Cyber attacks are now a routine fact of digital life in New Zealand, affecting everyone from small Kāpiti Coast retailers to major Wellington government agencies. This guide explains, in plain language, what these attacks actually look like, how they reach New Zealanders through local networks and everyday devices, and the practical, affordable steps that stop the vast majority of them. Whether you are on Chorus fibre through Spark, running a small business on a 2degrees mobile plan, or managing IT for a regional council, the threat landscape and the defences are largely the same.
Key Points
- The basics stop most attacks: multi-factor authentication, patched software and a password manager block the majority of incidents seen in New Zealand.
- Phishing is the main entry point: texts and emails impersonating IRD, NZ Post, Kiwibank and ACC target brands Kiwis trust — verify through official apps, never links.
- The numbers are real: the NCSC logged 5,995 incident reports and NZ.9M in directly reported losses in 2024/25, with the wider cost estimated near NZ
.6b for 2024.
- Businesses have legal duties: the Privacy Act 2020 requires notifying the Privacy Commissioner and affected people after a serious breach, with fines up to NZ,000 for failing to notify.
- Reporting has changed: CERT NZ is now part of the NCSC — report incidents at ncsc.govt.nz/report or on 0800 114 115.
What “cyber attack NZ” actually means for New Zealand users
The phrase covers a wide range of hostile digital activity, but in the New Zealand context it clusters around a handful of recurring attack types. Phishing remains the dominant entry point — emails and texts impersonating IRD, NZ Post, Kiwibank or ACC are perennial favourites because New Zealanders recognise those brands and act on them quickly. Ransomware has hit NZ hospitals, law firms and local councils hard; the Waikato District Health Board attack in May 2021, which forced hospitals onto manual workarounds for weeks, remains the most publicly visible example of what a single successful intrusion can cost.
Beyond those headline categories, NZ users face credential stuffing (attackers reusing leaked username and password pairs from overseas breaches to log into Trade Me, banking portals and government myIR accounts), business email compromise targeting finance staff, and distributed denial-of-service (DDoS) attacks against NZ-hosted services. This is not a fringe problem: the National Cyber Security Centre (NCSC) received 5,995 incident reports in the 2024/25 year and logged NZ$26.9 million in directly reported financial loss, while separate research estimates the true cost — once under-reporting is accounted for — at roughly NZ$1.6 billion across New Zealand adults in 2024. Crucially, the NCSC consistently notes that most successful attacks exploit known, already-patchable vulnerabilities and human error rather than sophisticated zero-day exploits, which means basic hygiene stops the majority of attempts. If you want the wider picture, our overview of cyber security in New Zealand sets out the defensive fundamentals in more depth.
New Zealand’s position as a Five Eyes partner is also relevant to the legal backdrop. Under the Privacy Act 2020, organisations that hold personal information have a mandatory breach-notification duty: if your business suffers a breach that is likely to cause serious harm, you must notify the Office of the Privacy Commissioner and affected individuals as soon as reasonably practicable. Failing to notify when required is an offence carrying a fine of up to NZ$10,000, on top of the reputational damage.
How cyber attacks reach NZ targets
The technical pathway
Most attacks against NZ targets are not aimed specifically at New Zealand — they come from automated scanning tools that probe every IP address on the internet looking for open ports, unpatched services and weak credentials. NZ residential and business IP ranges carried over Chorus, Enable Networks and Ultrafast Fibre become visible to these scanners the moment a device connects. A home router left on default credentials is exposed regardless of how fast the connection is; a high-bandwidth line such as Spark HyperFibre actually makes a compromised device a more attractive target for recruitment into a botnet.
Phishing reaches NZ inboxes through compromised or rented sending infrastructure, often routed via overseas mail servers to dodge basic filtering. SMS phishing (“smishing”) is increasingly common because mobile carriers cannot reliably block spoofed sender IDs at scale — the attacker’s text arrives displaying “NZ Post” or “IRD” simply because the sender-ID field has been set to that string. Treat any message that pushes urgency and a link with suspicion, and reach the organisation through its official app or a bookmarked address instead.
NZ-specific infrastructure considerations
New Zealand’s internet topology creates some particular risk factors. Most international traffic transits a small number of submarine cables — principally the Southern Cross and Hawaiki systems — so disruption at that layer would be a national-scale event. That is a state-level concern rather than something individuals defend against personally. More practically, NZ’s relatively concentrated ISP market means a fault or vulnerability in a major provider’s DNS resolver or core infrastructure can affect a large share of the country at once. On the positive side, the fibre rollout means most urban homes and businesses now have fast, low-latency connections that comfortably support proper security tooling — VPNs, encrypted DNS and network monitoring — without meaningful slowdown.
