New Zealand ranked 21st globally for social media scams and was one of several countries targeted for tech support scams, which rose 20 per cent last year, said Mark Shaw, technology strategist for Symantec, which sells the Norton anti-virus software. Its annual report, which is commonly cited globally in the absence of more independent figures, is based on data from its own network.
New Zealanders were fairly naive when engaging on the internet, Shaw said, and the country needed legislation to force companies to report data breaches to their customers.
Replacing the current voluntary data breach reporting law with mandatory reporting forms part of proposed changes to New Zealand's privacy legislation being drafted at present.
The Privacy Commissioner received 121 voluntary notifications of data breaches last year, mostly caused by human error or carelessness, but how many go unreported is unknown.
The Symantec report says a total of 429 million identities were exposed by cyber crime, up 23 per cent on the previous year, that is estimated to rise to half a billion if unreported breaches were included. The report found an 85 per cent increase in companies choosing not to report lost records last year.
Shaw said just under half of data breaches in 2015 were the result of external hackers, often thanks to lost laptops or USB sticks and some by malicious insiders.
The Dyre financial Trojan malware stole the credentials of thousands of customers worldwide before being largely snuffed out by the end of last year, Shaw said. It targeted all of New Zealand's major banks, triggered when customers did internet banking, he said.
The number of discovered zero-day vulnerabilities - where an unknown hole in the software is exploited by hackers - more than doubled to a record 54 in 2015, a 125 per cent rise on 2014.
Spear-phishing attacks using apparently genuine email addresses rose by 55 per cent in 2015. That included a growing number of small to medium enterprises which accounted for 43 per cent of spear-phishing attacks.
The NZ Fire Service and Te Wananga O Aotearoa were two local examples of companies hit by such attacks last year, Shaw said.
- BusinessDesk