New Zealand cyber fraud rises as attackers blend into everyday digital life

Losses through trusted platforms are landing in the grey zone between cyber and crime cover

New Zealand cyber fraud rises as attackers blend into everyday digital life

Cyber

By Roxanne Libatique

New Zealand’s cyber fraud environment is intensifying at both ends of the market – individuals facing a rising tide of online scams, and businesses exposed to attacks that arrive through the platforms and workflows they already trust. Gen’s half-year threat report, published in July 2026, documents the local picture in detail, and the pattern it describes cuts directly to a coverage question the New Zealand insurance market has not yet fully resolved.

The report recorded an 87% rise in e-shop scams in New Zealand during the first half of 2026, alongside a 73% increase in malicious remote access incidents, a 27% rise in tech support scams, and a 45% increase in Scam-Yourself attacks, where users are manipulated into installing harmful software themselves. New Zealand’s National Cyber Security Centre (NCSC) separately recorded $5.6 million in direct financial losses in Q1 2026 alone, a 76% increase on the previous quarter. The government’s Cyber Security Strategy 2026-2030, released by the Department of the Prime Minister and Cabinet (DPMC) in February 2026, estimated New Zealanders are losing approximately $1.6 billion annually to cybercrime, primarily through cyber-enabled fraud.

Fraud through trusted channels: a global pattern with local consequences

Gen’s report identifies a structural shift in how attacks are delivered. Rather than routing victims to obviously suspicious sites, cybercriminals are embedding fraud within services consumers and businesses already rely on – hotel booking systems, messaging applications, software update channels, and online advertising. The same pattern is visible globally: Gen recorded a 387% increase in government impersonation scams and a rise of more than 454% in family impersonation scams, the latter linked in part to abuse of WhatsApp’s linked-device feature to gain persistent account access. More than 304 million scam ad impressions were identified across the EU and UK in less than one month.

Vita Santrucek, chief technology & development officer at Gen, described the challenge this creates for detection. “The most effective attacks in the first half of 2026 didn’t look like attacks. They arrived through booking platforms, family message threads, software update channels, and AI agent workflows, all places people already trust. As attackers blend into everyday digital experiences, protection has to move closer to the moments where confidence is earned, exploited, or broken,” Santrucek said, as reported by Security Brief New Zealand.

The coverage gap this creates

When fraud arrives through a trusted channel, the boundary between a cyber event and a crime event becomes less clear. Coverage for business email compromise (BEC) and funds transfer fraud varies across cyber policies and may be excluded, subject to lower sublimits, or require social engineering or fraudulent funds transfer extensions. This creates an important coverage consideration for sectors such as professional services, legal, and real estate, where payment diversion scams remain a significant source of financial loss. Analysis by law firm Jones Walker notes that the “voluntary parting” exclusion in standard crime and fidelity policies is the primary coverage barrier because coverage typically does not apply when a deceived employee knowingly authorises a transfer, and that social engineering sublimits of $100,000 to $250,000 are increasingly viewed as inadequate for AI-scale losses.

The scale of this exposure in New Zealand is significant. Of the $265 million defrauded from New Zealanders through bank accounts in the 12 months to October 2025, approximately $126 million involved authorised payments where individuals were tricked into approving the transaction themselves, according to Payments NZ data published by MBIE. That category of loss – where no system is technically compromised – is precisely where cyber and crime policy wordings most frequently diverge.

Duncan Morrison, cyber practice leader at Aon New Zealand, has observed the gap between client perception and actual coverage. “Our regulators are nowhere near as punitive as the likes of Australia,” Morrison said, noting New Zealand’s relatively limited enforcement environment creates less pressure for businesses to scrutinise their actual coverage position. New Zealand ranks 49th on the National Cyber Security Index – the lowest of all Five Eyes partners – a baseline that affects both the quality of controls insurers can expect at underwriting and the claims environment that follows. Geordie Stewart, CISO at NSP, addressing an Insurance Brokers Association of New Zealand (IBANZ) webinar on cyber insurance in 2026, identified the underwriting implication: “Having a control isn’t the same as having an effective control. That’s the most common reason cyber claims fail.”

Regulatory backdrop adds compliance cost

The threat data sits within a tightening regulatory environment. The Office of the Privacy Commissioner’s 2025 Annual Report recorded a 27% increase in privacy breach notifications, and Privacy Commissioner Michael Webster has publicly stated the Privacy Act 2020 “doesn’t provide sufficient incentives for many organisations to understand or meet even the most basic privacy requirements.” The Privacy Amendment Act 2025 brought Information Privacy Principle 3A into force on May 1, 2026, requiring organisations to notify individuals when personal information is collected indirectly from third parties, subject to specified exceptions. The change expands organisations’ privacy compliance obligations and may increase the scope of privacy advice and response services required following a cyber incident.

The government’s Anti-Scam Alliance, established by MBIE in July 2025, published its 2026 work programme in June. A cross-sector pilot running from October 2025 to March 2026 detected and blocked more than 23,000 malicious domains, intercepted 3.1 million access attempts, and prevented $23.8 million from reaching scammers. The insurance sector is not yet named in the framework, though the sector-specific code structure it is developing could eventually extend formal obligations more broadly.

Agentic AI: regulatory guidance arrives, policy language has not

Gen’s report identifies agentic AI as an area of emerging risk, with its Sage platform recording high-risk AI agent behaviours including attempts to run system commands, open remote command channels, and read credential files without authorisation. New Zealand’s NCSC, alongside its Five Eyes counterparts, issued joint guidance in May 2026 titled Careful Adoption of Agentic AI Services, warning that autonomous AI tools introduce security and governance risks that differ from traditional software, identifying privilege escalation, insecure tool integrations, and accountability gaps as key concerns.

Kordia’s 2026 Business Cyber Security Report found that attacks exploiting AI-related vulnerabilities more than doubled year on year, and staff misuse of AI is now one of the top three cyber concerns for New Zealand organisations. Gallagher New Zealand has identified AI liability as a potential “silent risk,” drawing parallels with the early evolution of cyber insurance, when cyber-related exposures often sat within traditional policies before insurers clarified coverage through exclusions, endorsements, and standalone products. For underwriters, the combination of NCSC guidance and active regulatory consultation on critical infrastructure signals that the governance framework for AI-enabled systems is moving – and policy language will need to track it.

Gen also reported that globally it blocked 114.2 million e-shop scam attacks, up 109%; 20.3 million tech support scam attacks; and 1 million web skimming attacks, up 212%, along with approximately 1.9 billion tracking attempts in the first half of 2026.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!