Quarter Two Cyber Security Insights 2026

An overview of cyber security incidents impacting New Zealanders from 1 April – 30 June 2026.

Computerdudebug Card
Computerdudebug Card

Cyber security incidents recorded by the NCSC in the second quarter of 2026 were similar in number to the previous quarter.   

Between April and June 2026, the NCSC responded to 1,129 incident reports, compared to the 1,164 reports in the first quarter of 2026. 

Of these, 92 incidents were triaged for specialist technical support due to their potential national significance, a 20% increase from the previous quarter (77 incidents). The other 1,037 reports did not require specialist technical support.

Direct financial loss reported during Q2 was $2.7 million, a 52% decrease compared to the previous quarter’s $5.6 million. 

The most common category of incident reported was scams and fraud resulting in a financial loss of approximately $860K, followed by phishing and credential harvesting. Unauthorised access was notably responsible for a reported direct financial loss of $1.3M, roughly half of the total financial loss this quarter. 

This year has seen an increase in the number of New Zealanders reporting that they have been affected by malware scams. This has included incidents where scammers have developed creative schemes in attempts to deceive New Zealanders into downloading malware that steals their personal and sensitive information. In this quarter’s first article we give a rundown on what malware is and provide some examples of recent malware incidents. 

The second article takes a look at a type of scam that featured recently in the media for its use on Christchurch parking meters: QR code phishing. This type of phishing uses fraudulent QR codes to gain access to people’s devices and information. 

Read article: Malware: Silent predators of cyberspace.

Read article: QR codes: Think before you scan. 

The NCSC endeavours to provide the richest possible view of the data available. Where possible, our statistical categories include all incidents. However, due to the way information is collected and processed, for some categories it is not possible for us to include incidents triaged for specialist technical support.

Data highlights

If you are interested in more data, read our Data Landscape section. This provides a standardised set of results, graphs, and an analysis of the latest trends. 

Data Landscape: a closer look at our numbers

Number of incidents

A total of 1,129 incidents were recorded by the NCSC in Q2. 

FrontPage IncidentsPerQ Total

Breakdown by incident category

EventSubCategory Count FP

Direct financial loss

There were 303 incidents reported to the NCSC during Q2 2026 that reported a direct financial loss, and 291 reports that specified the loss amount. 

Direct financial losses totalled $2.7 million in Q2 2026, decreasing by 52% compared to last quarter. 

Frontpage LossPerQ

Incident severity

Of the total reports received:

  • 1 was categorised as C2 – highly significant incidents,
  • 11 were categorised as C3 - significant incidents,
  • 29 were categorised as C4 - moderate incidents,
  • 49 were categorised as C5 - routine incidents,
  • 899 were categorised as C6 - minor incidents,
  • remaining incidents were not categorised.

There were no C1 – national cyber emergencies, this quarter.

Incidents by suspected actors

Where possible, the NCSC links incidents triaged for specialist support to a known actor or activity grouping. Of the 92 such incidents handled by the NCSC in Q2 2026:

  • 23% were assessed to be likely linked to state-sponsored actors,
  • 37% were assessed to be likely linked to cybercrime actors, and
  • 40% did not have enough evidence to link the activity to a known malicious cyber actor.
SEE ALL QUARTERLY REPORTS
Top