State actors and their enablers are undertaking malicious cyber activity against New Zealand. The techniques they use are sophisticated and persistent, targeting both government and private sector organisations.
State actors are motivated by national priorities which may include diplomatic or military advantage, economic interests or suppression of dissent. In New Zealand the primary focus of state activity has been espionage, but internationally our partners have identified state actors using cyber tools to undertake intimidation, intellectual property theft, the disruption of networks and critical services, and in some cases, sabotage.
Changing strategic context
State-sponsored cyber activity is happening in the context of a changing threat environment driven by geostrategic competition, conflict and international tensions. In this environment the use of cyber as an offensive tool, or the threat of its employment, can be a mechanism states deploy when faced with a worsening political climate or a deterioration of international relations.
There is a concerning trend by state actors toward more aggressive and assertive activity in cyberspace. This is evidenced by the targeting of critical infrastructure such as energy and telecommunications networks, transport networks, water and financial systems. Actions such as the pre-positioning of offensive cyber capabilities on target systems or limited demonstrations of an attack capability, can be used as a deterrent, and if undetected can limit the warning time to identify and prevent a disruptive attack.
Taken together these actions are challenging the norms of responsible state behaviour in cyberspace. We anticipate that these trends are likely to continue, with AI enabling a significant increase in the volume of these types of operations. This trajectory is likely to create a more volatile and unpredictable environment during periods of conflict.
Why does this matter?
State-sponsored espionage against New Zealand government agencies, businesses and other organisations is a significant risk to our economy, long term security, and ability to shape the world toward our preference for a rules-based international system. Our location and distance from areas of conflict does not make New Zealand immune to the cascading impacts of cyber attacks. In a highly connected world, a cyber attack elsewhere could create direct or compounding impacts such as disruption of telecommunications and transport networks, interruption to supply chains (physical and digital), and the compromise of sensitive information.
The New Zealand and global context
In the past year the National Cyber Security Centre (NCSC) has identified activity, suspected of originating from foreign state actors, targeting New Zealand government agencies, organisations in the health and education sectors, and information technology managed service providers. The NCSC believes these incidents have exposed sensitive New Zealand information to risk. The NCSC has also joined other nations in identifying state-sponsored activity that targets critical national infrastructure.
Twenty three percent (23%) of the incidents of potential national significance dealt with in the 2025/26 year had suspected state-sponsored links. The NCSC has linked activity to suspected statesponsored actors from the People’s Republic of China, Russian Federation, Islamic Republic of Iran and the Democratic People’s Republic of Korea (North Korea). Of these nations the People’s Republic of China (PRC) is the most persistent and capable state actor undertaking cyber activity in New Zealand.
In April 2026 New Zealand joined nine other countries to warn against the large-scale use by China-affiliated actors of covert networks of compromised devices such as home routers to hide their malicious activity. Also known as ‘botnets’, these networks enable malicious activity at scale and have been used by PRC affiliated groups known as Volt Typhoon and Flax Typhoon to target infrastructure networks.
In December 2025 New Zealand joined thirteen other nations and the European Union to warn against attacks on US and global critical infrastructure by pro-Russian hacktivist groups with links to the Russian state. These attacks target water and wastewater, energy and food and agriculture organisations.
In August 2025 New Zealand joined twelve other nations in identifying a campaign of malicious cyber activity being undertaken by a PRC state-sponsored group known as Salt Typhoon. The campaign targeted telecommunications, transport and government networks globally by using publicly known vulnerabilities and exposures in networks and edge devices to undertake espionage including the harvesting of data, phone calls, credentials and network information. Salt Typhoon activity was observed in New Zealand.
The Pacific
Increasing geo-strategic competition is being seen in the South Pacific where we are aware of statesponsored cyber espionage targeting governments and infrastructure.
New Zealand is a Pacific country with family, cultural, political and economic links to South Pacific nations with whom we share a common interest in fostering regional stability and peace. It is concerning to see Pacific nations being targeted in ways that could impact citizens, businesses and civic institutions.
Tools and techniques
State-sponsored actors use a wide range of tools to achieve their objectives, and they constantly refine their techniques so their activity is difficult to detect and defend against. While some statesponsored activity can be defended against in the same way as other malicious cyber activity, at the extreme end of the spectrum state actors have access to tools and resources beyond the capability of most network defenders to detect and defend, even with third party support.
There are known links between state actors and cybercriminal networks, with an exchange of tools, information and techniques. For example, credentials stolen as part of a criminal exploit may be purchased or transferred to a state actor who then uses them to undertake espionage or other malicious activity. State actors are also known to use criminal groups as proxies to obfuscate their activities and avoid direct state-level retaliation or international sanctions.
Example: Russia-linked attack on Polish energy infrastructure
On December 29, 2025, a cyber actor undertook a coordinated attack on Polish energy infrastructure, targeting renewable energy systems including windfarms, solar farms and combined energy power plant supplying around 500,000 consumers.
Implications for organisations
A wide range of New Zealand businesses and organisations are potential targets for state-sponsored cyber espionage or other malicious cyber activity. These include businesses or organisations that operate infrastructure or networks, provide essential services to the public, or hold sensitive information that could provide strategic advantage.
State actors are stealthy and play the long game. Malicious activity can include reconnaissance of systems and the pre-positioning of cyber assets for the purposes of espionage or disruption. The compromise of sensitive information through long-term espionage efforts that are undetected for months or years can have real harm such as compromise of operational technology and the loss of corporate and personal information.
However, even the most sophisticated actors can be foiled by good solid controls. Organisations and businesses, particularly in the infrastructure or network sectors, should regularly review their cyber security settings and be familiar with advice provided by the NCSC on how to identify and tackle counterespionage and state-sponsored activity.
Questions leaders should be asking:
- Have we considered the risk of intrusion by a sophisticated actor, and the actions we would take to defend against or mitigate such an attack?
- Are we confident we can detect unusual activity in our environments, including persistent activity over long time frame?
- Can we identify our mission-critical information assets that need
to be protected against statesponsored threats? - Have we reviewed our critical controls recently to understand where we need to put effort to prevent intrusions or compromise of our systems?
Advisories
China-Nexus covert networks - April 2026
In April 2026 the National Cyber Security Centre joined industry and international partners to advise on how to defend against multiple covert networks which have been created and are being constantly updated by Chinese cyber actors.
Pro-Russia hacktivists conduct opportunistic attacks against US and global critical infrastructure - December 2025
In December 2025 the NCSC joined international partners in identifying pro-Russia hacktivist groups conducting cyber operations against numerous organizations and critical infrastructure sectors worldwide. Among the increasing number of groups, some appear to have associations with the Russian state through direct or indirect support.
Salt Typhoon – August 2025
In August 2025 the NCSC joined international partners in drawing global attention to a campaign of malicious activity being undertaken by PRC state-sponsored cyber threat actors targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks.
Resources
For further information, refer to the following guidance:
- New Zealand Information Security Manual External Link
- Government Information Security Framework and Policies External Link
Key cyber security terms and their definitions can be found in our glossary:
Case Study 1: North Korean IT workers in New Zealand
During the year a large New Zealand business became suspicious of the identity details of an IT contractor working remotely.