Key Takeaways
- Taiwan experienced an average of 2.63 million cyberattacks per day in 2025, more than double the 2023 level, with energy, emergency services, hospitals, and communications bearing the brunt.
- The surge is driven by Beijing’s desire to deter Taiwan’s de facto independence, undermine public trust, and compensate for waning economic leverage across the Strait.
- Chinese state‑backed hackers use cyberattacks as a gray‑zone tool to intimidate leadership (especially after President Lai Ching‑te’s 2024 election), spread disinformation, and test Taiwan’s resilience to a possible blockade or invasion.
- Taiwan’s vital semiconductor industry is a prime target for espionage and ransomware, posing risks to global supply chains even if China avoids direct sabotage.
- Despite establishing the Ministry of Digital Affairs and allocating NT 8.8 billion (≈ US $300 million) for a national cybersecurity program (2025‑2028), Taiwan’s annual spend (~US $75 million) lags far behind top global spenders, and a talent shortage hampers effective defense.
- Strengthening cybersecurity requires greater budgetary investment, overseas talent acquisition, and expanded international cooperation with like‑minded states and private sector partners.
Overview of the Cyberattack Surge
Taiwan’s National Security Bureau reported that, in 2025, the island faced a daily average of 2.63 million cyberattacks, a figure more than twice that recorded in 2023. The increase was not uniform across sectors; energy grids, emergency rescue services, hospitals, and communications infrastructure saw the sharpest rises. These attacks are part of a broader pattern of coercive “gray‑zone” activity that Beijing employs to pressure Taipei without crossing the threshold of open military conflict.
Political Motivations and the Lai Ching‑te Factor
The election of Lai Ching‑te as Taiwan’s president in January 2024 marked a turning point in Beijing’s cyber posture. Chinese officials label Lai a “separatist” whose statements—such as asserting that the Republic of China (Taiwan) and the People’s Republic of China are not subordinate, and urging China to reclaim territories occupied by Russia—are viewed as provocative. The NSB’s 2025 analysis documented spikes in Chinese cyber activity coinciding with Lai’s public speeches and overseas diplomatic trips, indicating that cyberattacks are used to intimidate the leadership into refraining from moves that could solidify Taiwan’s de facto independence.
Targeting Infrastructure and Spreading Disinformation
Beyond merely disrupting services, Chinese hackers aim to erode public confidence in the government’s ability to protect the nation. By infiltrating government websites and public‑service portals, attackers have replaced legitimate content with slogans claiming that cross‑strait unification has already been achieved. A 2024 survey by the Taiwan Network Information Center found that only 41 % of respondents trusted the government to respond effectively to cyber threats, while over 51 % expressed complete or partial distrust. This erosion of trust is a deliberate outcome of Beijing’s strategy, coupling technical intrusion with psychological warfare.
Economic Coercion and the Semiconductor Sector
Beijing’s economic influence over Taiwan has waned: China and Hong Kong’s share of Taiwan’s exports fell from 44 % in 2020 to 27 % in 2025, and outward foreign direct investment to China dropped from 84 % in 2010 to less than 4 % in 2025. Facing this decline, the PRC has turned to cyberattacks as a lever to menace Taiwanese businesses. The semiconductor industry—home to the world’s largest chip maker—is a particular focus. While China likely avoids outright sabotage that would harm its own semiconductor ambitions, it seeks to exfiltrate proprietary designs, steal customer data, or extort ransom payments. Such espionage threatens not only Taiwan’s high‑tech economy but also the global supply chain that depends on Taiwanese fabrication capacity.
Integration with PLA Military Activities
Cyber operations are now synchronized with the People’s Liberation Army’s conventional show of force. PLA aircraft sorties crossing the Taiwan Strait’s median line or entering Taiwan’s Air Defense Identification Zone rose dramatically—from 380 sorties in 2020 to 5,709 in 2025. In an invasion scenario, Beijing could employ cyberattacks to jam Taiwan’s communications with the outside world, hindering command‑and‑control, delaying international assistance, and degrading the island’s defensive coordination. Thus, cyberattacks serve both as a peacetime coercive tool and a potential enabler of kinetic aggression.
Evolution of Taiwan’s Cybersecurity Policy
Recognizing the growing threat, former President Tsai Ing‑Wen began embedding cybersecurity into Taiwan’s national security strategy in 2016. The Ministry of Digital Affairs (MODA), created in 2022, now oversees the formulation and execution of cybersecurity policies. Between 2025 and 2028, the government has earmarked NT 8.8 billion (≈ US $300 million) for a national cybersecurity development program. While this represents a notable increase, Taiwan’s annual cybersecurity expenditure—about US $75 million—remains far below the spending levels of the world’s top 20 cybersecurity investors.
Budgetary and Talent Shortfalls
Funding alone does not guarantee resilience. Taiwan’s historic emphasis on hardware manufacturing has left a gap in software and cybersecurity expertise. Firms across the island report difficulty finding qualified personnel, prompting many to invest in internal security measures while still feeling exposed to Chinese threats. To bridge this gap, experts recommend expanding overseas talent recruitment, enhancing on‑the‑job training programs, and creating incentives for cybersecurity professionals to remain in Taiwan.
The Role of International Cooperation
Collaboration with like‑minded nations is viewed as a force multiplier for Taiwan’s defenses. Initiatives such as the Taiwan Cybersecurity Resiliency Act of 2023 aim to deepen military‑to‑military cyber cooperation with the United States, covering network protection, joint training, and information sharing. Additionally, Taiwan has partnered with Paraguay on information security, smart technology, digital governance, and judicial cooperation. Broadening these alliances—particularly with the EU, Japan, Australia, and other democratic partners—can help Taiwan acquire advanced threat‑intelligence tools, conduct joint exercises, and deter Beijing through a unified front.
Conclusion and Recommendations
China’s persistent cyber campaign is an integral component of its broader strategy to prevent Taiwan from consolidating a distinct national identity, to undermine public trust, and to retain economic leverage despite declining trade ties. The attacks target critical infrastructure, exploit political moments, and seek to steal valuable semiconductor intellectual property.
To counter this multifaceted threat, Taiwan must:
- Increase cybersecurity spending to at least match the average of the top‑20 global investors, allocating resources for cutting‑edge detection, response, and recovery capabilities.
- Address the talent shortage by overseas recruitment, scholarship programs, and public‑private partnerships that funnel skilled workers into both government and industry roles.
- Deepen international cooperation, expanding existing U.S. and regional agreements and seeking new frameworks that include private‑sector threat‑sharing and joint incident‑response drills.
- Harden critical sectors, especially energy, health, and communications, through mandatory baseline standards, regular red‑team exercises, and segregation of essential networks from public‑facing services.
- Leverage the semiconductor industry’s strategic importance by encouraging firms to adopt zero‑trust architectures, encrypt sensitive design data, and participate in national information‑sharing hubs that can rapidly disseminate threat indicators.
By taking these steps, Taiwan can bolster its digital resilience, safeguard its democratic institutions, and maintain its pivotal role in the global technology supply chain—thereby raising the cost for Beijing to achieve its coercive objectives through cyber means.

