Taiwan's National Security Bureau reported a dramatic escalation in cyberattacks attributed to China, with incidents targeting the country's energy sector increasing tenfold in 2025 compared to the previous year. The overall number of cyber incidents linked to China grew by 6%, with critical infrastructure sectors such as energy, hospitals, emergency services, and banks being the primary targets. Attackers focused on exploiting hardware and software vulnerabilities, launching distributed denial-of-service (DDoS) attacks, conducting social engineering campaigns, and attempting supply-chain compromises. Notably, the energy sector, including petroleum, electricity, and natural gas companies, faced intensive probing of industrial control systems, with attackers seeking opportunities to inject malware during scheduled software upgrades.
The frequency of these attacks averaged 2.6 million per day, and many were reportedly coordinated with Chinese military exercises and major political events, such as speeches or international visits by senior Taiwanese officials. The semiconductor industry, including companies like TSMC, was also among the targets. While the Chinese government has denied involvement, Taiwanese authorities emphasize the strategic nature of these cyber operations, which often coincide with periods of heightened political tension. The report underscores the persistent and evolving threat posed to Taiwan's critical infrastructure by state-sponsored cyber actors from China.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
After Taiwan publicly blamed Chinese state-linked actors for the 2025 campaign, the Chinese government denied involvement and accused Taiwan of similar hacking activity. The denial accompanied wider reporting on the surge in attacks against Taiwan's infrastructure.
By early January 2026, Taiwan said it had strengthened international cyber cooperation with more than 30 countries through intelligence sharing and joint investigations. The effort was presented as part of its response to the 2025 China-linked intrusion campaign.
In its public reporting on the 2025 activity, Taiwan's National Security Bureau attributed the campaign to groups including BlackTech, Flax Typhoon, Mustang Panda, APT41, and UNC3886. The bureau said the actors used vulnerability exploitation, DDoS, social engineering, adversary-in-the-middle, phishing, and supply-chain techniques.
Across 2025, many of the cyberattacks were timed to coincide with Chinese military exercises and major political moments in Taiwan. Activity reportedly peaked around significant events, including the anniversary of President Lai's inauguration.
In 2025, China-linked actors expanded operations beyond traditional government targets to telecommunications networks, semiconductor firms, and defense supply-chain partners. The campaigns sought to steal design documentation, strategic plans, sensitive technologies, and intelligence.
In 2025, hospitals in Taiwan were heavily targeted by China-linked cyber operations, including ransomware attacks and theft of medical data. Reports said at least 20 confirmed cases involved stolen patient information being sold on dark web forums.
During 2025, Taiwan's energy sector saw the sharpest escalation, with cyberattacks increasing tenfold compared with 2024. Attackers targeted industrial control systems and in some cases reportedly implanted malware during software upgrades to monitor operations.
Throughout 2025, Taiwan recorded an average of about 2.6 to 2.63 million daily cyber intrusion attempts attributed to China, a roughly 6% increase over 2024. The activity targeted nine critical infrastructure sectors, including energy, healthcare, communications, government, finance, and technology.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecybersecuritynews.com
Open sourcecyberscoop.com
Open sourcebleepingcomputer.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.