NCSC Q2 2026
- Katarzyna Celińska

- 2 days ago
- 2 min read
The latest New Zealand NCSC Cyber Security Insights – Q2 2026 report is another good example of why I like reading threat reports from different countries.
The geography may be different, but many of the patterns are very familiar.
Between April and June 2026, the NCSC responded to 1,129 cyber incident reports, compared with 1,164 in Q1. So overall volume remained relatively stable.

Photo: pvproductions na Magnific
92 incidents required specialist technical support because of their potential national significance, up from 77 in the previous quarter. That is roughly a 20% increase. In other words: fewer headlines in total, but more cases with potentially serious impact. Cybersecurity incidents become more complex.
The incident categories also repeat patterns seen in many other reports.
➡️ The most common category was scams and fraud, with 348 incidents and around NZD 860,000 in reported losses.
➡️ The second most common category was phishing and credential harvesting.
For me, these two categories should be interpreted differently.
➡️ Scams and fraud are usually the monetisation stage itself. The objective is direct financial gain: steal money, manipulate a payment, abuse an identity or deceive the victim.
➡️ Phishing and credential harvesting, on the other hand, are often only the beginning.
Stolen credentials may become the initial access point for:
➡️ ransomware,
➡️ business email compromise,
➡️ data theft,
➡️ espionage,
➡️ persistent access,
➡️ even penetration of critical infrastructure.
Credential compromise is often the prelude to a much larger offensive operation.
Another interesting point is the financial-loss profile.
Reported direct losses fell to NZD 2.7 million, down 52% from Q1. But 49 incidents with losses above NZD 10,000 accounted for NZD 2.4 million, 91% of the total reported loss. Unauthorized access alone was linked to approximately NZD 1.3 million, close to half of all losses in the quarter. It shows that a relatively small number of successful incidents can generate disproportionate financial damage.
What is also worth watching is attribution among the 92 more serious incidents:
➡️ 23% were assessed as likely linked to state-sponsored actors,
➡️ 37% to cybercrime actors,
➡️ 40% could not be linked with sufficient confidence.
Author: Sebastian Burgemejster



Comments