sign up log in
Want to go ad-free? Find out how, here.

AI supercharging cyber attacks as NZ's political parties briefed ahead of election

Technology / news
AI supercharging cyber attacks as NZ's political parties briefed ahead of election
Head of the National Cyber Security Centre (NCSC) Catriona Robinson.
Head of the National Cyber Security Centre (NCSC) Catriona Robinson. Image source: Mandy Te

New Zealand's political parties are receiving briefings on AI-powered cyber threats ahead of the election, as the country's latest cyber security report warns that advanced AI tools, currently limited to leading frontier models, could be in the hands of malicious actors as soon as early 2027.

The Cyber Threat Report 2026, released on Thursday, says AI tools already in the hands of malicious actors are being used to increase the "speed and scale of cyber attacks, create deep-fakes, execute targeted phishing attacks, and undertake reconnaissance at scale."

It comes as Australia PM Anthony Albanese reported an AI agent hacked into the country's Medicare data portal, accessing some files that were not public, with OpenAI taking three months to admit the breach, the ABC reported

Catriona Robinson, Deputy Director General Cyber Security, who leads the National Cyber Security Centre (NCSC), which sits in the Government Communications Security Bureau (GCSB), said two major differences in this year's report were that artificial intelligence (AI) was rapidly reshaping the cyber landscape, and social engineering remained a persistent threat.

"Social engineering - it means trying to take advantage of humans' natural propensity to trust other humans... impersonating a trusted person, using emotional language or messages, trying to pressure victims to take action. Scams and frauds is where we see it a lot, but also constructing really valid-looking emails to persuade you to click on links, or constructing deep fake videos or voice messages, those kinds of things."

The NCSC report said the trajectory of AI development is such that, by early 2027, malicious actors may have access to advanced AI capabilities currently available only through leading frontier AI models.

"The threat to businesses and organisations is real. There will be incidents and disruptions, potentially with little warning. The time to prepare your defences is now."

Robinson said AI gives cybercriminals and other malicious actors "new tools in order to persuade and manipulate and deceive people", but it also meant that there were more emerging tools to find and fix vulnerabilities fast.

Electoral risk

On the potential for attacks to hit political parties ahead of the election, Robinson said they were "certainly aware that that risk exists for sure."

"We have been over the past eight or 12 weeks, [been] briefing all of the leaders of the political parties, all of those who are polling about 5% at least, on the cybersecurity landscape, what AI could do... if their websites got taken over, for example, or their messaging got hijacked by somebody, and then we've provided bespoke advice for some individuals, for example, the ones who went to Taiwan recently, about how to keep themselves safe online as well."

State sponsored attacks 

Almost a quarter (23%) of cyber incidents that were deemed potentially of national significance in the last year were linked to suspected state-sponsored actors.

"There is a concerning trend by state actors toward more aggressive and assertive activity in cyberspace. This is evidenced by the targeting of critical infrastructure such as energy and telecommunications networks, transport networks, water and financial systems," the report said.

The agency linked incidents to suspected state-sponsored actors from the People’s Republic of China, Russian Federation, Islamic Republic of Iran and the Democratic People’s Republic of Korea (North Korea).

Robinson said they assessed China was "the most capable and the most persistent country targeting us."

"It's certainly not the only country that's targeting us, but it is definitely the most capable."

The report said cyber security controls controls were the best defence against attacks. 

"One of the things we've discovered is that the tools work way better with a human actively involved with them," Robinson said. 

"So when we were looking for vulnerabilities in code using these tools, it was two to three times more effective when we had a human guiding its work than if we just left it to do open discovery. So for me, what that means is humans, will be massively amplified by using these tools, but actually the tools are better when used with humans as well."

The report recommended organisations review cyber security controls. 

That included: 

- Reduce your attack surface: Limit unnecessary system access and external connectivity. Challenge
whether systems need to be exposed at all and isolate those that do not.
- Accelerate patching processes: AI is shortening the time between vulnerability discovery and
exploitation. Delays in patching increase risk, especially for operational systems with long update cycles. Prioritise security updates to manage risks.
- Address legacy systems: Unsupported systems are easy targets. They don’t just represent technical
debt, they are strategic liabilities. Ensure assets nearing the end of their supportable life are replaced.
- Review and strengthen identity and access controls: Limit who can access critical systems. Enforce
strong authentication and regularly review permissions.
- Prepare for incidents before they happen: Test response plans, train and prepare teams, and assume breaches will occur. Focus on fast containment and recovery.

We welcome your comments below. If you are not already registered, please register to comment

Remember we welcome robust, respectful and insightful debate. We don't welcome abusive or defamatory comments and will de-register those repeatedly making such comments. Our current comment policy is here.