New Zealand’s National Cyber Security Centre (NCSC) has warned organisations and employees about the risks of using work accounts and devices for personal activity, following a rise in phishing and credential theft incidents. In its Quarter Four 2025 Cyber Security Insights report, the agency said cyber criminals continue to exploit weak account practices and poor separation between professional and personal digital activity.
The report, published on 12 March 2026 by the National Cyber Security Centre, covers the period from 1 October to 31 December 2025. During that quarter, the agency responded to 1,131 incident reports, with phishing and credential harvesting accounting for 34% of reports submitted by organisations through the general triage process.
Credential reuse remains a significant security risk
NCSC Chief Operating Officer Mike Jagusch said the reuse of work email addresses and passwords for personal online services can create serious security vulnerabilities for organisations. According to the report, threat actors can exploit credentials exposed in unrelated data breaches to gain access to workplace systems and email accounts.
“Using a work email address or password for personal reasons may not seem like a big deal, but the consequences can be far-reaching to both you and your organisation.” Mike Jagusch, Chief Operating Officer, National Cyber Security Centre
The agency said compromised credentials can allow attackers to conduct phishing campaigns, social engineering attacks, ransomware operations and financial fraud. The report highlights that even a single exposed account may provide a pathway into broader organisational systems if adequate security controls are not in place.
Of the 90 incidents escalated for specialist technical support because of their potential national significance, 51% were assessed as likely linked to cybercrime actors. The figures underline the continued operational burden placed on public and private sector organisations responding to increasingly sophisticated cyber threats.
Concerns over unauthorised workplace technology use
The report also draws attention to the growing risks associated with so-called ‘shadow IT’, where staff use unapproved digital tools or services outside organisational oversight. Examples include forwarding work emails to personal accounts or storing official documents in private cloud storage platforms.
“Shadow IT includes things like forwarding work emails to a personal account or storing business documents in a private cloud account.” Mike Jagusch, Chief Operating Officer, National Cyber Security Centre
According to the NCSC, organisations may be unable to apply appropriate safeguards when they are unaware of how staff are handling information or accessing systems. This can increase the likelihood of data leakage, privacy breaches and legal or regulatory complications.
The agency advised organisations to strengthen internal cyber security policies and ensure staff understand approved processes for handling work information. The report also emphasises the importance of regular staff training to improve awareness of phishing tactics, credential protection and safe online behaviour.
Financial losses decline despite ongoing scam activity
Scams and fraud remained the most commonly reported incident category among individuals, accounting for 46% of personal reports received by the agency. However, the number of reported incidents fell slightly from 446 cases in the third quarter to 432 in the fourth quarter.
The report also recorded a significant decline in direct financial losses. Reported losses totalled NZ$3.2 million (approximately US$1.9 million) during the quarter, representing a 75% decrease compared with the previous reporting period.
Despite the overall decline, higher-value incidents continued to account for the majority of financial harm. Incidents involving losses of NZ$10,000 or more (approximately US$5,900) represented NZ$2.9 million (approximately US$1.7 million), or 93% of total reported losses, while comprising only 39 individual incidents.
Mr Jagusch said organisations should encourage employees to apply cyber security awareness not only in the workplace but also in their personal digital lives. The NCSC argues that stronger individual cyber hygiene practices can help reduce broader organisational and national cyber risks.
This article is created with the assistance of OpenGov AI.