Skip to content

New Zealand warns frontier AI will accelerate cyber threats by 2027

New Zealand warns frontier AI will accelerate cyber threats by 2027

New Zealand’s National Cyber Security Centre, the government agency responsible for monitoring major cyber threats, has warned that frontier AI is rapidly changing the country’s security environment as criminals and state-backed actors gain access to stronger automated capabilities.

The NCSC puts frontier AI at the top of its 2026 threat assessment, alongside established risks involving cybercrime, state-sponsored espionage and supply-chain attacks.

“Cyber security is now a critically important consideration for every New Zealand business and organisation,” NCSC head Catriona Robinson said. She said malicious groups already use AI to increase the speed and scale of attacks, while more advanced models will give attackers stronger capabilities for finding vulnerabilities, conducting reconnaissance and targeting individuals.

The NCSC assesses a realistic prospect that by early 2027, malicious actors will gain access to advanced AI capabilities currently concentrated among developers of leading frontier models. Wider access would lower the technical barriers around some forms of cyber activity and allow less sophisticated groups to automate work previously requiring specialist expertise.

The agency expects frontier models to accelerate searches for zero-day vulnerabilities and automate parts of brute-force attacks.

AI is also improving phishing, scams, deepfakes and social engineering by producing more convincing material tailored to individual targets.

Those developments don’t replace conventional cyber risks. Instead, AI gives criminal and state-linked operators another tool for scaling techniques already used against businesses, public agencies and individuals.

The NCSC said senior management teams need to assess whether their organisations have enough staff, processes and security resources for an environment where attacks develop faster. That includes the ability to patch systems promptly, respond to newly disclosed vulnerabilities and investigate breaches before attackers gain wider access.

Cybercrime increased during the latest reporting year. The NCSC handled 369 incidents considered to have potential national significance in 2025/26, up from 331 in the previous year, while 162 showed links to criminal or financially motivated actors.

That represented an 18% increase in financially motivated incidents compared with 2024/25. Criminal activity accounted for 44% of the cases sent for specialist NCSC analysis, while another 86 incidents showed suspected links to state-sponsored actors.

The agency also recorded four C2, or Highly Significant, cyber incidents during 2025/26. That matched the total number of incidents at the same severity level recorded across the previous decade, according to the NCSC.

New Zealand’s NCSC identified China as its most persistent state-backed cyber threat after 86 major cyber incidents showed suspected state links

High-impact cases included attacks involving healthcare and education organisations. The agency cited the theft of more than 99,000 patient records from the Manage My Health portal and a breach affecting the Canvas learning management system used by several large New Zealand educational institutions.

The NCSC described modern cybercrime as an industrialised international business built around extortion, stolen data and increasingly persistent attempts to force payments.

Stolen personal information also creates secondary risks when criminals sell or transfer data for further fraud, scams or other malicious activity.

New Zealand recorded 4,673 cyber incident reports during 2025/26, compared with 5,995 a year earlier. Although the total number fell, the subset requiring specialist technical assistance increased, showing a shift towards more serious cases rather than simply greater incident volume.

Direct financial losses reported to the NCSC reached NZ$23.8 mn during the year, down from NZ$26.9 mn in 2024/25. Those figures cover reported direct losses and don’t represent the full economic cost of outages, recovery work, stolen information or longer-term business disruption.

The report also documents an emerging risk involving North Korean technology workers seeking remote employment inside foreign companies. During the year, a large New Zealand business contacted authorities after becoming suspicious about the identity of a remote IT contractor.

An investigation involving the NCSC and New Zealand Police identified the worker as a North Korean national operating under a false identity.

According to the NCSC, the individual used fabricated identity documents and a New Zealand contact address, while a New Zealand citizen received and operated the company’s laptop on the worker’s behalf.

The business terminated the employment arrangement and refused payment after discovering the worker’s identity. The individual then claimed to possess commercially sensitive information and threatened to release it unless the company paid, according to the report.

North Korea operates organised networks of overseas IT workers to generate foreign currency for the state, the NCSC said. Some cases also involve espionage or malicious cyber activity, creating risks beyond payroll fraud for companies that unknowingly hire workers operating under false identities.

The issue carries an additional legal dimension because United Nations sanctions against North Korea have effect under New Zealand law. The sanctions include restrictions related to employment and the transfer of data or software for the benefit of North Korea.

The NCSC advises employers to strengthen checks around remote technical recruitment, including identity verification and equipment handling. Warning signs identified in the report include requests for cryptocurrency payments, avoidance of video meetings and working patterns inconsistent with the employee’s stated location.

AI adds another layer to these existing threats by making impersonation and social engineering easier to scale. Generative systems produce realistic written communication and synthetic content at low cost, giving attackers more material for phishing campaigns and fraudulent identities.

The same technology offers defensive uses. The NCSC is studying how frontier models support vulnerability detection, analysis and cyber defence, while warning organisations against adopting AI tools without assessing how those systems interact with confidential information and internal infrastructure.

Robinson said responsibility for organisational cyber security remains with boards, chief executives and senior managers rather than government agencies alone. The report recommends maintaining basic controls around credentials, software and sensitive data even as AI changes the speed and technical scope of attacks.

Multi-factor authentication, strong passwords, passkeys and software allow lists remain among the controls cited by the NCSC. The agency’s assessment is that many common attacks still succeed through weaknesses in basic security rather than highly advanced technical methods.