Cyber Attacks Explained: The Eight Types That Hit New Zealand Businesses

Cyber attacks are deliberate attempts to steal data, disrupt systems, or take money from a business. Eight types account for nearly all attacks on New Zealand SMEs: phishing, ransomware, credential theft, business email compromise, insider threats, supply chain breaches, exploitation of unpatched systems, and denial of service.

Cyber attacks: flat vector of eight arrows approaching a business network, most deflected by a layered defence barrier.

On a Tuesday afternoon your accounts administrator opens an email from a supplier you have used for six years. Same signature, same tone, correct invoice number. The bank account is different. She pays it, because nothing about it looks wrong.

There was no virus and no breached firewall, and nobody did anything obviously careless. The cyber attacks that take the most money off New Zealand businesses tend to look like ordinary Tuesday admin, and the other seven types of cyber attacks in this guide are much the same.

New Zealand’s National Cyber Security Centre logged 1,164 cyber security incidents in the first three months of 2026, and phishing and credential harvesting made up 437 of them, more than any other category. Those reports come from businesses of every size, because the entry points barely change between a 25-person firm and a large organisation.

Reviewing the quarter’s three most serious incidents, NCSC Chief Operating Officer Mike Jagusch was direct about the cause. Basic measures such as multi-factor authentication, managing who has full access to the network, and protecting the network edges “could have helped to defend against these incidents”. Those three were the most severe New Zealand has seen since the 2021/22 financial year, and they struck organisations of national significance. The controls that would have blunted them are the same ones a South Island business can switch on this month.

This guide covers the eight types of cyber attacks that matter to New Zealand businesses, what they cost in practice, and which doors to shut first.

What Are Cyber Attacks and How Do They Actually Work?

Cyber attacks work in four stages: reconnaissance, initial access, escalation, and payoff. Attackers scan for exposed systems, get in using a stolen password or a clicked link, hunt for administrator rights, then encrypt your files or redirect a payment.

Cyber attack chain: flat vector of reconnaissance, initial access, escalation, and payoff, with controls breaking the chain.

In plain terms: someone works out who your staff are and what systems you run, they obtain one set of login details, they use those details to reach further than that account should allow, and then they take something.

Reconnaissance in most cyber attacks is cheap and constant. Attackers harvest staff names from LinkedIn, check whether your email domain has weak sender protections, and look for anything reachable from the internet. None of it requires skill or a target list.

Most of the damage happens at escalation. A single compromised laptop is a nuisance you can rebuild over a weekend. If the account signed into it holds administrator rights, the attacker reaches payroll, client files, and the backups as well.

Blocking every attempt at stage one is unrealistic, and you do not need to. Breaking the chain at any stage stops the payoff, which is the argument for several overlapping controls instead of one product.

Is a Cyber Attack the Same as a Data Breach?

A cyber attack is the attempt to get in. A data breach is one possible result of that attempt, where personal or confidential information is accessed or disclosed without authorisation.

The distinction matters because only one of them triggers a legal duty. Cyber attacks that never reach personal information carry no notification obligation, while a breach involving personal information brings the Privacy Act 2020 into play. Plenty of attacks cause serious downtime without ever becoming a notifiable breach.

Are Cyber Attacks Automated or Targeted?

Cyber attacks are both automated and targeted, and the mix has shifted towards automation. Scanning tools find exposed systems within hours of them going online, so small businesses get discovered without anyone choosing them specifically.

Targeted attacks follow for anything that looks profitable. Law firms, real estate agencies, and any business handling large transfers get individual attention because the payoff justifies the effort.

How Has AI Changed Cyber Attacks?

AI has made reconnaissance and social engineering faster and cheaper. The NCSC has warned that frontier AI models let attackers find and exploit weaknesses at unprecedented speed and scale, while noting the same models can assist defence and that the best preparation remains getting the basic measures in place.

The warning signs people were taught to watch for have mostly gone. Phishing emails now use correct grammar, accurate company detail, and a plausible reason to hurry. The old advice about spotting typos no longer applies.

Why Do Cyber Attacks Hit Smaller New Zealand Businesses Hardest?

Attackers concentrate on smaller New Zealand businesses because a 25-person firm with no dedicated security staff is faster and cheaper to break into than an enterprise with a security team on shift around the clock. Automation has made the smaller payoff worth chasing.

