2degrees turns on default blocks for malicious sites
Wed, 19th Aug 2026 (Today)
2degrees has introduced automatic network-level protection that blocks connections to known malicious sites for its customers. The measure uses threat intelligence from the National Cyber Security Centre's Malware Free Networks service.
The protection is enabled by default for customers using 2degrees DNS servers and does not require them to sign up, install an app, or change settings. It works by blocking access on the company's network when a malicious domain, web address, or IP address has been identified.
The threat data comes from Malware Free Networks, a partner-led service run by the National Cyber Security Centre within the Government Communications Security Bureau. The centre identifies malicious online destinations targeting New Zealanders and shares those indicators with participating network operators, including 2degrees.
That allows blocks to be applied before a customer reaches a harmful site linked to a scam, phishing attempt, or other cyber threat. The service provides near real-time intelligence and, according to 2degrees, does not require additional equipment to be installed on its network.
Scam response
The move is part of a broader effort to respond to rising scam activity and online fraud. 2degrees has also taken part in a cross-industry scam disruption initiative involving major banks, telecommunications providers, an online marketplace, and a New Zealand technology company.
The pilot has focused on identifying and blocking malicious websites soon after they appear. Government figures released in June said the programme had blocked more than 23,000 malicious domains over six months and helped avoid an estimated NZD $23.8 million in fraud losses.
Cyber security is a growing concern for telecoms groups as fraudsters increasingly use text messages, email, and spoofed websites to target consumers. Network-level interventions have drawn attention because they can protect an entire customer base without relying on individuals to spot suspicious links themselves.
Ivan Reutskiy, General Manager of Security at 2degrees, said the company wanted the safeguard to be broadly available rather than limited to customers who actively opted in.
"Security shouldn't be a premium product or something only the tech-savvy get, so we've turned this on for everyone by default," said Ivan Reutskiy, General Manager of Security at 2degrees.
He said the measure was intended to help customers who were less likely to identify fraudulent messages or fake websites before clicking on them.
"We want to protect all our customers, particularly those most at risk who are usually the least equipped to spot a convincing scam. If one of our customers taps a known malicious link in a scam text or email, this threat intelligence can often stop the connection before any damage is done," Reutskiy said.
Privacy design
2degrees said the system was designed so customer browsing information is not shared with the National Cyber Security Centre. Instead, the company applies the blocks on its own network and sends back limited operational feedback.
That feedback does not include personal information and records only which threat indicator was triggered and when, according to 2degrees. The approach reflects a common challenge in network security measures: expanding protection without increasing the collection of user data.
The National Cyber Security Centre describes Malware Free Networks as a threat disruption service that helps partner organisations counter malware, phishing, remote scanning, and attempted exploitation. By distributing indicators of compromise to internet and telecoms providers, the system is intended to stop malicious traffic earlier in the chain.
For operators such as 2degrees, the model adds a layer of defence at network level rather than relying solely on device-based software. Even with the new filtering in place, customers should still remain alert to scams and other cyber risks.
Government-backed and industry-led efforts to block harmful domains have gained momentum in New Zealand as authorities and private companies look for ways to reduce fraud losses. The reported blocking of more than 23,000 malicious domains over six months underlines the scale of the problem facing telecoms providers, banks, and online platforms.