New Zealand warns AI could accelerate cyberattacks and increase risks

0
159
New Zealand warns businesses of growing AI-driven cyber risks
New Zealand warns businesses of growing AI-driven cyber risks

Artificial intelligence is reshaping New Zealand’s cyber threat environment, with the National Cyber Security Centre warning that attackers could use AI to make cyberattacks faster, larger in scale and more personalised.

The NCSC said cybercriminal groups and state-backed actors are already putting pressure on the country’s cyber defences. AI could further help attackers automate attacks, find vulnerabilities and target organisations and individuals more precisely.

Catriona Robinson, Head of the NCSC, said cyber security is no longer only an IT issue. It requires attention from senior management and boards as AI adds another layer to existing cybercrime and espionage risks.

The agency said criminals are already using AI for more convincing phishing, scams and social engineering. Future AI models could further automate attacks and vulnerability discovery. Tools currently limited to leading frontier models could also become available to malicious actors by early 2027.

Cyber incidents and emerging risks

The NCSC handled 369 incidents of potential national significance during 2025-26, up 16.2% from the previous year. 4 incidents were classified as C2, or Highly Significant, matching the combined total recorded at that level over the previous 10 years.

The agency said cybercriminals are becoming more persistent in using extortion and data theft to demand payment. Stolen personal information can also expose victims to further criminal activity.

The NCSC also warned about North Korean IT operatives secretly obtaining remote jobs with New Zealand businesses to generate foreign currency for the North Korean state. Such activity can create compliance, espionage and extortion risks and may breach United Nations sanctions.

Basic security remains critical

Despite the growing use of AI, the NCSC said basic cyber security remains the strongest protection. Organisations should maintain both human-led and AI-enabled defences and regularly update their security fundamentals.

Boards and senior leaders must ensure their organisations have the right people, processes and resources to respond to faster-moving threats.

“Government cannot protect every organisation from every cyber threat,” Robinson said.

The NCSC said leaders remain responsible for cyber security, and early preparation will help organisations manage risks linked to frontier AI.

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter

About us:

The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.