Taiwan — Cyber Threat Profile
Taiwan is one of the most cyber-contested territories globally. China's cyber army launched an average of 2.63 million intrusion attempts per day against Taiwan's critical infrastructure in 2025, a 6% increase over 2024 and a 113% increase from 2023. The energy sector saw a tenfold surge in Chinese intrusion attempts in 2025, while hospitals and emergency services faced a 54% rise. The top five active Chinese groups are BlackTech, Flax Typhoon, Mustang Panda, APT41, and UNC3886. Attack methods include hardware vulnerability exploitation, DDoS via botnets, social engineering, and supply chain compromises.- National CERT/CSIRT: TWCERT/CC
Latest Taiwan coverage
- Fake Cloudflare page hidden in an npm package redirects victims to a phishing site 2026-07-05 · Cyber Incidents
Threat actors targeting Taiwan
- Antlion APT
- APT27 APT
- APT41 APT
- BlackTech APT
- Flax Typhoon APT
- Mustang Panda APT
- Salt Typhoon APT
- TIDRONE APT
- Tropic Trooper APT
- Winnti Group APT
- Qilin Ransomware · 19 incident(s)
- The Gentlemen Ransomware · 18 incident(s)
- INC Ransom Ransomware · 9 incident(s)
- NightSpire Ransomware · 9 incident(s)
- RansomHub Ransomware · 9 incident(s)
- LockBit Ransomware · 8 incident(s)
- Orova Ransomware · 8 incident(s)
- Akira Ransomware · 5 incident(s)
- DragonForce Ransomware · 5 incident(s)
- Hunters International Ransomware · 4 incident(s)
- Krybit Ransomware · 4 incident(s)
- Lynx Ransomware Ransomware · 4 incident(s)
- World Leaks Ransomware · 3 incident(s)
- BlackSuit Ransomware · 2 incident(s)
- Cl0p Ransomware · 2 incident(s)
- Coinbase Cartel Ransomware · 2 incident(s)
- Deadlock Ransomware · 2 incident(s)
- Sarcoma Ransomware · 2 incident(s)
- Settra Ransomware · 2 incident(s)
- 8Base Ransomware · 1 incident(s)
- AiLock Ransomware · 1 incident(s)
- Blackfield Ransomware · 1 incident(s)
- Cactus Ransomware · 1 incident(s)
- Embargo Ransomware · 1 incident(s)
- Everest Ransomware · 1 incident(s)
- Exitium Ransomware · 1 incident(s)
- FunkSec Ransomware · 1 incident(s)
- Morpheus Ransomware · 1 incident(s)
- Nitrogen Ransomware · 1 incident(s)
- Payload Ransomware · 1 incident(s)
Most targeted sectors
- Technology 55 incident(s)
- Manufacturing 36 incident(s)
- Healthcare 10 incident(s)
- Business & Professional Services 6 incident(s)
- Retail & Consumer 6 incident(s)
- Agriculture & Food 2 incident(s)
- Construction 2 incident(s)
- Education & Research 2 incident(s)
- Energy & Utilities 2 incident(s)
- Hospitality & Tourism 2 incident(s)
- Telecommunications 2 incident(s)
- Financial Services 1 incident(s)
Recent claimed incidents
- VIVOTEK 2026-09-01 · Technology
- ASYS Corporation 2026-08-31 · Technology
- Easyoga 2026-08-31 · Retail & E-Commerce
- Probe Test System 2026-08-30 · Technology
- Bai-chi CPA Firm 2026-08-25 · Professional Services
- Arich Enterprise Co., Ltd. 2026-08-25 · Other
- Volktek 2026-08-23 · Technology
- BioPharma 2026-08-20 · Healthcare
- UFOC 2026-08-19
- Foresee Pharmaceuticals 2026-08-18 · Healthcare
- Smartsoft 2026-08-16 · Technology
- HISS Taroko Door & Window Technologies, Inc. (喜室清展股份有限公司) 2026-08-12
- LARGAN.COM.TW 2026-08-12 · Manufacturing
- PharmaEssentia 2026-08-10 · Healthcare
- Panda Logistics Taichung Branch 2026-08-09 · Transportation