Recommended security setup for NZ users in 2026
Layered defence for individuals
The single most effective thing most New Zealanders can do today is enable multi-factor authentication on every account that supports it, keep software patched, and use a reputable password manager. Everything below builds on that foundation.
- Password manager: Use a well-regarded manager to generate and store a unique password for every account; the NZD cost ranges from free to about $5 per month. Never reuse passwords across IRD, banking and email. See our password manager guide for NZ for options.
- Multi-factor authentication (MFA): Turn on app-based (TOTP) MFA — using an authenticator app such as Aegis, Authy or Google Authenticator — for email, banking, Trade Me and any government portals. SMS codes are better than nothing but are vulnerable to SIM-swap attacks.
- DNS filtering: Point your router or devices at a filtering resolver such as Cloudflare’s 1.1.1.1 for Families or NextDNS to block known malicious domains before any device can reach them. Our walkthrough on how to change your router’s DNS takes about ten minutes.
- VPN for untrusted networks: On public Wi-Fi — an airport, a café, free CBD networks — a VPN encrypts your traffic before it leaves your device. Compare options in our guide to the best VPNs for NZ users.
- Software updates: Enable automatic updates everywhere. The majority of successful NZ ransomware incidents exploited vulnerabilities that had patches available weeks or months earlier.
- Encrypted backups: Follow the 3-2-1 rule — three copies, two media types, one kept offsite. A local drive or NAS plus a reputable cloud backup service (several bill in NZD) covers this well and is your best defence against ransomware.
- Check your exposure: Run your email addresses through Have I Been Pwned to see whether they appear in known breaches, then change any reused passwords those breaches expose.
Additional steps for NZ small businesses
Small businesses are disproportionately targeted because they often lack dedicated IT staff yet hold valuable data — customer payment details, employee records, supplier contracts. Under the Privacy Act 2020, even a sole trader handling customer personal information has obligations. At a minimum, a small NZ business should deploy endpoint detection and response (EDR) software on company devices, separate guest Wi-Fi from the internal network, and keep a written incident-response plan that lists the NCSC contact details and the Privacy Commissioner’s breach-notification process. The NCSC (which now includes the former CERT NZ) publishes free, NZ-specific guidance and critical-controls advice for small businesses that maps directly to the attack vectors seen in real local incidents.
NZ-specific considerations: ISPs, jurisdiction and data
ISP-level visibility
Your ISP — Spark, One NZ, 2degrees, Voyager or a regional provider — can see the DNS queries and any unencrypted traffic leaving your connection, and is required to assist lawful interception when directed. This is not a reason for paranoia, but it is a reason to use encrypted DNS (DNS-over-HTTPS or DNS-over-TLS) and to be clear about what a VPN does. A VPN shifts trust from your ISP to the VPN provider; it does not make you anonymous.
Five Eyes jurisdiction
New Zealand is a founding member of the Five Eyes intelligence alliance alongside Australia, Canada, the UK and the US, and intelligence sharing between these nations is extensive. For most people this is background context rather than a personal threat. For journalists, activists or anyone with a specific reason to minimise surveillance exposure, choosing a provider headquartered outside Five Eyes jurisdiction — such as Mullvad in Sweden or ProtonVPN in Switzerland — is a meaningful consideration. For the average person worried about phishing and ransomware, a provider’s technical security practices matter far more than its jurisdiction.
NZ streaming and geo-restrictions
A secondary use case for VPNs in NZ is content access. TVNZ+, ThreeNow, Neon, Sky Sport Now and Whakaata Māori are geo-restricted to NZ IP addresses, so New Zealanders travelling overseas often use a VPN to keep access, and some viewers use one to reach overseas libraries. This is a distinct use case from security, though the same tool serves both. Note that using a VPN to get around geo-restrictions may breach a platform’s terms of service, even though it is not illegal under NZ law.
Best tools and providers for NZ users
The comparison below covers the most relevant VPN options for NZ users based on published specifications, independent audits and realistic performance on local connections. As a performance guide: from an Auckland fibre line to a Sydney server, expect latency around 28–45ms (the physics floor for NZ–AU is roughly 28ms) and, on a well-tuned WireGuard connection, 80–90% of your base speed retained; a US West Coast server realistically floors around 138–165ms given cable routing.