Four patterns explain most of the exposure we see across Canterbury and Otago.

Nobody Is Watching Overnight

Attackers time their move for when nobody is looking. Encryption often starts on a Friday evening or over a public holiday, which hands them the whole weekend.

With no monitoring in place, you find out when the first person opens a laptop on Monday and nothing loads. By then the encryption has finished and recovery runs into days. Monitoring picks up the same event within minutes, while it is still confined to one machine, and you are usually trading again the same morning.

Security Sits Outside the Annual Plan

Patching schedules, backup testing, and access reviews rarely make the annual planning agenda until something breaks. Growth and hiring take the available attention, and security renewals often lapse without anyone noticing.

One unpatched machine is enough to get an attacker inside. It only needs to be reachable from the internet and running software with a publicly known weakness for automated tooling to find it, usually within days of that weakness being published.

Training Wears Off Faster Than People Expect

Staff who have never seen a convincing fake invoice have no reference point for spotting one. Induction-only training fades within a few months, and the techniques change faster than that.

Ongoing security awareness training works when it runs continuously and includes simulated phishing, so you can see whether click rates are actually falling. A programme with no measurement tells you nothing about whether your team improved.

Tools Get Adopted Without IT Knowing

Staff sign up for file-sharing apps, AI assistants, and project tools to get work done. Those accounts sit outside your security controls, often with reused passwords and no multi-factor protection.

This is shadow IT, and it widens your exposure to cyber attacks without anyone ever formally deciding to accept the extra risk.

What Are the Eight Most Common Types of Cyber Attacks?

The eight most common types of cyber attacks are phishing and credential harvesting, ransomware, credential theft and account takeover, business email compromise, insider threats, supply chain breaches, exploitation of unpatched systems, and denial of service. Phishing leads by a wide margin in New Zealand, with 437 reported incidents in the first three months of 2026.

Types of cyber attacks: flat vector grid showing phishing, ransomware, credential theft, and five other attack types.

Real incidents usually combine several of these cyber attacks. A phishing email harvests a password, the password enables account takeover, the mailbox is then used for business email compromise, and ransomware arrives last if the attacker finds nothing easier to monetise. Stop the phishing email and the rest of that chain never happens.

1. Phishing and Credential Harvesting

Phishing is a fake message designed to make you enter your login details on a page the attacker controls. It remains the single most reported category in New Zealand.

Modern versions clone your Microsoft 365 sign-in page precisely and can relay your multi-factor code in real time. Our guide to phishing scams covers the current techniques in detail.

2. Ransomware

Ransomware encrypts your files and demands payment for the key. Staff arrive, nothing opens, and a text file on the desktop sets out the terms.

Attackers now steal a copy of the data before encrypting it, so refusing to pay still carries a threat of publication. Restoring from backup no longer settles it on its own.

Paying does not reliably return your data, and it marks the business as willing to pay again. The dependable answer is backups you have tested, held in a form that cannot be altered or deleted even by someone holding your administrator password. Several ransomware myths still lead owners to the wrong conclusion here.

3. Credential Theft and Account Takeover

Credential theft uses a valid username and password to log in as a legitimate user. Nothing looks wrong from the inside, which is why this activity often runs for weeks before anyone notices.

There is usually no alert to miss. The attacker reads email, sets a mailbox rule to forward a copy of every invoice, and waits for something worth intercepting.

Passwords reach attackers through phishing, reuse across breached third-party sites, and malware on home devices. Enforcing multi-factor authentication on every account blocks the overwhelming majority of these attempts, and phishing-resistant methods such as passkeys close most of what is left.

4. Business Email Compromise

Business email compromise is a scam in which an attacker impersonates a supplier, executive, or colleague to redirect a genuine payment into their own account. No malicious software is involved, so email filters frequently miss it.

A typical sequence runs like this. The attacker gains access to a mailbox and watches it without touching anything. They wait for an invoice discussion to begin. Then they send updated bank details from a lookalike domain, timed to arrive when the payment is expected.

Verifying every change of bank account by phone, on a number you already hold, stops nearly all of it. It costs nothing and needs no software. Any business can start doing it this week.

