top of page

Quarter Two Cyber Security Insights 2026: What You Need to Know

Aug 24
4 min read

The National Cyber Security Centre's (NCSC) latest Cyber Security Insights report provides a snapshot of the threats impacting New Zealanders between 1 April and 30 June 2026.

While reported financial losses dropped significantly compared to the previous quarter, cybercriminals continue to evolve their tactics, with malware scams, phishing campaigns, and QR code fraud becoming increasingly prevalent. Meanwhile, the number of incidents requiring specialist technical intervention due to their potential national significance rose notably.

For New Zealand organisations, the findings reinforce a simple reality: cyber security is no longer just an IT responsibility. It is a business resilience issue that requires ongoing investment in people, processes, and technology.


Cyber Security Insights - Key Takeaways

New Zealand's cyber threat landscape remained active throughout Q2 2026, with the NCSC responding to 1,129 cyber security incidents between April and June. While reported financial losses fell by 52% to $2.7 million, the number of incidents requiring specialist support for potential national harm increased by 20%, highlighting a rise in more serious cyber events. Scams, fraud, phishing, credential theft, malware campaigns, and QR code phishing remained major threats, reinforcing the need for organisations to strengthen cyber resilience, employee awareness, and identity security controls.


  • 1,129 cyber incidents reported to the NCSC.

  • Financial losses dropped to $2.7 million, down from $5.6 million in Q1.

  • Scams and fraud were the most common reported incident type.

  • Unauthorised access incidents caused approximately $1.3 million in losses.

  • Malware scams and QR code phishing ("quishing") emerged as growing concerns.

  • Businesses should prioritise MFA, staff training, proactive monitoring, and incident response readiness.


Cyber Security Insights

The Numbers in Detail


Between April and June 2026, the NCSC recorded 1,129 cyber security incidents, slightly down from the 1,164 incidents reported in the first quarter. However, beneath the headline figure lies a more significant trend. The NCSC provided specialist technical support for 92 incidents with potential national significance, representing a 20% increase compared to the previous quarter's 77 incidents.


This suggests that while overall incident volumes remained relatively stable, the complexity and potential impact of some cyber events are increasing.


Financial Losses Decreased, but High-Impact Attacks Remain a Concern


Reported direct financial losses in Q2 2026 totalled $2.7 million, a 52% decrease from the $5.6 million reported in Q1 2026. This is a positive sign, but it does not mean cyber risk is declining.


A key finding in the report is that incidents involving losses of $10,000 or more accounted for 91% of all reported financial losses, even though they represented only 49 incidents. This shows that a relatively small number of successful attacks can have a disproportionate financial impact.


For business leaders, this highlights the importance of preventing high-impact incidents, rather than focusing only on the volume of attacks.


Scams, Fraud, and Phishing Remain the Most Common Threats


Scams and fraud were again the most frequently reported cyber incident category, with 348 incidents recorded during the quarter. Phishing and credential harvesting also remained widespread.


These methods are effective because they target people, not just technology. Cybercriminals often use social engineering to trick users into clicking malicious links, entering login details, or authorising fraudulent transactions.


The NCSC report reinforces the need for businesses to invest in:

  • Security awareness training.

  • Multi-factor authentication (MFA).

  • Email security controls.

  • Regular phishing simulations.

  • Strong password management policies.


These measures remain some of the most effective defences against common cyber attacks.


QR Code Phishing: A Growing Concern

The NCSC also highlighted QR code phishing, sometimes called "quishing." This involves fraudulent QR codes that direct victims to malicious websites designed to steal credentials, payment information, or install malware.


The report noted growing awareness of these scams, including incidents involving fake QR codes on Christchurch parking meters.


As QR codes become more common in workplaces, payments, marketing, and public services, organisations should educate employees and customers about the risks of scanning unknown codes.


Simple precautions include:


  • Verifying the source before scanning a QR code.

  • Checking the URL before entering any credentials.

  • Using trusted payment platforms.

  • Reporting suspicious QR codes immediately.


Understanding the Threat Landscape


Of the 92 incidents that required specialist support, the NCSC determined that:

  • 37% were likely linked to cybercrime actors.

  • 23% were likely linked to state-sponsored actors.

  • 40% could not be conclusively attributed.


This shows that New Zealand organisations face threats from both financially motivated criminals and more advanced nation-state actors. The presence of state-sponsored activity highlights the importance of cyber resilience, particularly for organisations involved in critical infrastructure, government services, health, education, and key commercial sectors.


Key Takeaways and Recommended Actions


The Q2 2026 Cyber Security Insights report shows that while direct financial losses have declined, cybercriminals are refining their methods through malware scams, phishing campaigns, and QR code attacks. At the same time, the rise in nationally significant incidents signals that cyber security is increasingly a strategic issue.


Three actions businesses should prioritise now:


  • Strengthen identity security by implementing multi-factor authentication and privileged access controls.

  • Invest in employee awareness training to protect against phishing, scams, malware, and QR code threats.

  • Improve cyber resilience through proactive monitoring, regular patching, tested backups, and incident response planning.


Cyber security is no longer just an IT concern. It is a business continuity, reputation, and risk management priority. Organisations that build resilience now will be better prepared for the evolving threats of the future.


Wondering how your organisation would stand up against today's cyber threats? Book a Cyber Security Assessment to identify risks, uncover security gaps, and receive practical recommendations to strengthen your cyber resilience.


bottom of page