369 serious incidents, and the NCSC’s message to every business leader: prepare for AI now
On 24 September the National Cyber Security Centre released its Cyber Threat Report 2026, covering July 2025 to June 2026. It handled 369 incidents of potential national significance — the serious end, not the everyday phishing email. 86 of them had suspected links to state-sponsored actors, and the NCSC named the People’s Republic of China as the most persistent and capable state actor operating in New Zealand, alongside activity linked to Russia, Iran and North Korea. The targets it listed are worth reading slowly: government agencies, health and education organisations, and IT managed-service providers — the companies that hold the keys to everyone else. China’s foreign ministry rejected the finding.
The criminal side grew too. 162 incidents were tied to criminal or financially motivated actors, up 18% on the year before, and four were rated “highly significant” — as many as in the previous ten years combined. The report also calls out North Korean IT workers landing remote jobs with New Zealand businesses under false identities to earn money for the regime. But the headline the NCSC chose was about AI. Its warning is that the next generation of frontier AI models could automate attacks, find vulnerabilities and personalise targeting, and that those capabilities may be widely in attackers’ hands by early 2027. Readers of Issue 017 have already seen what that looks like: an AI agent swarm through 440 print servers in days.