Whakataunga 3 Judgement 3

Cybercrime and extortion are escalating in severity

Kei te kino haere kē atu te taihara ipurangi me te mure

In the twelve months to June 2026, New Zealand experienced more high-impact cybercriminal activity than in the past five years. This activity included high-profile attacks on health service providers and tertiary institutions.

Of the 369 cyber incidents of potential national significance reported to the National Cyber Security Centre (NCSC), 162 had links to criminal or financially motivated actors, a jump of 18% over the previous year.  Of these cyber incidents, four were classified C2, or highly significant, the first cybercrime incidents of this severity for five years. High profile incidents include the theft of over 99,000 patient records from the Manage My Health patient portal, and the breach of the Canvas learning management system used by some of New Zealand’s largest educational institutions. 

While some cyber attacks are complex, most common cybercrime could be prevented if businesses and organisations took simple actions to protect credentials and identify data, using tools such as multi-factor authentication, long strong passwords, passkeys and software allow lists.

Why does this matter?

Cybercrime has a significant impact on individuals, businesses and organisations. The impact includes direct financial costs to businesses, the theft of private and sensitive information, financial scams and espionage.

For individuals the theft of sensitive personal information, such as health records, legal or financial information or identity data, can be distressing. Once stolen this information is often resold by cybercriminals, creating a long tail of risk for individuals. 

For businesses and organisations, a cyber attack can have significant impacts including disruption of operations, a loss of trust among customers and clients, investigations by regulators and financial impacts from loss of business. Containing and remediating cyber attacks can be costly in both financial terms and in the impact on staff.

Cybercrime has major impacts on New Zealanders
  • In December 2025 the NCSC contacted 26,000 New Zealanders to warn them their credentials had been stolen by a malware known as Lumma Stealer, a credential stealing tool linked by open-source assessments to criminals operating in Russia. 
  • In February 2026 the operation of many aged care facilities, hospices and community pharmacies was disrupted when the medication management platform MediMap was hacked. The attackers altered some patient records, and normal medication distribution was disrupted while the system was offline.
  • In May 2026 the Canvas learning management system, used by some of New Zealand’s major tertiary education providers, was breached in a supply chain attack. It is estimated that data and identity information was stolen from between 110,000 and 120,000 students and staff. 

Why is cybercrime on the increase?

The cybercrime landscape is dynamic and responds quickly to changes in technology, enforcement and economic incentives.

Cybercrime is now an industrialised, global industry in which advanced malware and tools are available for purchase or rent as a service and are sometimes customised to exploit the vulnerabilities of particular targets. Some cybercriminals are using sophisticated tools to plan and orchestrate attacks thereby reducing the effort expended on individual exploits.

Cybercriminals are becoming more capable and considered in their efforts to evade detection. Some of the capabilities and techniques being utilised make it challenging for the victim to identify what has been stolen and by whom.

Cybercriminals have become more aggressive in their pursuit of monetary payment, via ransoms or extortion. The tactics include:

  • Targeting individuals
  • Increased harassment of potential victims
  • Increased focus on theft and exposure of highly sensitive information (such as health, legal or insurance records)
  • Greater focus on victims with a low tolerance for disruption, such as infrastructure or health service providers.

Case study 2: Malware-as-a-Service

Lumma Stealer
In December 2025 the NCSC alerted over 26,000 New Zealanders that their devices had been infected with malware known as Lumma Stealer which is designed to steal sensitive information like passwords and login details for online accounts. 

Monitoring threats

In a constantly developing threat landscape, businesses may wish to consider the use of tools or services that monitor areas where breached data may exist. These places may include the dark web, known hacking or online forums, and communication or channels such as Telegram and WhatsApp. For most businesses having an external cyber-security supplier will be the most cost- effective way to provide visibility of threats and inform their approach to cyber defence.

Cybercriminals operate internationally, sometimes in coordination with states 

Cybercrime is an international enterprise. Attacks targeting New Zealanders can originate from almost anywhere on the globe, and stolen data will be sold internationally for use in future attacks, by criminal or state-affiliated actors. 

While most cybercriminal activity is financially motivated there is evidence that state actors enable and support cybercriminals, and use data stolen by criminals for other state purposes. For example, the individuals or group behind Lumma Stealer are Russian in origin, and their tools have been used by criminal groups affiliated with both Russia and the People’s Republic of China.

Data and credential theft - a growing focus for cybercriminals

Theft of data and credentials is becoming more common as cybercriminals seek to extort ransoms from organisations and individuals. The more personal or sensitive the information the more likely an organisation or individual will pay a ransom. This explains the focus of cybercriminals on organisations in the health services sector holding highly personal information. 

Because stolen data may contain sensitive personal or business information it can be monetised in several ways including immediate attempts to extort a ransom or sale to another actor for use in targeting or accessing victims.

Credentials are less valuable individually but are sold on global markets in large numbers where they can be purchased and reused by other cybercriminals or state actors leading to cascading harm to individuals or organisations.

The payment of ransoms does not guarantee the recovery of data or the destruction of stolen information. An international survey of 5,750 businesses by UK insurer Hiscox Ltd indicates that approximately 40% of victims who paid a ransom fail to recover data and approximately 80% of organisations that paid ransoms were attacked again, often by the same attacker or a related group.

Artificial Intelligence is part of the cybercrime toolkit 

Attackers are beginning to leverage Artificial Intelligence (AI) in combination with social engineering to create threats that are increasingly difficult to detect and remove. 

State actors and cybercriminals are already using AI to develop more authentic phishing messages and scams, undertake more effective reconnaissance of targets, and increase the volume and scale of attacks.  

In 2025, we have seen the emergence of AI-powered malware: code that can make simple decisions without human oversight. This new breed of programmes can adapt automatically to new security environments, avoid detection by rewriting sections of their own code, and choose their own target when an opportunity presents itself. 

Implications for organisations

The impact of cyber attacks on businesses and organisations can be severe including longterm damage to customer trust and business reputation, disruption of services and direct costs to remediate and restore systems.

Three questions leaders should be asking

  1. Have we ensured that access credentials are secure and well managed? 
  2. Is our software patching up to date, and known vulnerabilities addressed? 
  3. Do we have the management and business continuity systems in place to manage a cyber attack?

How do cybercriminals target New Zealanders?

Cybercrime affects New Zealand in multiple ways. These are some of the most common: 

  • Extortion. Cybercriminals extort money from individuals or businesses, usually by demanding money to avoid the leaking of sensitive information. Other methods include encrypting user data or systems and demanding money to restore the system. 
  • Credential theft. Credentials are stolen from a user or business, and then the criminal monetises through extortion, and often the resale of the credentials. The reuse of stolen credentials is common and can lead to further attacks. 
  • Scams. Cybercriminals trick the victim into sending money, sharing sensitive information, or purchasing a bogus product or service. These scams often rely on the use of stolen credentials or social engineering techniques such as seemingly authentic messages to deceive the victim.

Case study 3: Manage My Health

In late December 2025 a cybercriminal gained access to the Manage My Health (MMH) Patient Portal Web App, using a valid user’s credentials (username and password). These credentials had been stolen through a malware infection known as Lumma Stealer.

Resources

For further information, refer to the following guidance:

Key cyber security terms and their definitions can be found in our glossary:

Top