5. Insider Threats

Not all cyber attacks come from outside. Insider threats come from people who already have legitimate access, and most are careless. A staff member emails a client list to a personal address before resigning, without thinking of it as theft.

Access reviews and offboarding discipline do most of the work here. Our guide to insider threats sets out the practical controls.

6. Supply Chain and Third-Party Breaches

Supply chain cyber attacks reach you through a supplier, software vendor, or IT provider you trust. Compromising one vendor gives attackers a route into every customer that vendor serves.

Ask your key suppliers what controls they hold and how quickly they would tell you about a breach. Contracts with your most critical vendors should state those notification timeframes explicitly, and any provider with administrative access to your systems should be able to answer without hesitation.

7. Exploitation of Unpatched Systems

Exploitation targets known weaknesses in software you have not updated. Once a vulnerability becomes public, automated scanning finds exposed systems within days.

Priority goes to anything sitting where your network meets the internet: firewalls, VPN appliances, remote access gateways, and web servers. The NCSC specifically cited protection of those network edges as a factor in the serious incidents it handled this year.

8. Denial of Service

Denial of service floods your systems or internet connection with traffic until legitimate users cannot get through. You lose trading hours instead of data, and an online store that cannot take orders for six hours has still lost six hours of orders.

Extortion demands sometimes accompany these cyber attacks, with a threat to keep the flood running until payment arrives. Any business taking orders, bookings, or payments online should confirm what mitigation against these cyber attacks its hosting and internet providers already include, because most include some and few businesses know which.

What Do Cyber Attacks Actually Cost a New Zealand Business?

Cyber attacks caused NZ$5.6 million in directly reported losses in New Zealand in the first three months of 2026, up 76% on the previous quarter, although individuals accounted for NZ$5.2 million of that total. Despite the quarterly rise, the figure sits below the average of the past two years.

Cost of cyber attacks: flat vector showing reported direct loss above the line with downtime and recovery costs below.

Do not read too much comfort into it. The figure captures only what was reported to the NCSC, and reporting is voluntary, so plenty of businesses go to their insurer or the Police instead. It also excludes downtime and recovery costs, which are usually the larger part of the bill for a business.

Look at how the losses cluster. Just 42 incidents of NZ$10,000 or more accounted for 97% of all reported losses that quarter, so the realistic outcomes are a minor nuisance or a very expensive month.

How Should You Estimate Your Own Exposure?

Estimate the cost of cyber attacks to your business by starting with your own downtime, because that is the number a national total cannot give you. Work out what one day of not trading costs in wages, lost orders, and delayed invoicing.

Multiply that by three, since three days is a realistic recovery window for a business restoring from backup after ransomware. Then add forensic investigation, legal advice on notification, hardware replacement, and the overtime needed to catch up.

Most businesses forget to count the fortnight afterwards, when staff are rebuilding records and chasing confirmations instead of serving customers. For most Canterbury and Otago firms we assess, the full total lands well above several years of the preventative spend that would have avoided it.

What Are Your Legal Obligations After a Breach?

Under the Privacy Act 2020, you must notify the Office of the Privacy Commissioner and affected individuals of any privacy breach that has caused or is likely to cause serious harm. The Commissioner expects notification as soon as you are practically able, and has indicated an expectation of within 72 hours of establishing that a breach is notifiable.

Failing to notify the Privacy Commissioner without reasonable excuse is an offence under section 118 of the Privacy Act 2020, carrying a fine of up to $10,000, alongside the possibility of a public compliance notice. Our guide to NZ Privacy Act cybersecurity explains the controls the Act expects you to have in place.

How Do Cyber Attacks Affect Customer Trust?

Reputational damage from cyber attacks lasts longer than the technical recovery. Clients who receive a breach notification about their own personal information will ask what changed afterwards.

Clients who hear a clear answer about what changed generally stay. Vague reassurance costs you some of them at renewal.

Does Cyber Insurance Cover the Loss?

Cyber insurance covers a defined portion of the cost, commonly including incident response, forensic work, and business interruption. Coverage depends entirely on the policy wording.

Underwriters now ask detailed questions about controls before quoting. Missing multi-factor authentication or endpoint detection can reduce a payout or invalidate cover, so work through the questionnaire before you need to and fix whatever you cannot answer yes to.

How Do You Prevent Cyber Attacks Without a Big IT Budget?

