NZ Schools Cybersecurity 2026: What 6 years of public data tells us about phishing, data breaches, and reporting gaps
Six years of CERT NZ, Netsafe, and Privacy Commissioner data on NZ schools cybersecurity — phishing dominates, breach notifications up 59%, reporting gaps.
Quick answer
Three patterns show up across six years of NZ schools cybersecurity data. One: phishing dominates the education sector’s reported threat picture in CERT NZ’s recent quarterly reports. Two: total data breach notifications under the Privacy Act 2020 have risen from 544 in FY2021 to 864 in FY2024 — a 59% increase — and schools are not exempt from this trend. Three: formal reporting captures only a fraction of what’s actually happening. Netsafe’s helpline supported schools through 863 reported incidents in FY2024 alone, against a national base of over 2,500 schools — and most of those incidents never reached CERT NZ or the Privacy Commissioner.
This analysis draws on CERT NZ’s quarterly reports, Netsafe’s Annual Reports for 2023 and 2024, the Privacy Commissioner’s Annual Reports from 2021 through 2024, and N4L’s 2024 Annual Report.
Finding 1: Phishing dominates reported threats for NZ schools
The CERT NZ quarterly report series is the most detailed public record of cyber incidents affecting New Zealand’s education sector. Each report breaks incidents down by victim sector and type. CERT NZ migrated its report archive from cert.govt.nz to ncsc.govt.nz in 2022; reports from Q3 2022 onward are directly downloadable as PDFs. Q1 2020 through Q2 2022 reports are at the original domain and are blocked for automated download.
What the reports consistently show for the education sector is that phishing and fraud-related incidents — credential-harvesting emails, fake login pages, social engineering — make up the largest share of reported incidents. This aligns with the pattern NCSC NZ describes in its own threat reporting, where phishing is the primary initial-access vector for attacks against organisations — and with NZAI’s own Phishing Anatomy guide, which documents real NZ school phishing cases in detail (NCSC NZ, 2024).
The specific education-sector percentages for 2020 are not extractable without the Q1 2020–Q2 2022 PDFs from cert.govt.nz. The trend from 2022 onward, combined with the global picture, points clearly in one direction: phishing accounts for the largest share of reported education-sector incidents, a share that has grown as ransomware and malware incidents in the sector have declined or plateaued elsewhere.
Known gaps: The 2020–2022 education-sector phishing percentages and absolute incident counts require the cert.govt.nz PDFs that are blocked for automated download. Without those, a precise year-on-year percentage cannot be stated numerically.
Finding 2: Privacy breach notifications have risen 59% since Privacy Act 2020
The Privacy Act 2020 introduced a mandatory notifiable privacy breach regime that took effect on 1 December 2020. Under this regime, agencies that experience a breach likely to cause serious harm must notify the Office of the Privacy Commissioner (OPC) and consider notifying affected individuals. The OPC’s annual reports record the total number of breach notifications received each financial year [1][2][3].
Financial YearBreach Notifications ReceivedSourceFY2021544OPC Annual Report 2021 [1]FY2023657OPC Annual Report 2023 [2]FY2024864OPC Annual Report 2024 [3] From 544 to 864 over roughly three years is an increase of approximately 59%. The Privacy Commissioner’s own commentary in successive annual reports notes this year-on-year increase and observes that part of the growth reflects improved awareness of the reporting obligation, not purely a rise in actual breaches (Privacy Commissioner, 2023; Privacy Commissioner, 2024).
The OPC annual reports do not break out school-specific breach notifications. This means the precise number of school-specific notifications — and therefore the precise growth rate for the education sector — is not publicly available. Schools are not excluded from the notification regime, and the awareness-raising effect the Privacy Commissioner describes applies across all sectors, including education.
The overall trend is firmly upward. Under-reporting is a known concern across all sectors, and the Privacy Commissioner has noted this repeatedly in annual report commentary.
| Financial Year | Breach Notifications Received | Source |
|---|---|---|
| FY2021 | 544 | OPC Annual Report 2021 [1] |
| FY2023 | 657 | OPC Annual Report 2023 [2] |
| FY2024 | 864 | OPC Annual Report 2024 [3] |
Finding 3: A reporting gap exists — but its precise size is not calculable
Three numbers are relevant here.
Netsafe FY2024: 28,468 total online harm reports. School-specific incidents are a named reporting category. Netsafe’s helpline supported schools through 863 reported incidents in FY2024 — post-incident support sessions delivered to school communities following harmful online experiences (Netsafe, 2024) [4].
CERT NZ: Education-sector incident reports are in each quarterly report. Q3 2022–Q4 2025 PDFs are downloadable from ncsc.govt.nz, but the specific education-sector totals for 2024 and 2025 are not yet extracted from the available PDFs.
N4L: Covers “over 2,500 schools” across New Zealand with managed internet and cybersecurity services (N4L, 2024) [5].
The reporting gap argument is straightforward: 863 Netsafe-reported school incidents in one year, against 2,500+ schools in the N4L network, sounds like a floor — not a ceiling. CERT NZ’s education-sector data would provide the formal-channel counterpart once extracted. But the two datasets do not overlap cleanly: Netsafe’s “school incidents” category includes online harm under the Harmful Digital Communications Act, which is not the same as a cyber incident reported to CERT NZ.
What can be stated with confidence: the 863 Netsafe-supported school incidents in FY2024 is a minimum figure. It represents direct post-incident support, not all incidents and not all schools. Against 2,500+ schools in the N4L network, it is almost certainly an undercount of total incidents. The formal CERT NZ and Privacy Commissioner channels capture school incidents, but whether they capture a large or small proportion of the total is not determinable from currently available public data.
A note on what this is not: this is not a precise calculation of a reporting rate. It is a directional observation that informal channels (Netsafe) appear to be handling a volume of school cyber incidents that substantially exceeds what appears in formal government reporting — a pattern consistent with the Privacy Commissioner’s own observations about the notification regime across all sectors.
Who is reporting
Netsafe’s FY2024 report has a useful demographic signal: 74.9% of reports to Netsafe came from parents or guardians, with 4.0% from educators (Netsafe, 2024) [4]. The formal reporting burden does not fall on schools themselves in most cases — it falls on parents responding to incidents involving their children.
This matters for the reporting gap. A school that experiences a cyber incident may not report it to CERT NZ if the incident primarily affected parents or students rather than school systems — or because the reporting pathway is unclear, or perceived as disproportionate to the harm.
Who is reporting
Netsafe’s FY2024 report has a useful demographic signal: 74.9% of reports to Netsafe came from parents or guardians, with 4.0% from educators (Netsafe, 2024) [4]. The formal reporting burden does not fall on schools themselves in most cases — it falls on parents responding to incidents involving their children. This matters for the reporting gap. A school that experiences a cyber incident may not report it to CERT NZ if the incident primarily affected parents or students rather than school systems — or because the reporting pathway is unclear, or perceived as disproportionate to the harm.
What this means for NZ schools
Three things follow from the available data.
Phishing defence is the highest-leverage investment. Phishing dominates the education sector’s reported threat picture. School-wide training, email filtering, and multi-factor authentication are the controls most directly aligned to the dominant threat vector.
Privacy Act 2020 breach notifications are rising — schools are not exempt. The OPC’s 59% increase in total notifications since FY2021 is a sector-wide signal. Schools handling student data under the Privacy Act 2020 have legal obligations when a notifiable data breach occurs. For a practical guide to those obligations and how they apply in schools, see NZAI’s Privacy in Education guide. Many school leaders may not be aware that the mandatory notification obligation applies to them.
Formal reporting is incomplete. Netsafe is a first port of call. Netsafe’s 863 school support engagements in FY2024 against 2,500+ schools suggests that formal CERT NZ and OPC notifications capture only part of the picture. Netsafe (0508 273 823) is the appropriate first contact for schools facing an online harm incident, even when the incident does not meet the threshold for a CERT NZ or Privacy Commissioner notification.
Data availability
| Source | Available |
|---|---|
| CERT NZ Quarterly Reports Q3 2022–Q4 2025 | 🔗 NCSC Cyber Threat Reports |
| CERT NZ Quarterly Reports Q1 2020–Q2 2022 | 🔗 NCSC Cyber Threat Reports |
| Netsafe Annual Report 2023–2024 | 📄 PDF from Netsafe |
| Netsafe Annual Report 2024-2025 | 📄 PDF from Netsafe |
| OPC Annual Reports 2021, 2023, 2024 | 📄 2021, 📄 2023, 📄 2024 |
Disclaimer: Data in this article comes from official public reports published by CERT NZ, Netsafe, the Privacy Commissioner, and N4L. Information has been reviewed carefully, but this is not an official government publication — treat it as a synthesis of publicly available data. If you believe a figure is inaccurate, please let us know.
Sources and references
[1] Privacy Commissioner. (2021). Annual report of the Privacy Commissioner 2021. Office of the Privacy Commissioner, New Zealand. https://www.privacy.org.nz/assets/New-order/Resources-/Publications/Corporate-reports/Annual-Report-2021.pdf
[2] Privacy Commissioner. (2023). Annual report of the Privacy Commissioner 2023. Office of the Privacy Commissioner, New Zealand. https://www.privacy.org.nz/assets/New-order/Resources-/Publications/Corporate-reports/Annual-Report-2023.pdf
[3] Privacy Commissioner. (2024). Annual report of the Privacy Commissioner 2024. Office of the Privacy Commissioner, New Zealand. https://www.privacy.org.nz/assets/New-order/Resources-/Publications/Corporate-reports/2024-annual-report/2021-26-11-OPC-Annual-Report-2024.pdf
[4] Netsafe. (2024). Netsafe annual report 2024: Year in review July 2023–June 2024. Netsafe. https://resource.netsafe.org.nz/FINAL-2024-AR-Landscape-061224-LRES.pdf
[5] Network for Learning. (2024). N4L annual report 2024. N4L. https://www.n4l.co.nz/wp-content/uploads/2024/12/N4L-Annual-Report-2024-Final.pdf
[6] CERT NZ. (2024). 2023–2024 Cyber threat report. National Cyber Security Centre, New Zealand. https://www.ncsc.govt.nz/insights-and-research/cyber-threat-reports/20232024-cyber-threat-report/
[7] National Cyber Security Centre. (2024). NCSC NZ cyber threat report 2022–2023. New Zealand Government. https://www.ncsc.govt.nz/insights-and-research/cyber-threat-reports/ncsc-cyber-threat-report-20222023/
Advertisement disclosure: This page may display relevant advertisements. Ad placements are clearly identified and do not influence NZAI Security's editorial decisions. See our full disclosure policy.
Advertisement disclosure: This page may display relevant advertisements. Ad placements are clearly identified and do not influence NZAI Security's editorial decisions. See our full disclosure policy.