Five Cyber Threats: Lessons for NZ Businesses from 2025

A look back at five cyber risks facing NZ businesses in 2025, with practical controls for phishing, ransomware, supplier access and payment fraud.

Five Cyber Threats: Lessons for NZ Businesses from 2025

Illustrative scenario: A staff member at an Auckland accounting firm opens an email that looks like it came from their managing partner. It asks them to pay an urgent invoice before the bank closes. The logo is right, the signature is right, the tone is right. They pay $18,000. The partner never sent it.

This guide looks back at five cyber risks relevant to New Zealand businesses in 2025. It is a practical selection, not an official ranking. The opening example is fictional. The NCSC’s Quarter Three 2025 report describes real financial losses associated with business email compromise.

Updated 9 September 2026 to clarify the historical scope, label the example and add sources.

How phishing puts accounts at risk

Phishing messages try to make a malicious link, login page or payment request look trustworthy. A stolen email password can give an attacker access to business conversations and documents.

Do not rely on spelling mistakes to identify phishing. A message can be well written, reference a real project or copy a supplier’s invoice format. Check the request through a trusted channel before acting.

The defences that work:

  • Multi-factor authentication on every account that supports it, especially email and banking.
  • A verification habit for any payment change. If a supplier emails new bank details, ring them on a number you already have.
  • Reporting that is easy. Staff need a one-click way to flag a suspicious email without feeling silly.

Why ransomware still hurts smaller businesses

Ransomware encrypts your files and demands payment for the key. Smaller businesses can also lose access to essential systems, with disruption that continues while files and services are restored.

What has changed is the model. Many groups now run “double extortion”: they steal a copy of your data before encrypting it, then threaten to publish it if you do not pay. Backups do not undo the disclosure of stolen information. If a privacy breach has caused or is likely to cause serious harm, notification requirements apply. See the Privacy Commissioner’s breach guidance.

Paying is a poor option. There is no guarantee you get your data back, and it marks you as a business that pays. The better position is one where you do not have to choose:

  • Keep at least one backup offline or immutable, so ransomware cannot reach it.
  • Test that you can actually restore from those backups. An untested backup is a guess.
  • Patch quickly. Many ransomware infections start with a known vulnerability that had a fix available for months.

How attackers get in through your suppliers

Supplier access creates another route into business systems. Instead of attacking you directly, the attacker compromises a piece of software you trust, or a vendor that has access to your systems, and rides that trust inside.

A managed software update, a plugin on your website, or a third-party tool with admin access to your network can all become the route in. For a Kiwi SME this is hard to manage alone because you cannot audit every vendor.

Practical steps:

  • Keep an inventory of which third parties have access to your systems and what level of access they hold.
  • Remove access the moment a contract ends or a tool is retired.
  • Ask suppliers, especially IT vendors, how they secure their own environment. A serious provider will answer plainly.

Why business email compromise needs payment controls

Business email compromise (BEC) is the type of scam illustrated at the start of this article: an attacker uses a fake or hijacked email account to trick someone into moving money or changing payment details.

BEC works because it targets people and process rather than technology. There is often no malware to detect. The attacker has simply studied your business, learned who approves payments, and timed the request well.

The controls are mostly procedural:

  • Require two people to approve payments above a set amount.
  • Treat any change to bank details as a red flag that needs phone verification.
  • Lock down email forwarding rules. Attackers often set up quiet auto-forwarding to watch conversations.

The NCSC’s Q3 2025 report says a small number of high-value business email compromise reports drove an increase in reported financial losses that quarter. The report does not measure every incident in New Zealand.

What about weak passwords and unmanaged devices?

The least glamorous threat is often the one that lets everything else happen. Reused passwords, accounts with no MFA, and personal phones or laptops connecting to business data create gaps that attackers scan for constantly.

When staff work from home, from cafes, or from their own devices, the boundary of your business stretches well beyond the office in Wairau Valley or wherever you are based. Each unmanaged device is a small piece of your attack surface.

Sensible baseline controls:

  • A password manager so staff stop reusing the same three passwords everywhere.
  • MFA enforced as policy, not left to individual choice.
  • Device management that lets you wipe a lost or stolen phone remotely and confirm that laptops are encrypted and patched.

Pulling it together

Start with controls appropriate to your systems and the information you hold. Phishing, ransomware, supply chain risk, business email compromise, and weak account hygiene all respond to the same handful of disciplines: MFA everywhere, tested backups, fast patching, a payment verification habit, and knowing which devices and vendors touch your data.

The hard part is doing these consistently while you also run the business. That is where a managed IT partner earns its keep, by making good security the default rather than a project you keep meaning to start.

If you would like a clear picture of where your business stands against these threats, talk to the team at iT360. We work with SMEs across New Zealand and can tell you plainly what is worth doing first.

For help applying these controls, explore our cyber security services.

Make the plan real

Get a technology partner who can help execute.

See our cyber security services

Book a free consultation