You can prevent most cyber attacks with three inexpensive controls: multi-factor authentication on every account, automated patching of anything facing the internet, and backups you have actually tested. The NCSC named these same basics as the gap in New Zealand’s most serious incidents this year, so work through the following list in order.

  1. Enforce multi-factor authentication on email, remote access, and any cloud application holding customer data. This single control blocks the largest share of cyber attacks for the least cost.
  2. Patch internet-facing systems within days and everything else within a month. Automate it so it does not depend on someone remembering.
  3. Follow the 3-2-1-1 rule for backups: three copies, two media types, one offsite, one offline or unable to be altered. Restore something every quarter, because an untested backup has a real failure rate and you want to discover that on a quiet Tuesday.
  4. Restrict administrator rights to the people who genuinely need them, and use separate accounts for admin work. Many attacks fail at the escalation stage when admin rights are scarce.
  5. Deploy endpoint detection and response on every device, including laptops that leave the office. Cyber insurers increasingly expect it as a condition of cover.
  6. Verify every payment detail change by phone using a number you already hold. This one procedural rule defeats most business email compromise.
  7. Run continuous awareness training with simulated phishing, and track whether click rates fall.

You do not need a large team for any of this. Put one person’s name against each control, set a recurring reminder, and check every quarter that they are all still switched on.

Which Cyber Attacks Should You Defend Against First?

For most New Zealand SMEs, the four cyber attacks to defend against first are credential theft, phishing, business email compromise, and ransomware. These four combine high likelihood with high cost, and they sit ahead of the threats that get the most media coverage.

Weighting shifts with the business. A Christchurch professional services firm holding client financial data should weight credential theft and business email compromise heavily. A manufacturer running production systems should weight ransomware and unpatched systems higher, because downtime halts output immediately. An online retailer needs denial of service mitigation that a purely office-based firm can reasonably skip.

A cyber security assessment works this out for your specific operation. It maps which types of cyber attacks actually threaten you, identifies which controls you already hold, and produces a costed order of work.

How Often Should the Priorities Be Reviewed?

An annual review suits most SMEs, with an extra review after any significant change. New systems, new premises, an acquisition, or a shift to more remote working all alter the exposure.

Reviewing after an incident matters just as much, including near misses. If one staff member reported a phishing email and another clicked it, run the next training round on that team.

What Are the Warning Signs of a Cyber Attack?

Most cyber attacks show up first as small operational oddities, not as an obvious alarm. The warning signs worth acting on the same day are:

  • Staff locked out of an account that worked yesterday, with no password change on record
  • Colleagues or clients receiving emails from your address that nobody sent
  • Mailbox rules or forwarding addresses that nobody in the business created
  • Multi-factor prompts arriving on a phone when that person is not logging in
  • Shared drives or line-of-business software slowing down sharply without a known cause
  • New user accounts, or existing accounts suddenly holding administrator rights
  • Antivirus or endpoint software switched off or reporting that it cannot update

Any one of these has an innocent explanation. Two or three in the same week rarely do.

How Long Do Attacks Go Unnoticed?

Credential-based cyber attacks commonly run for weeks before detection, because a valid login raises no alarm. Ransomware is the exception, since it announces itself the moment encryption finishes.

That gap between entry and discovery is the argument for monitoring. It is also why the mailbox rule check is worth doing today rather than after something goes wrong.

How Should Your Cyber Attack Response Work in the First Hour?

An effective cyber attack response starts with containment. In the first hour, disconnect affected devices from the network without powering them off, call your IT provider, reset passwords and revoke active sessions on any account involved, and start a written timeline. Leaving devices powered on preserves evidence held in memory.

People routinely skip revoking active sessions. A password change on its own does not end a session the attacker is already inside, so they carry on working while you think the door is shut. The other easy one to forget is checking whether personal information was involved, because that starts the Privacy Act clock.

Deciding all of this while the phones are ringing rarely goes well. A documented incident response plan assigns each step to a named person in advance, and a current data backup strategy gives you the option to restore. Our Christchurch and Dunedin teams both hold after-hours contacts for exactly this reason.

How Does a Managed IT Partner Reduce the Risk of Cyber Attacks?

