Lumma Info Stealer Alert — why NZ’s cyber agency emailed 26,000 people
New Zealand’s National Cyber Security Centre (NCSC) has taken an unusually direct step: emailing around 26,000 email addresses to warn that devices linked to those accounts may be infected with Lumma Stealer, a credential‑stealing malware. The NCSC says this is the first time it has conducted public outreach at this scale and has emphasised the message is legitimate.
What Happened?
The NCSC says it became aware of the issue through cybersecurity partnerships and worked with government agencies and financial institutions to contact some affected users, before expanding the campaign to direct email notifications.
The emails direct recipients to the NCSC’s Own Your Online guidance for help removing the malware and reducing risk to online accounts.
What is Lumma Stealer?
Lumma Stealer is “information stealer” malware designed to quietly steal passwords and login details, most commonly from Windows devices.
The NCSC says it has successfully stolen credentials for thousands of New Zealanders’ online accounts.
How to know if you’re affected
- If you received an NCSC email, official guidance says it comes from no-reply@comms.ncsc.govt.nz.
- Watch for unusual account activity (unexpected logins, settings changes, being locked out) or unauthorised transactions — the NCSC notes this malware can be hard to detect on the device itself.
What to do now (simple steps that reduce risk fast)
- Scan and remove the malware
The NCSC recommends running an antivirus/antimalware scan; its Own Your Online guidance includes using Microsoft Defender offline scan and applying outstanding updates. - Change passwords for key accounts first
Start with email (because it resets everything else), then banking, then work logins and other high‑value services. The NCSC stresses you also need to secure accounts accessed from the affected device. - Turn on Multi‑Factor Authentication (MFA)
This reduces the chance that stolen passwords alone can be used to take over accounts. - For businesses: treat this as a credential‑theft readiness test
Review staff MFA coverage, endpoint protection, and phishing awareness — because credential‑stealer infections often start with malicious downloads or phishing.
Ready to Strengthen Your Cybersecurity?
If you’d like help confirming whether devices/accounts are compromised — or you want to uplift MFA and endpoint protection across your team, we’re here to help.





