In a significant geopolitical statement, New Zealand's National Cyber Security Centre (NCSC) has officially named the People's Republic of China as the primary state-sponsored cyber threat facing the country. The NCSC's annual Cyber Threat Report, covering the year to June 2026, states that China is the "most persistent and capable state actor" conducting cyber operations against New Zealand's interests. The report links state-sponsored actors to 86 of 369 nationally significant cyber incidents, highlighting a sustained campaign of espionage targeting critical sectors and national information.
The NCSC, part of New Zealand's intelligence apparatus, has observed a consistent pattern of cyber espionage targeting a broad range of organizations. The primary goal of these campaigns appears to be intelligence gathering, with threat actors establishing long-term, stealthy access to networks. This allows them to conduct reconnaissance and exfiltrate data over months or years before being detected.
The report also noted cyber activities linked to Iran, North Korea, and Russia, but singled out China for the scale and sophistication of its operations. This aligns with previous assessments from New Zealand's security agencies and reflects a growing trend of geopolitical competition playing out in cyberspace, particularly in the South Pacific region.
The TTPs associated with state-sponsored espionage groups like those attributed to China are typically characterized by a "low-and-slow" approach, prioritizing stealth over speed. Analyst assessment suggests the following MITRE ATT&CK techniques are relevant:
T1593 - Search Open Websites/Domains) to identify key personnel and infrastructure.T1566.001 - Spearphishing Attachment) and exploitation of public-facing applications (T1190 - Exploit Public-Facing Application) are common entry vectors.T1543.003 - Windows Service) or using scheduled tasks (T1053.005 - Scheduled Task), to ensure long-term access even if one method is discovered.T1003 - OS Credential Dumping) are used to harvest credentials for lateral movement.T1041 - Exfiltrate Data to C2).The primary impact of this state-sponsored activity is the long-term strategic loss for New Zealand. The theft of sensitive government information, intellectual property, and personal data can undermine national security, economic competitiveness, and diplomatic relationships. By targeting critical sectors like healthcare and IT service providers, these actors can also gain access to vast amounts of data and potentially disrupt essential services. The targeting of infrastructure in the wider South Pacific region indicates a broader effort to gain geopolitical influence.
The report identifies a wide array of targeted sectors within New Zealand, including:
This broad targeting demonstrates an intent to gather intelligence across all facets of New Zealand's society and economy.
Detecting advanced persistent threats (APTs) requires a mature security program:
D3-UBA - User Behavior Analysis to detect anomalous account activity, such as logins at unusual times or from strange locations, which could indicate a compromised account.Defending against well-resourced state actors requires a robust, defense-in-depth approach:
M1021 - Restrict Web-Based Content).M1030 - Network Segmentation).M1026 - Privileged Account Management).M1047 - Audit).Implement comprehensive logging and regular auditing to detect stealthy, long-term malicious activity.
Segment networks to contain breaches and prevent lateral movement from less sensitive to more sensitive systems.
Mapped D3FEND Techniques:
Strictly control and monitor privileged accounts to limit an attacker's ability to escalate privileges and move through the network.
Mapped D3FEND Techniques:
Use endpoint detection and response (EDR) and user behavior analytics (UBA) to identify anomalous activity indicative of an APT.
Mapped D3FEND Techniques:
New Zealand's NCSC releases its annual Cyber Threat Report for the year ending June 2026.
Media outlets begin reporting on the NCSC's findings regarding state-sponsored threats.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.