New Zealand’s National Cyber Security Centre has warned businesses and organisational leaders that artificial intelligence is changing the cyber threat environment, making attacks faster, more scalable and potentially more personalised.
How Is AI Changing Cyber Threats?
The NCSC said the cyber risk environment is already under growing pressure from cybercriminal groups and state-backed actors, and artificial intelligence could further increase the speed, scale and sophistication of malicious activity.
The agency warned that AI could allow attackers to automate attacks, identify vulnerabilities and tailor targeting more closely to organisations and individuals.
Catriona Robinson, Head of the National Cyber Security Centre, said cyber security was no longer simply an IT consideration for New Zealand businesses and organisations, but an issue requiring the attention of senior management and boards.
She said the established combination of cybercrime and espionage risks was now being altered by another factor: artificial intelligence.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
Are Criminals Already Using AI?
The NCSC said AI is already part of a criminal toolkit. It pointed to more convincing phishing campaigns, scams and social engineering attacks as examples of how AI is lowering barriers for attackers and increasing the credibility of fraudulent approaches.
The agency warned that AI provides malicious actors with opportunities to increase the speed, scale and sophistication of cyberattacks.
It said future generations of AI models could automate attacks, identify vulnerabilities and enable highly personalised targeting of organisations and individuals.
The warning also extends beyond today’s most advanced AI models. As development accelerates, tools that are currently limited to leading frontier models could become available to malicious actors by early 2027, the NCSC said.
How Serious Are New Zealand’s Cyber Incidents?
The NCSC said it handled 369 incidents of potential national significance during 2025-26, a 16.2% increase compared with the previous year.
Four of those incidents were classified as C2, or Highly Significant. The agency said that figure matched the total number of incidents at that level recorded over the previous 10 years combined.
Robinson said the severity of incidents had increased.
The NCSC linked this development to a broader change in the economics and organisation of cybercrime. Cybercriminals are becoming more persistent and aggressive in pursuing payment through extortion and data theft, it said.
The agency also warned that attacks cause harm beyond the immediate financial loss to businesses. New Zealanders whose personal information is stolen may also become victims of other criminal activity.
What New Risk Has the NCSC Identified?
The threat assessment also highlighted concerns involving North Korean operatives seeking remote information technology employment.
The NCSC said it had encountered the threat of a North Korean IT worker clandestinely obtaining remote work with a New Zealand business to earn foreign currency for the North Korean state.
Such activity creates both compliance and security concerns, the agency said. The cases fall under United Nations sanctions against North Korea and may also create espionage and extortion risks for targeted businesses.
Can Basic Cybersecurity Still Stop AI-Enabled Attacks?
Despite the emergence of AI-driven risks, the NCSC said the strongest protection remains basic cyber security measures.
The agency stressed that businesses should maintain both human-led and AI-enabled threat defences.
It also said organisations must regularly update their cyber security fundamentals rather than assume AI requires an entirely separate approach to protection.
The warning suggests that while AI may increase the capabilities available to attackers, weaknesses in basic security practices can still provide the openings criminals need.
What Should Boards and Senior Leaders Do?
The NCSC said cyber security is a governance issue and that responsibility for it rests at the top of an organisation, particularly when decisions involve budgets, staffing and operational priorities.
Boards, chief executives and senior leaders should consider whether their businesses have the people, processes and resources required to respond to a faster-moving cyber threat environment.
The agency said preparing for every possible cyber threat is difficult, making preparation by individual leaders particularly important as AI becomes more central to the threat landscape.
“Government cannot protect every organisation from every cyber threat,” Robinson said.
The NCSC said leaders remain responsible for cyber security within their organisations, and those preparing now will be better positioned to manage the challenges associated with frontier AI.
The420 Insight
The warning shows that AI is not creating an entirely separate category of cybercrime, but is increasing what attackers can do with familiar techniques such as phishing, social engineering, vulnerability discovery and targeted attacks.
For organisations, the key takeaway is that adopting advanced security technology alone is not enough. Strong cyber security fundamentals, clear responsibility at board level, adequate resources and preparation for increasingly automated attacks remain central to managing the emerging risk.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics