the NCSC dealt with 369 incidents of potential national significance, 162 of them linked to criminal or financially motivated actors, up 18 per cent from the previous year.
Those incidents included four cases classified as C2, or Highly Significant, matching the number recorded over the previous 10 years combined.
"The severity of incidents has increased," Robinson said.
She linked that trend to a broader shift in the economics and organisation of cybercrime.
"Cybercrime has evolved into an industrialised global industry. Cybercriminals are becoming more persistent, aggressive and effective in their pursuit of payment through extortion and data theft. As well as the harm they cause to businesses, these attacks cause harm to New Zealanders whose personal information is stolen and potentially sold to other criminals or malicious actors," Robinson said.
AI is already part of that criminal toolkit, the centre said. It pointed to more convincing phishing campaigns, scams and social engineering attacks as examples of how AI is lowering barriers for attackers and increasing the credibility of fraudulent approaches.
New risk
Alongside broader changes in criminal activity, the report identifies a more specific concern involving North Korean operatives seeking remote information technology work. The centre said it had seen the threat of a North Korean IT worker clandestinely securing remote work with a New Zealand business to earn foreign currency for the North Korean state.
According to the agency, that activity raises both compliance and security concerns. Such cases fall under United Nations sanctions in force under New Zealand law and may also create espionage and extortion risks for targeted businesses.
Robinson said AI presents both opportunities and risks, but warned that attackers are already using it in practice.
"AI offers many opportunities, but it is already being used by malicious actors to increase the speed, scale and sophistication of cyber attacks. The next generation of frontier AI models could automate attacks, identify vulnerabilities and enable highly personalised targeting of organisations and individuals," Robinson said.
The report argues that, despite the emergence of AI-driven risks, the strongest protection still lies in basic cyber security measures. The best defence against both human-led and AI-enabled threats, it says, remains strong cyber security fundamentals.
That places responsibility at the top of organisations, particularly where risk decisions involve budgets, staffing and operational priorities.
"Boards, chief executives and senior leaders need to consider whether their businesses or organisations have the people, processes and resources needed to respond to a faster-moving cyber threat environment," Robinson said.
The centre said the state cannot shield every organisation from every threat and that preparation by individual leaders will be decisive as AI becomes more central to the threat environment.
"Government cannot protect every organisation from every cyber threat. Leaders are responsible for cyber security within their organisations, and those who prepare now will be best placed to manage the challenges of frontier AI," Robinson said.