Taiwan’s National Security Bureau has reported a significant increase in cyberattacks and disinformation campaigns attributed to China, with government networks facing an average of 2.8 million intrusion attempts per day in 2025, marking a 17 percent rise from the previous year. Much of this activity targets critical infrastructure sectors such as defense, telecommunications, energy, and medical systems. Chinese operations combine cyber intrusions with coordinated information warfare, leveraging state media and organized online troll armies to spread fabricated content across social networks and forums. Over 10,000 abnormal social media accounts have been identified, disseminating more than 1.5 million pieces of disinformation, much of which attacks the Taiwanese government, promotes pro-China narratives, and seeks to undermine trust in the United States. These influence operations have increasingly used AI-generated memes and videos to amplify false narratives about sensitive issues, including tariff negotiations and domestic energy policies, as part of a broader strategy to shape public perception ahead of Taiwan’s 2026 local elections. The NSB describes these efforts as a state-level campaign designed to erode public trust in government institutions and deepen divisions within Taiwan’s democracy. In parallel, Poland has experienced a surge in cyberattacks linked to Russian actors, with Moscow’s military intelligence reportedly tripling its cyber resources targeting Polish infrastructure in 2025. Of the 170,000 cyber incidents recorded in Poland in the first nine months of the year, a substantial share was attributed to Russian state-backed groups, with daily incidents ranging from 2,000 to 4,000 and about 1,000 posing real threats to national security. Russian attackers have expanded their focus from utilities to the energy sector, and a major coordinated cyberattack on September 10 coincided with a Russian drone strike, representing the largest digital assault on Poland since 2022. Following this attack, Russian-linked bots reactivated dormant networks to spread disinformation blaming Ukraine, aiming to destabilize public trust. Both the Taiwanese and Polish cases illustrate a growing trend of state-sponsored cyber operations that blend technical intrusions with sophisticated influence campaigns. These operations are designed not only to compromise critical infrastructure but also to manipulate public opinion and undermine democratic processes. The use of AI and coordinated online activity has amplified the reach and impact of disinformation, making detection and response more challenging for targeted nations. The scale and persistence of these campaigns highlight the evolving threat landscape, where cyber and information warfare are increasingly intertwined. National security agencies in both countries have emphasized the need for heightened vigilance and international cooperation to counter these threats. The incidents underscore the importance of robust cyber defenses, real-time threat intelligence sharing, and public awareness initiatives to mitigate the risks posed by hostile state actors. As adversaries continue to innovate and escalate their tactics, defending against such multifaceted campaigns remains a top priority for governments and critical infrastructure operators worldwide.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
The Record reported that Taiwan's National Security Bureau disclosed an increase in cyber activity and disinformation efforts attributed to China. With no more specific timing in the reference, the event date is inferred from the publication date.
SC Media reported that Russian hackers were targeting Poland's infrastructure. The reference provides no additional incident details beyond the targeting claim, so the event date is inferred from the publication date.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.