A managed IT partner reduces cyber attack risk by running patching, backup verification, monitoring, and access reviews to a fixed schedule instead of whenever someone finds spare time. Every one of those controls slips when it competes with other priorities.

Exodesk has supported South Island businesses since 1989, from offices in Christchurch and Dunedin. Our cyber security services cover monitoring, patch management, endpoint detection, backup testing, and staff training as one managed programme, with a local team that can be on site when something needs hands on it.

What Should You Expect From a Provider?

Expect specifics, in writing. A provider should tell you which devices carry endpoint detection, when the last backup restore was tested and whether it succeeded, how quickly critical patches get applied, and who to call outside business hours.

Ask what happens during an active incident as well. Response time commitments, escalation paths, and whether the provider carries its own cyber liability cover all matter during live cyber attacks, even if they seem like small print during a sales conversation. Any provider holding administrative access to your systems is part of your supply chain risk, so their internal controls deserve the same scrutiny you would apply to your own.

Close the Eight Doors Before Someone Tries Them

Most of the eight types of cyber attacks described here are stopped by controls you can put in place this quarter, not by a project that takes a year and a new budget line.

If you are not certain that multi-factor authentication is enforced on every account, start there this week. The second call to make is finding out whether your last backup restore actually worked.

Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.

Frequently Asked Questions

What are the most common types of cyber attacks on New Zealand businesses?

Phishing and credential harvesting top the list. The NCSC recorded 437 phishing and credential harvesting incidents in the first three months of 2026, more than any other category. Ransomware, account takeover, and business email compromise follow closely for small and medium firms.

How many cyber security incidents happen in New Zealand each quarter?

The National Cyber Security Centre responded to 1,164 incidents between January and March 2026. Of those, 77 required specialist technical support and three were classified as highly significant, the first incidents of that severity since the 2021/22 financial year.

Do hackers target small businesses in New Zealand?

Small and medium businesses are targeted heavily because they are cheaper to break into for a similar payoff. Automated scanning finds exposed systems regardless of company size, and most cyber attacks on smaller firms go undetected for longer because nobody is employed to watch for them.

What is business email compromise and how is it different from phishing?

Business email compromise is a scam in which an attacker impersonates a supplier, executive, or colleague to redirect a genuine payment into their own bank account. Phishing, by contrast, aims to capture login credentials. Business email compromise usually involves no malicious software at all, which is why email filters often fail to catch it.

Does multi-factor authentication stop cyber attacks on its own?

Multi-factor authentication blocks the overwhelming majority of password-based attacks but does not stop every one. Attackers can relay codes in real time or fatigue users into approving prompts. Phishing-resistant methods such as passkeys or hardware security keys close that remaining gap.

Should a business ever pay a ransomware demand?

Ransom payment is discouraged by New Zealand government guidance. Payment does not reliably restore data and identifies the business as willing to pay again. Tested offline backups and a documented recovery plan let a business decline the demand.

What is the correct cyber attack response in the first hour?

The first step is containment. Disconnect affected devices from the network without powering them off, contact your IT provider, reset credentials and revoke active sessions, then begin a written timeline. Preserving evidence matters for both insurance claims and any report to the Privacy Commissioner.

Do cyber attacks have to be reported in New Zealand?

Notification is required under the Privacy Act 2020 when a privacy breach has caused or is likely to cause serious harm. The Privacy Commissioner and affected individuals must be told as soon as you are practically able, with the Commissioner indicating an expectation of within 72 hours. Failing to notify the Commissioner without reasonable excuse carries a fine of up to $10,000.

How much does it cost to protect a small business against cyber attacks?

Protection costs depend on staff numbers and existing systems, though the three highest-value controls are inexpensive. Multi-factor authentication, automated patching, and tested backups typically cost less than a single day of unplanned downtime. A cyber security assessment establishes the specific figure for your setup.

How does Exodesk help protect against cyber attacks?

Exodesk delivers monitoring, patch management, endpoint detection, backup verification, and staff awareness training as one managed service. Teams in Christchurch and Dunedin support businesses across the South Island, with on-site response available when remote work is not enough.

Start typing and press Enter to search

Secure passwords shown as a strong padlock built from unrelated shapes, representing length and unpredictabilityManaged firewall: flat vector of an internet connection passing through a maintained gateway into a business network. Call Us Now