Chinese hackers have intensified their attacks against Taiwan's critical infrastructure in 2025, a clear escalation of digital warfare tactics.
See also: Chinese hackers use rootkit to hide ToneShell

Taiwan's national intelligence community recorded a worrying development: an average of about 2.63 million hacking attempts per day were directed against vital systems in nine key sectors, including energy, health, communications, and transportation.
This number represents a 6% increase compared to 2024, indicating a rapidly deteriorating threat environment that requires immediate mobilization from both cybersecurity experts and relevant policymakers. The offensive campaigns reveal an advanced, multi-layered cyberattack strategy, which appears to be coordinated with military exercises and political developments.
A notable increase in cyberattacks was observed during major ceremonies and high-level diplomatic visits to Taiwan, with May 2025 recording unprecedented activity coinciding with the anniversary of President Lai's inauguration.
See also: 'Ink Dragon' threat group targets IIS servers

This correlation between digital and physical forms of pressure reveals an overall strategy of destabilizing Taiwan’s functioning and gathering information about government decision-making processes.
National Security Bureau analysts found that the energy and healthcare sectors were the most heavily attacked, with five key Chinese hacking groups—BlackTech, Flax Typhoon, Mustang Panda, APT41, and UNC3886—leading coordinated operations.
These groups used ransomware-style attacks against hospitals, with at least 20 confirmed cases of medical data being stolen, which was then put up for sale on dark web forums.
See also: Chinese hackers exploit React2Shell vulnerability

The targeting of Taiwan's healthcare infrastructure demonstrates how adversaries consciously choose to threaten the civilian population and critical public services.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
