NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / New Zealand / Politics

Hacking: GCSB report admits need for improvement when handling foreign threats against MPs

Thomas Coughlan
By Thomas Coughlan
Political Editor·NZ Herald·
15 Jul, 2024 01:59 AM8 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Former MP Simon O'Connor was among those hacked. Photo / Mark Mitchell

Former MP Simon O'Connor was among those hacked. Photo / Mark Mitchell

A report into the way the GCSB handled a cyber attack on New Zealand MPs and a prominent academic has found that processes could be improved and that, in some circumstances, it should contact people affected by cyber attacks.

The review began earlier this year when the spy agency confirmed it had been aware of a 2021 China-backed cyber attack on two MPs who were part of the Inter-Parliamentary Alliance on China (IPAC), Simon O’Connor and Louisa Wall, as well as Canterbury University professor Anne-Marie Brady.

The victims of the attack were frustrated the GCSB and its cyber-security arm, the National Cyber Security Centre (NCSC), were not informed by the agency that they had been targeted by APT 31, a state-backed Chinese hacking group.

The internal review, published today, recommended that “where appropriate, the NCSC should consider some form of engagement with individuals” when it discovered they had been targeted by “state-sponsored actors”. It found that the attack, which was mainly phishing emails, did not succeed in compromising email accounts.

Currently, the NCSC does not have procedures for how to respond to reports indicating foreign actors might be targeting New Zealanders. The report also recommended that the NCSC not only focus on the “technical” response to cyber-security incidents, but broaden focus to their “wider implications”.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

The review also said the agencies should do better at identifying incidents on which the minister should be briefed. Currently, only the “no surprises” rule applies, meaning a large volume of important incidents might pass the minister by. The report included the caveat that it would not be “possible to prescribe all of the circumstances in which it may be appropriate for the NCSC to brief the minister”.

Brady said the NCSC “need to have a better understanding of foreign interference”.

“China is both the main source of cyber attacks on New Zealand, and the main source of foreign interference and espionage in New Zealand. New Zealand’s national cyber agency needs to understand China’s foreign interference activities in order to better mitigate against the ongoing cyber attacks,” Brady said.

Advertisement
Advertise with NZME.

O’Connor told the Herald that while he was pleased the agencies had finally “taken the matter seriously”, he was still “disappointed as to how this was handled”.

He said the recommendations were “good and appropriate” but that he hoped that the changes will see “a better and more robust response in the future”.

Lisa Fong, the GCSB’s deputy director-general cyber security, said the report “did not identify any information to indicate the activity resulted in a successful cyber-security compromise but did identify a number of phishing emails sent to parliamentary email addresses”.

Brady said that the report was effectively looking in the wrong direction by focusing on emails.

“The FBI reports say the hack attempt was a progressive hack aimed at getting IP addresses. The NCSC report wrongly focuses on whether emails were compromised,” she said.

The review said the NCSC is aware of a “large volume” of potential malicious cyber activity. The agency conducts “preliminary analysis” of these threats and if the threat is determined to reach a certain threshold, a “formal incident” is created and the threat investigated. Each “incident” is given a rating from C1, “National Cyber Emergency”, to C6, “Minor Incident”.

Last year, the NCSC recorded 316 incidents. The report found that most incidents are not escalated to this threshold and would best be categorised as random, phishing-style exercises.

Canterbury University professor Anne-Marie Brady was a target of the attack. Photo / Michael Craig
Canterbury University professor Anne-Marie Brady was a target of the attack. Photo / Michael Craig

“A significant amount of malicious cyber activity affecting New Zealand is not targeted, and is instead part of opportunistic exploitation of vulnerable systems and often global in nature,” the report said.

“This includes most email-based phishing campaigns. The NCSC’s staff prioritise escalation of activity judged most likely to cause significant harm to New Zealand’s nationally significant organisations or cause a high national harm.”

The report gave a timeline of when it became aware of hacking.

Advertisement
Advertise with NZME.

In June 2021, the Parliamentary Service advised the NCSC that an MP who was a member of IPAC had raised concerns about possible malicious cyber activity against IPAC members. The NCSC opened an “incident” in relation to that complaint and coded it C5 or a “routine incident”, as it “related to scanning, reconnaissance or a potential threat”.

The NCSC engaged with the New Zealand Security Intelligence Service (NZSIS), who provided the NCSC with “classified intelligence” from another international partner agency, which was not named in the report but is often assumed to be the United States.

The “incident” was closed in mid-July 2021 after the NCSC advised Parliamentary Service that it did not have any material information to update and the Parliamentary Service confirmed it was not expecting any further assistance from the NCSC.

In April 2022, the NZSIS provided the NCSC with a classified intelligence report from an international partner agency related to possible malicious cyber activity against IPAC members. It did not explicitly reference any targeting of New Zealand individuals and the NCSC did not open an incident on it.

In June 2022, an unnamed international partner agency informed police and the NZSIS about possible foreign state cyber activity that may have affected New Zealand members of IPAC. The NZSIS passed that information to the NCSC to lead the incident response. This time, the NCSC did open an “incident”, tagging it C5 or a “routine incident”.

As a result of this investigation, the NCSC “considered taking actions in relation to... [one individual] who may have been affected by the reported cyber activity”, likely O’Connor or Wall, but the NCSC assumed they were likely aware of the risk of targeting by foreign state-sponsored actors and would already be taking appropriate security measures.

Advertisement
Advertise with NZME.

This particularly irked O’Connor.

“For any agency to just ‘assume’ that we would be prepared seems quite lax, no matter how well prepared we are by our own resources. I note that Parliamentary Services systems failed to prevent this phishing attempt in the first instance and they also failed to identify the issue, even when told.,” he said.

That incident was closed in August 2022, the international partner agency “corrected” the information it had provided the NZSIS, but the NCSC did not reopen the incident.

The report mentions the engagement the NCSC had with Parliament, but it does not mention any engagement with Brady’s employer, the University of Canterbury.

Brady told the Herald the University of Canterbury is a “customer” of the NCSC along with other “research institutions”, which meant it should have been informed of the attack.

“They informed the Parliamentary Service, but they did not inform the University of Canterbury of the cyber attack, even though they are required to,” she said.

Advertisement
Advertise with NZME.

In May 2024, following news of the attack breaking publicly, the NCSC finally engaged with people caught up in the attack.

O’Connor remained unhappy with what the NCSC had uncovered during the review.

“Good intelligence should always rely on context as well as technical data. It remains concerning to me that no one thought beyond the technical details,” he said.

“At day’s end, this was not a random cyber activity. A foreign state actor [China] specifically targeted three New Zealanders in public roles and who have been outspoken in their criticism of the CCP [Chinese Communist Party]. I remain unimpressed that this was not apparently considered at the time,” he said.

O’Connor said Chinese proxies “sought to surgically target outspoken individuals who hold significant information and contacts relating to CCP activities both in New Zealand and abroad”. He was particularly critical of the finding that NCSC staff assumed that he and the other targets were taking precautions with cyber security, and did not think to contact them personally.

“All of this highlights the need for greater vigilance and a more proactive approach to those targeted. Had any of these agencies engaged with IPAC members, we would have been able to source the emails in question and eliminate the threat,” he said.

Advertisement
Advertise with NZME.

The current IPAC co-chairs Labour’s Ingrid Leary and National’s Joseph Mooney said they were “pleased the matter has been taken seriously and a review undertaken. It finds that no parliamentary emails were accessed, but does make recommendations for improvements which IPAC supports being implemented”.

The Inspector-General of Intelligence and Security, Brendan Horsley, who monitors the GCSB, said no further review was necessary.

“I have reviewed the classified and public reports prepared by the NCSC. I am satisfied that the NCSC review: fully and fairly covers what happened: the public report discloses the important facts; and the NCSC has properly recognised where it can improve. I have decided that a separate IGIS inquiry is not needed. However, I will monitor NCSC’s action on the recommendations,” he said.

Thomas Coughlan is Deputy Political Editor and covers politics from Parliament. He has worked for the Herald since 2021 and has worked in the press gallery since 2018.

Save

    Share this article

Latest from Politics

Politics

Meat and skincare on the agenda for PM's first day in China

17 Jun 11:36 PM
PoliticsUpdated

Takeover powers: Govt set to override councils under RMA shake-up

17 Jun 09:07 PM
Premium
Opinion

Simon Wilson: Chlöe Swarbrick and the lost lessons of Monopoly

17 Jun 05:00 PM

Jono and Ben brew up a tea-fuelled adventure in Sri Lanka

sponsored
Advertisement
Advertise with NZME.

Latest from Politics

Meat and skincare on the agenda for PM's first day in China

Meat and skincare on the agenda for PM's first day in China

17 Jun 11:36 PM

Christopher Luxon's first day in China includes a surprising win for cosmetics exporters.

Takeover powers: Govt set to override councils under RMA shake-up

Takeover powers: Govt set to override councils under RMA shake-up

17 Jun 09:07 PM
Premium
Simon Wilson: Chlöe Swarbrick and the lost lessons of Monopoly

Simon Wilson: Chlöe Swarbrick and the lost lessons of Monopoly

17 Jun 05:00 PM
Premium
Audrey Young: Behind the pay equity dispute over male vs female-dominated jobs

Audrey Young: Behind the pay equity dispute over male vs female-dominated jobs

17 Jun 05:00 PM
Help for those helping hardest-hit
sponsored

Help for those helping hardest-hit

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP