A North Korean operative posing as a remote IT contractor was unknowingly hired by a New Zealand business using a fake identity and a local recruit to receive and operate the company’s laptop.
The ruse was part of a global operation in which North Korean workers secure jobs with overseas companies, generating hundreds of millions of dollars for the regime’s nuclear weapons and missile programmes.
“During the year a large New Zealand business became suspicious of the identity details of an IT contractor working remotely,” according to the National Cyber Security Centre’s (NCSC) Cyber Threat Report 2026.
The business, which is not identified in the report, contacted the NCSC and New Zealand Police, with investigators determining the worker was from North Korea.
“The IT workers use identity masking technology to hide their North Korean identity when securing contracts for remote work,” the report said.
The National Cyber Security Centre is warning of foreign interference and how powerful AI could supercharge cyber criminals. (Source: Breakfast)
Investigators found the worker had used a New Zealand address and recruited a New Zealand citizen.
After the contract was terminated, the worker claimed to have obtained commercially sensitive information and threatened to release it unless they were paid.
The case mirrored so-called “laptop farm” schemes uncovered globally, where local intermediaries receive and operate company-issued devices on behalf of North Korean workers, helping disguise their true location.
“This kind of activity is subject to UN sanctions which have effect under New Zealand law and also creates risks of espionage and extortion for businesses that are targeted,” NCSC Deputy Director-General Catriona Robinson said.
In July, New Zealand joined the United States, United Kingdom, Australia, Canada, Japan and several European countries in a joint warning that North Korean IT workers were using false identities to secure remote jobs and evade sanctions.
US authorities say the scheme generated US$800 million (NZ$1.4 billion) in 2024.
The NCSC recommends employers consider interviewing potential staff face-to-face and require new hires to pick up IT equipment personally.
AI boosts speed, scale and sophistication of cyber-attacks

The case is one of several emerging threats highlighted by the NCSC, which warns artificial intelligence is rapidly reshaping the cyber threat landscape.
“AI offers many opportunities, but it is already being used by malicious actors to increase the speed, scale and sophistication of cyber-attacks,” Robinson said.
The agency said that by early 2027, malicious actors may have access to advanced AI capabilities currently available only through the world’s leading frontier AI models.
The NCSC warned disruptive cyber incidents could occur with little warning.
“As well as the harm they cause to businesses, these attacks cause harm to New Zealanders whose personal information is stolen and potentially sold to other criminals or malicious actors.”
Robinson said it was up to chief executives and senior leaders to manage cyber security within their organisations and to “prepare now”.
The report also highlights a sharp increase in the severity of cybercrime.
Of the 369 incidents of potential national significance handled by the NCSC during 2025/26, 162 were linked to criminal or financially motivated actors, up 18% on the previous year.
In the same period, four incidents were classified as “highly significant” – the same number as the previous decade combined.
The Manage My Health data breach, which saw more than 99,000 patient records stolen, was among the major incidents highlighted in the report.
The morning’s headlines in 90 seconds, including two people rescued from the bottom of a cliff, how AI might kill us all, and the dramatic moment two military pilots eject from their plane. (Source: 1News)
