INTERPOL has released its Asia and South Pacific Cyber Threat Assessment Report 2025/2026, drawing on survey responses from 18 member countries, private-sector data and intelligence from INTERPOL's own Asia and South Pacific Desk (ASP Desk).

While New Zealand is not separately profiled in the report, the trends it documents are directly relevant to a country embedded in the wider Asia-Pacific digital and financial system.
The headline numbers
More than half of surveyed countries reported that cybercrime now makes up over 30 percent of all recorded crime nationally. A third reported over 10,000 online scam cases each, and half reported financial losses exceeding US$10,000, with several over US$100 million.
Distributed Denial-of-Service (DDoS) attacks surged 92 percent, with government websites targeted around election periods and financial institutions later in the year.
As for New Zealand
The global trends on losses and severity of attack are mirrored at home, less so the number of incident reports being received.
According to the National Cyber Security Centre’s (NCSC) Q1, 2026 Cyber Security Insights Report, cyber security incidents had higher losses and higher severity though slightly fewer were reported. Direct financial loss reported during Q1 was $5.6 million, a 76% increase compared to the previous quarter’s $3.2 million. Individuals accounted for $5.2 million in direct financial loss, and organisations for approximately $340,000.

Direct Financial Losses by quarter Q2 2024 to Q1 2026
Three incidents were categorised as C2 (‘highly significant’). C2 category incidents impact key sensitive data or cause disruption to essential New Zealand services in organisations of national significance. The three C2 incidents in Q1 impacted thousands of New Zealanders with sensitive data being accessed.
Where possible, the NCSC links incidents triaged for specialist support to a known actor or activity grouping. Of the 77 such incidents handled by the NCSC in Q1 2026:
- 17% were assessed to be likely linked to state-sponsored actors,
- 52% were assessed to be likely linked to cybercrime actors, and
- 31% did not have enough evidence to link the activity to a known malicious cyber actor.
Scams are industrialised
The Interpol report explained that whilst online scams and phishing remain at the top of the list of cybercrime types by volume, what has changed is scale and organisation. Transnational crime groups in Cambodia, Lao PDR, Myanmar, and the Philippines have built large scam centres that INTERPOL says generate close to US$40 billion a year through romance scams, fake investment schemes, and illegal online gambling.
This issue was also identified in a 2024 UNODC Convergence report which noted that “While cyber-enabled fraud continues to expand and poses growing challenges, the region is witnessing a major convergence of different crime types and criminal services. Rapidly shifting advancements in physical, technological, and digital infrastructure have allowed organized crime networks to expand these operations.
Casinos, hotels, Special Economic Zones (SEZs), and other business parks and property developments across the region have become hubs for the booming illicit economy.” Some of these venues are serving as operation bases for transnational criminal groups to conduct other criminal activities including drug production and trafficking, illegal gambling, trafficking in persons for forced criminality, prostitution, pornography, and money laundering operations.”
Human trafficking
This is a governance and human-rights story as much as a technology one. Many of these operations rely on forced labour - people trafficked or deceived into working the scam floors themselves.
A February 2026 report by the Office of the United Nations High Commissioner for Human Rights (OHCHR) estimates that the scam workforce is at least 300,000 people originating from 66 countries, particularly from within Asia.
Data theft is pervasive
Infostealer malware designed to quietly harvest credentials, banking details, and personal data was flagged as the second-highest volume cybercrime type. “Infostealer" malware like RedLine, LummaC2, and Lokibot were found operating in numerous countries across the region, feeding stolen data into dark web marketplaces that fuel identity theft and account takeovers,
LummaC2 (Lumma Stealer) is reported as a primary infostealer at work in NZ right now, it typically impacts Windows devices, aiming to steal sensitive information like email addresses and passwords, with some stolen passwords connected to government agency systems and bank accounts.
In December 2025, NZ's National Cyber Security Centre emailed around 26,000 New Zealanders to notify them their devices may be affected by Lumma Stealer.
A widening gap across the Pacific
The Interpol report is candid that cybersecurity maturity varies sharply across the region. Smaller Pacific states and developing countries face real shortages in forensic tools, technical training, and legislative frameworks, making them both direct targets and unwitting gateways for wider criminal networks. Two-thirds of surveyed law enforcement agencies have adopted AI tools for detection and investigation, but a third have not. (See our other article on Pacific).
What are NZ agencies doing?
While New Zealand is a contributing partner to threat assessments and intelligence gathering, it is not as clear about the extent of New Zealand agencies involvement in INTERPOL’s Operation First Light 2026 early this year.This operation targeted social engineering scams and associated money laundering, resulting in over 5,800 arrests, US$ 293 million intercepted, and roughly 142,000 identified victims across nearly 100 countries.
INTERPOL and regional law enforcement have also focused on infrastructure-level disruption, taking down more than 20,000 malicious IP addresses and domains tied to infostealer malware campaigns across Asia-Pacific.
Domestic Efforts: The NZ Anti‑Scam Alliance
New Zealand’s primary domestic coordination mechanism for scam prevention and disruption is the NZ Anti‑Scam Alliance, established to coordinate a response system across government agencies and relevant businesses including banks, telcos, Google and Meta..
Conclusion
The INTERPOL assessment and other reports are clear that cybercrime in the Asia–Pacific region is a highly organised, industrialised ecosystem spanning scam centres, human trafficking, infostealer malware markets, and cross‑border financial networks. New Zealand is not immune to these dynamics. The NCSC’s Q1 data shows rising losses, increasing severity, and continued exposure to both cybercrime groups and state‑linked actors.
Against this backdrop, New Zealand’s participation in regional intelligence sharing, global takedown operations, and domestic coordination is an essential element of responding to the scale and pace of criminal activity.