Comparison
| Provider | Protocols | AU/NZ servers | Independent no-logs audit | Approx. NZD/month (annual) | Headquarters |
|---|---|---|---|---|---|
| Mullvad | WireGuard, OpenVPN | AU yes, NZ limited | Yes (Cure53, Assured) | ~NZ flat | Sweden (non–Five Eyes) |
| ProtonVPN | WireGuard, OpenVPN, Stealth | AU yes, NZ yes | Yes (Securitum, annual) | ~NZ–16 | Switzerland (non–Five Eyes) |
| ExpressVPN | Lightway, OpenVPN | AU yes, NZ yes | Yes (KPMG) | ~NZ–22 | British Virgin Islands |
| NordVPN | NordLynx (WireGuard), OpenVPN | AU yes, NZ yes | Yes (Deloitte, 5th in 2024) | ~NZ–12 | Panama |
| Surfshark | WireGuard, OpenVPN, IKEv2 | AU yes, NZ yes | Yes (Deloitte) | ~NZ –8 | Netherlands |
Pricing is approximate and based on published annual-plan rates; check each provider’s NZD checkout directly, as some bill in NZD and others in USD. If budget is tight, our free VPN guide explains which free options are genuinely usable and which are privacy risks in disguise. Beyond VPNs, a few tools are worth adding to any NZ security stack:
- On-demand malware scanner: A reputable second-opinion scanner for Windows and macOS catches what your main antivirus misses; free tiers cover on-demand scans, with paid tiers adding real-time protection.
- Breach monitoring: Have I Been Pwned, run by security researcher Troy Hunt, is a free service that flags whether your email appears in known data breaches — highly relevant given the volume of credential-stuffing attacks aimed at NZ accounts.
- DNS filtering: Configurable resolvers such as NextDNS work across all your devices, including mobile, and have a usable free tier plus low-cost paid plans.
What to do if you have been attacked
If you suspect a device or account has been compromised, act in this order. First, disconnect the affected device from the network to limit further data theft or spread. Second, change the passwords for critical accounts (email, banking, IRD) from a different, clean device. Third, report the incident to the NCSC — reporting is free and confidential, available online at ncsc.govt.nz/report or by phone on 0800 114 115 (this replaces the former CERT NZ line). Fourth, if the incident involves personal data you hold about others, assess whether you have a notification duty under the Privacy Act 2020 and contact the Office of the Privacy Commissioner if in doubt. Fifth, if any financial account may be involved, contact your bank immediately — NZ banks have dedicated fraud teams — and report the crime to Police via 105.
For ransomware specifically: do not pay the ransom without professional advice. Payment does not guarantee decryption, it funds criminal operations, and it may carry legal risk if the attacker is a sanctioned entity. Engage a reputable incident-response firm — several operate in NZ — before making any decision, and restore from your offline backups where you can.
Sources
- NCSC — Incident reporting analysis 2024/25
- NCSC — Online threats cost New Zealanders
.6 billion in 2024
- NCSC — CERT NZ and NCSC integration now complete
- NCSC — Report a cyber security issue
- Privacy Act 2020, s118 — Offence to fail to notify the Commissioner
- Office of the Privacy Commissioner
- New Zealand Police — Fraud, scam and cybercrime reporting (105)
- Te Whatu Ora — Waikato DHB incident response analysis
- NordVPN — Fifth no-logs assurance assessment (Deloitte, 2024)
Vanliga frågor (FAQ)
Is New Zealand a high-risk target for cyber attacks?
New Zealand is not uniquely targeted compared with other developed nations, but it is far from low-risk. The NCSC recorded almost 6,000 incident reports and NZ$26.9 million in directly reported losses in 2024/25, and high internet penetration, an affluent population and a relatively small cybersecurity workforce make the country an attractive target for financially motivated attackers. Its Five Eyes membership also means NZ infrastructure is of interest to state-level actors.
Does a VPN protect me from cyber attacks?
A VPN protects a specific, limited slice of your attack surface: it encrypts traffic between your device and the VPN server, preventing interception on untrusted networks, and it hides your IP address from the sites you visit. It does not stop phishing, malware you download, weak passwords, unpatched software or attacks aimed directly at your accounts. Treat it as one layer in a broader defence, not a complete solution.
What are my legal obligations if my NZ business suffers a data breach?
Under the Privacy Act 2020, if your organisation experiences a privacy breach that is likely to cause serious harm, you must notify both the Office of the Privacy Commissioner and the affected individuals as soon as reasonably practicable after becoming aware of it. There is no fixed statutory deadline, but you should act without undue delay. Failing to notify when required is an offence with a fine of up to NZ$10,000.
What is SIM swapping and how does it affect NZ users?
SIM swapping is an attack where a criminal convinces your mobile carrier to move your phone number onto a SIM they control. Once they have your number they can intercept SMS-based two-factor codes and take over banking, email and other accounts. NZ carriers have tightened verification, but the attack still happens. The best defences are to use an authenticator app rather than SMS for MFA wherever possible, and to add a PIN or passphrase to your mobile account.
How do I report a cyber attack in New Zealand?
Report incidents to the NCSC online at ncsc.govt.nz/report or by calling 0800 114 115 — this single service now covers everyone from individuals to critical-infrastructure operators, following the integration of the former CERT NZ. If financial fraud is involved, contact your bank immediately and report the crime to Police on 105. If personal data about others has been compromised, consider notifying the Office of the Privacy Commissioner.




