#1 Middle East & Africa Trusted Cybersecurity News & Magazine |

31 C
Dubai
Saturday, October 25, 2025
HomeEuropeNCSC Report: 6,779 Cyber Incidents Impact Individuals & SMEs in Aotearoa NZ...

NCSC Report: 6,779 Cyber Incidents Impact Individuals & SMEs in Aotearoa NZ during 2023/24

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

New Zealand’s National Cyber Security Centre (NCSC) recorded 7,122 cyber security incidents between 1 July 2023 and 30 June 2024, with the vast majority-6,779 incidents-targeting individuals and small to medium businesses. These incidents, typically driven by scams, phishing and unauthorized access, highlight persistent threats to personal and organizational security from everyday online activity to critical sector exposure.

In the 2023/24 financial year, the NCSC received 7,122 incident reports. Most 6,779 of them (≈95%)-were handled via its general incident triage process, indicating they did not require advanced technical intervention. These incidents typically affected individuals and SMEs and resulted in US $21.6 million in reported losses. This represents a 12.5% reduction from the previous year (down from 7,744 incidents).

A smaller subset of 343 incidents was escalated for specialist technical support due to potential national significance. Among these, 110 were linked to state-sponsored actors, and 65 appeared financially motivated.

Most Common Incident Types

Scams & Fraud

Accounts for 30% of general triage incidents, making scams and fraud the most prevalent type. Examples include fake investment opportunities and too-good-to-be-true online deals. While technically simple, they rely on users identifying deception.

Phishing & Credential Harvesting

The second-most common incident type 3,455 cases. Although down 31% from last year, this remains prevalent due to its use in enabling unauthorized money transfers, ransomware, and identity theft. Most phishing themes mimic mail/package delivery, government services, banks, or online shopping.

Unauthorized Access

681 incidents of unauthorized access via general triage: 601 affecting individuals and 57 affecting SMEs a decrease of roughly 23% and 27%, respectively. Many reports involved compromised social media accounts used to propagate further scams or malware.

Economic Harm & Victim Impact

Despite fewer incidents, per-incident losses rose from US $14,000 to $25,500. Total individual-reported losses hit $20.1 million, with organizations reporting $1.2 million highlighting the financial toll on vulnerable groups. Investment scam losses quadrupled to $4 million, and losses affecting older adults aged 65+ doubled to $4 million.

MEA & Global Context (Optional Perspective)

Though the report reflects New Zealand’s threat landscape, its insights resonate globally: small organizations and individuals remain frequent targets due to limited cybersecurity maturity. In regions like the Middle East and Africa, similar patterns-scams, phishing, and weak IAM-persist, underscoring the global nature of low-sophistication attacks and the need for basic protective measures.

Expert Insights

“Scams and phishing continue to exploit trust. Without awareness training and basic safeguards, individuals remain soft targets.” – NCSC Officials

“Unauthorized-access incidents decreased but remain significant—especially social-media breaches used to fuel more scams.” – GCSB/NCSC analysts

Actionable Takeaways for Defenders & Executives

  1. Enforce phishing awareness training and simulations.
  2. Require multi-factor authentication (MFA) on all personal and organizational accounts.
  3. Advise clients/customers on recognizing scams involving fake investments or packages.
  4. Implement long, unique passwords and password managers.
  5. Encourage regular backups and incident reporting to cyber authorities.
  6. Promote basic cybersecurity hygiene across SMEs and households.
  7. Monitor unauthorized access alerts—especially social media or email hijacks.
  8. Provide targeted awareness to older demographics, who face rising losses.
  9. Engage incident response services for recovery and identity theft support.
  10. Share community-level guidance (especially in MEA) to raise collective resilience.

Conclusion

Although the frequency of general cyber incidents in New Zealand decreased in 2023/24, financial losses per incident increased notably. The report underscores how scams, phishing, and unauthorized access continue to prey on everyday users and small businesses. Basic safeguards-awareness, MFA, secure passwords-remain the frontline defense. As the global threat landscape grows more complex, cyber resilience starts with defense at the grassroots level.

Sources

  • NCSC Cyber Threat Report 2023/24 – “Incidents usually affecting individuals or small to medium businesses”
  • NCSC “By the numbers” summary
  • NCSC Loss and Harm breakdown
  • Incident specifics on unauthorized access and phishing
  • Management.co.nz editorial summarizing the NCSC report
Ouaissou DEMBELE
Ouaissou DEMBELEhttp://cybercory.com
Ouaissou DEMBELE is a seasoned cybersecurity expert with over 12 years of experience, specializing in purple teaming, governance, risk management, and compliance (GRC). He currently serves as Co-founder & Group CEO of Sainttly Group, a UAE-based conglomerate comprising Saintynet Cybersecurity, Cybercory.com, and CISO Paradise. At Saintynet, where he also acts as General Manager, Ouaissou leads the company’s cybersecurity vision—developing long-term strategies, ensuring regulatory compliance, and guiding clients in identifying and mitigating evolving threats. As CEO, his mission is to empower organizations with resilient, future-ready cybersecurity frameworks while driving innovation, trust, and strategic value across Sainttly Group’s divisions. Before founding Saintynet, Ouaissou held various consulting roles across the MEA region, collaborating with global organizations on security architecture, operations, and compliance programs. He is also an experienced speaker and trainer, frequently sharing his insights at industry conferences and professional events. Ouaissou holds and teaches multiple certifications, including CCNP Security, CEH, CISSP, CISM, CCSP, Security+, ITILv4, PMP, and ISO 27001, in addition to a Master’s Diploma in Network Security (2013). Through his deep expertise and leadership, Ouaissou plays a pivotal role at Cybercory.com as Editor-in-Chief, and remains a trusted advisor to organizations seeking to elevate their cybersecurity posture and resilience in an increasingly complex threat landscape.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img

LEAVE A REPLY

Please enter your comment!
Please enter your name here