New Zealand names China its most persistent state-backed cyber threat
New Zealand's NCSC says China is the most persistent and capable state-backed cyber actor targeting the country, with 86 of 369 significant incidents showing suspected state links.
New Zealand's cyber security agency has identified China as the most persistent and capable state-backed actor conducting cyber activity against the country, according to its annual threat assessment.
The National Cyber Security Centre (NCSC), which sits within New Zealand's intelligence community, said it had traced activity suspected to originate from foreign state actors that placed sensitive national information at risk. Alongside China, the report linked suspected state-sponsored operations to actors from Russia, Iran and North Korea.
"Of these nations the People's Republic of China is the most persistent and capable state actor undertaking cyber activity in New Zealand," the assessment stated.
The finding adds to a series of warnings from Western-aligned intelligence agencies about alleged Chinese cyber espionage, allegations Beijing has consistently rejected. It follows an August report from New Zealand's security agency describing China as the only country detected conducting espionage in the country "at scale."
According to the cyber threat report, 86 of 369 incidents judged to be of potential national significance in the year to June 2026 had suspected links to state-sponsored actors. Those incidents included activity aimed at government agencies, health and education organisations, and IT managed-service providers.
The NCSC cautioned that geopolitical rivalry is increasingly being played out in the South Pacific, where it said it was aware of state-backed cyber espionage directed at governments and infrastructure. New Zealand maintains close family, cultural, political and economic ties across the region, and such activity could affect its citizens, businesses and civic institutions, it said.
State-backed actors are likely to prioritise organisations that run infrastructure or networks, deliver essential public services, or hold information capable of conferring a strategic advantage, the agency added.
It also warned that cyber espionage is often hard to detect, with intruders carrying out reconnaissance and establishing access within systems over months or years before using it to gather intelligence or cause disruption. Prolonged intrusions of this kind could compromise operational technology and lead to the loss of corporate and personal data, the NCSC said.