Summary
- Cyber security incidents rose by 25% in Q1 since the same quarter in 2020, CERT NZ reported.
- Nearly 23% of the breaches resulted in direct financial losses.
- About 500 vulnerable Microsoft Exchange email servers were found in Q1.
As per a new quarterly report from NZ government’s cybersecurity agency CERT NZ, there were 1,431 cyber security incidents in Q1 of 2021, up by 25% YOY, but a 32% decline on Q4 of 2020.
Phishing and credential harvesting were the most reported incident category (making 46% of all incident reports in Q1 2021), followed by scams and fraud.

Source: Copyright © 2021 Kalkine Media
Here’s a look at the incident categories that have risen or fallen in Q1 of 2021 when compared to the previous quarter:
- There was a 24% drop in phishing and credential harvesting in this quarter as compared to Q4 2020.
- Reports about unauthorised access rose 18% in Q1 this year compared to Q4 2020.
- There was a 94% decline in malware from Q4 2020, due to international agencies successfully dismantling the Emotet malware infrastructure.
Rob Pope, the director of CERT New Zealand, stated that attackers were continuously inventing new and more sophisticated operations as more time was spent online. He added that was the prime reason why that was critical to practice excellent cyber hygiene. Applying updates, having a lengthy, strong password, and utilising two-factor authentication can help.
ALSO READ: Did Kiwi Cloud Storage Firm Fall Victim To Malware Attackers?
The agency revealed that about 23% of reports made to the cyber security agency resulted in a financial loss of $3 million, up by 7% from Q4 of 2020. The most susceptible Kiwis are those aged 45 to 54 and 55 to 64, with overall monetary losses increasing by 175% and 196%, respectively.
Email servers being targeted, vaccine scams
CERT NZ found over 500 vulnerable Microsoft Exchange email servers and more than 100 hacked email servers during the quarter. The bulk of the infected mail servers belonged to small enterprises, while a few large corporations were also affected.
DO READ: RBNZ Publishes Results of Data Breach Review
ALSO READ: Cyber-attacks on the rise in Australia as cyber criminals spare no sector
The attackers took advantage of 4 newly found Microsoft Exchange susceptibilities to gain access to the Microsoft Exchange Server. The agency recommended applying latest security updates for that particular version of Microsoft Exchange and alter passwords related to Microsoft servers.
Cyber attackers are opportunistic and are constantly evolving their campaigns to trick people into sharing their personal information. COVID-19 vaccine scams are one of the areas that may increase in the future.
CERT NZ responded to less than 10 reports about COVID-19 vaccine-related scams in the quarter, but the volume of scams is likely to increase and vary in look and message content.
ALSO READ: COVID-19 Vaccine Development: A Glance at the Latest Updates around the World
The agency urged Kiwis to be ware and now, since the coronavirus vaccine is free, Kiwis will not be asked to pay for the vaccine or for jumping the queue to get an early vaccination.