New Zealand’s cybersecurity agency warned that China remains the nation’s most persistent and capable state‑backed cyber threat, with foreign actors targeting government agencies and organizations across health, education, and information technology sectors.
The National Cyber Security Center (NCSC), an arm of New Zealand’s intelligence community, reported that it had detected activity it believes was carried out by foreign state actors, jeopardizing sensitive New Zealand information.
The report attributed the suspected state‑sponsored cyber activity to actors from China, Russia, Iran, and North Korea, according to its annual Cyber Threat Report released on Thursday.
The assessment represents the latest warning from a Western‑aligned intelligence agency concerning alleged Chinese cyber espionage, which Beijing consistently denies.
This finding follows a prior report from New Zealand’s security agency in August, which stated that China was the sole country the agency had identified conducting espionage at scale.
The Cyber Security report indicated that 86 of 369 cyber incidents considered potentially significant for national security between now and June 2026 were suspected to be linked to state‑sponsored actors, encompassing attacks on government agencies, health and education bodies, and IT managed‑service providers.
The agency cautioned that rising geopolitical competition is playing out in the South Pacific, where it has identified state‑backed cyber espionage targeting government entities and critical infrastructure.
New Zealand maintains strong familial, cultural, political, and economic ties throughout the Pacific, and this activity could impact citizens, businesses, and civic institutions, the agency noted.
State‑backed actors are likely to target organizations that manage infrastructure or networks, deliver essential public services, or possess information that could confer a strategic advantage, the NCSC said.
It warned that cyber espionage is often hard to detect, as actors conduct reconnaissance and embed access into systems over months or years before exploiting it for intelligence collection or disruption.
Prolonged intrusions may result in the compromise of operational technology and the loss of corporate and personal data, it said.
