The cybersecurity threat landscape in 2026 looks materially different from even two years ago. AI has accelerated attack timelines, criminal groups have professionalised their operations, and the attack surface for the average NZ business has expanded significantly with cloud adoption and remote work. Understanding what is actually trending — not just theoretical risks — is the starting point for allocating your security investment intelligently.
Here are the 10 trends shaping what NZ businesses face right now.
1. AI-Accelerated Ransomware
Ransomware is not new. What is new in 2026 is the speed at which attacks move from initial access to full encryption. AI tools are being used by ransomware affiliates to automate lateral movement, identify the most valuable targets within a network, and time detonation for maximum impact. Where a ransomware dwell time of 5-10 days was typical two years ago, attacks are now moving to detonation in under 24 hours in many documented cases.
The practical implication: detection and response programmes designed around a multi-day dwell time are no longer sufficient. NZ businesses need to assume that initial access and full compromise may be separated by hours, not days.
2. Initial Access Brokers as Infrastructure
Criminal specialisation has created an ecosystem where gaining access and exploiting that access are separate, professional operations. Initial access brokers (IABs) compromise organisations — through unpatched vulnerabilities, phishing, or credential stuffing — and sell verified access to ransomware affiliates. The IAB model means that a vulnerability in your internet-facing systems may be exploited for profit by an attacker who has no intention of attacking you directly.
This is why critical vulnerability patching timelines matter so acutely. An unpatched system is not just a risk to you — it is inventory in a commercial marketplace.
3. Microsoft 365 and SharePoint Exploitation
CISA confirmed in July 2026 that threat actors are actively exploiting multiple critical Microsoft SharePoint and Microsoft 365 vulnerabilities in real-world attacks. Microsoft environments are targeted at volume because of their ubiquity. A single successful compromise of a Microsoft 365 tenant can provide access to email, files, Teams messages, and authentication tokens for every connected service.
NZ businesses using Microsoft 365 should prioritise: MFA on all accounts, conditional access policies that block legacy authentication protocols, and immediate patching of on-premises SharePoint instances if applicable.
4. WordPress and CMS Supply Chain Attacks
Two trends are converging in the CMS space. First, critical vulnerabilities in WordPress core itself — including CVE-2026-63030, an unauthenticated remote code execution flaw disclosed in July 2026 — are being actively exploited within hours of public disclosure. Second, supply chain attacks through compromised WordPress plugins and themes allow attackers to inject malicious code into thousands of sites simultaneously.
For NZ businesses running WordPress sites: auto-update plugins, remove unused plugins immediately, and treat your CMS as a security-critical system requiring the same patching discipline as your internal infrastructure.
5. Credential Stuffing at Scale
Leaked credential databases now contain over 13 billion username and password combinations. Automated tools allow attackers to test these credentials against hundreds of services simultaneously. The majority fail. The ones that succeed — because an employee reused a password from a breached site — give attackers authenticated access without any exploitation required.
Every NZ employee who reuses a personal account password for their work Microsoft 365, VPN, or cloud application login is a credential stuffing risk vector. MFA eliminates the risk from stolen passwords. Without it, your exposure is proportional to your employees' password hygiene across every account they have ever created.
6. AI-Generated Phishing and Social Engineering
The quality ceiling on phishing content has collapsed. AI tools allow attackers to generate grammatically correct, contextually appropriate phishing emails in fluent New Zealand English at volume and at near-zero cost. The spelling mistakes and awkward phrasing that staff were trained to look for are no longer reliable indicators of a phishing attempt.
More sophisticated AI-assisted attacks are also enabling deepfake voice and video fraud, where attackers impersonate executives or finance contacts to authorise fraudulent payments. This is not theoretical — CERT NZ has received reports of deepfake-assisted business email compromise attempts targeting NZ organisations. See our post on deepfake CEO fraud targeting NZ businesses for how these attacks work.
7. Supply Chain and Third-Party Risk
Attackers increasingly target the supply chain rather than their ultimate target directly. A software vendor, managed service provider, or SaaS platform with access to multiple organisations is a force-multiplier target — compromise one, access many. The MOVEit, 3CX, and SolarWinds attacks established this pattern. It has continued in 2026 with attacks against IT management and remote access tools used by MSPs serving NZ businesses.
Understanding which of your suppliers have privileged access to your systems or data — and what security controls they operate — is now a baseline security obligation, not an advanced practice.
8. Cloud Misconfiguration as the New Perimeter Failure
As NZ businesses have moved workloads to AWS, Azure, and Google Cloud, misconfiguration has replaced unpatched software as the most common cause of cloud security incidents. Publicly accessible S3 buckets, overly permissive IAM roles, and storage accounts with no access controls continue to expose sensitive data at a rate that patching and penetration testing do not address.
Cloud security requires a different discipline from traditional infrastructure security. The controls are available — the gap is in configuration and ongoing review, not in the platforms themselves.
9. Ransomware Shifting to Data Extortion
Ransomware groups are increasingly skipping encryption entirely in favour of pure data extortion. The model: exfiltrate sensitive data, threaten to publish it unless a ransom is paid, and make clear that even paying does not guarantee deletion. This shift matters because it changes the risk calculus for backups. A robust backup strategy eliminates the leverage in traditional file-encrypting ransomware. It does not eliminate the leverage in data theft extortion.
NZ businesses holding customer personal information under the Privacy Act 2020 face additional exposure — a data breach notification obligation on top of the extortion pressure.
10. Human Layer Attacks Remain the Entry Point
Despite all the technical sophistication in the 2026 threat landscape, the most common initial access vector across documented attacks remains the same: a human clicking something they should not have. Phishing, social engineering, and credential misuse account for the majority of breach entry points in every credible survey of incident data.
This is not an argument against technical controls — it is an argument for investing in the human layer alongside them. Staff who understand how attacks work, recognise social engineering attempts, and know how to report suspicious activity are a meaningful defensive layer. Staff who have never received security training are a reliable attack surface.
Start building your human security layer with SecureAZ awareness training