A massive cyberattack on Taiwan’s critical infrastructure could provide an early warning of an impending Chinese invasion, a Taiwanese national-security adviser said while joining a Capitol Hill forum remotely from Taiwan on July 21.“If there is a massive cyberattack on critical infrastructure, that will be a very strong indicator of Chinese invasion of Taiwan,” Yu-Chieh Lee, an advisory member of Taiwan’s National Security Council, said.Taiwan recorded an average of 2.63 million daily intrusion attempts against its critical infrastructure in 2025, a 6 percent increase from 2024, according to the island’s National Security Bureau.The figure indicates attempted intrusions rather than successful breaches.Lee identified power plants, communications networks, transportation systems, and financial institutions among the infrastructure Taiwan considers central to its national security.He spoke during a cybersecurity session of the Chinese Freedom & U.S.–Taiwan Security Forum organized by Consilium Institute, an independent public policy think tank based in New York, and co-organized by Hello Taiwan, a U.S.-based nonprofit that promotes U.S.–Taiwan ties.Rep. Andy Ogles (R-Tenn.), chairman of the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection, and cybersecurity executive Hao-Wei Chen joined the panel in Washington.The Chinese Communist Party claims Taiwan as its territory and has not ruled out using force to bring the self-governed island under its control. Taiwan rejects Beijing’s sovereignty claims.Daily Intrusion AttemptsTaiwan defines critical infrastructure to include energy, water, communications, transportation, finance, hospitals and emergency services, government agencies, industrial parks, and food supply.Lee said automated systems detect more than 99 percent of attempted intrusions. The volume nevertheless leaves additional alerts to be reviewed by a cybersecurity workforce facing persistent personnel shortages.Defenders must block every successful entry, while attackers need to find only one opening, Ogles said.One person using artificial intelligence (AI) can now perform tasks that would have required a team of hackers only months or years earlier, he said.Lee placed critical-infrastructure protection among four parts of Taiwan’s national cybersecurity strategy.The other parts are whole-of-society cyber defense, supply-chain and domestic cybersecurity-industry development, and the use of AI and other emerging technologies.Taiwan’s Phase Seven National Cyber Security Development Program, covering 2025 through 2028, adopts the same four areas. It calls for AI-assisted active defenses, greater ability to trace and disrupt threats, expanded cybersecurity training, and closer cooperation between government and private industry.The Ministry of Digital Affairs said Taiwan had also completed an amendment to the Cyber Security Management Act and established protective mechanisms covering preparation, active response, and recovery from cyber incidents.Lee said Taiwan has formed specialized teams to protect operational technology—the systems that run power plants, water networks, transportation infrastructure, and other physical operations.Those networks present different challenges from ordinary office computers, because many provide continuous public services and cannot be shut down immediately to install a security update.‘We Have Hours’Ogles said governments, intelligence agencies, and private companies may each detect only one part of a developing cyber operation.Taiwan could see one form of malicious activity, a U.S. company another, and an allied intelligence service a third, he said. Without rapid communication, no participant may recognize the larger operation until it is too late.“We don’t have months or years to respond to a zero-day vulnerability,” Ogles said. “We have hours, and communication is key.”A zero-day vulnerability is a previously unknown software or hardware flaw that defenders have had no opportunity to correct before attackers begin exploiting it.Ogles said Congress should ensure that the Cybersecurity and Infrastructure Security Agency has the authority and liability protections needed to exchange threat information with private companies in real time.Companies can be reluctant to disclose incidents because of concerns about customer privacy, civil lawsuits, criminal exposure, or reputational harm, he said.Ogles did not announce legislation during the forum.Chen, Coupang’s chief information security officer for Taiwan and Japan, said companies must also examine the defenses of contractors and suppliers that connect to their systems.Attackers frequently seek entry through smaller vendors whose security is weaker than that of the principal company, he said.Chen described vendor assessments, penetration testing, simulated attacks, bug-bounty programs, and tabletop exercises as layers of protection that should be in place before an actual incident.He said companies that compete intensely in business still need to exchange threat information because the same attackers may target all of them.From left: Xiaoxu Sean Lin, executive director of the Consilium Institute; Rep. Andy Ogles (R-Tenn.), chairman of the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection; and Hao-Wei Chen, Coupang’s chief information security officer for Taiwan and Japan, attend a panel on U.S.–Taiwan cybersecurity at the Chinese Freedom and U.S.–Taiwan Security Forum in Washington on July 21, 2026. Nan Lin/The Epoch TimesAI Makes Attacks Faster and Harder to SpotLee and Chen said AI is helping hackers increase the speed, scale, and precision of attacks.Attackers can combine previously stolen personal information with AI-generated language to produce phishing messages aimed at specific government employees or other targets, Chen said.Taiwanese recipients could previously identify some messages originating in China because they used mainland terminology or contained unnatural wording. AI can now remove many of those clues, he said.Lee described a recent incident in which attackers replaced an official registration QR code on a conference poster with a fraudulent version intended to collect personal information from people who scanned it.Lee said the stolen information could be sorted by profession or other categories and later used to prepare more targeted attacks.AI tools can also help identify vulnerabilities, reverse-engineer software patches, automate reconnaissance, and develop malicious code, the panelists said.Defenders can use the same technology to review code and sort large numbers of security alerts, but correcting a vulnerability may still require taking an essential service offline.Chen said automatic patching remains difficult for companies and infrastructure operators whose systems must run around the clock.They must identify the most important systems, prepare backups, and decide whether the danger from an uncorrected flaw outweighs the disruption caused by shutting a service down, he said.Disruption Beyond TaiwanLee said attacks against infrastructure outside Taiwan could also affect a conflict across the Taiwan Strait.If electricity, water, communications, transportation, or commerce were disrupted in countries capable of assisting Taiwan, those governments could be forced to concentrate on emergencies at home, he said.Ogles said Chinese hackers’ presence in foreign telecommunications and infrastructure networks raised the question of whether Beijing was preparing the ability to create widespread disruption during a future crisis.“I don’t know that they would ever do that, but they’re certainly preparing, in my opinion, as if,” he said.The panel also discussed the security of technology supply chains, including software, communications equipment, surveillance cameras, drones, and connected vehicles.Lee said equipment may appear to carry a Taiwanese or another non-Chinese brand while containing Chinese-made components that introduce cybersecurity risks.That claim would require product level verification before being applied to any named company or device.Taiwan Seeks Wider CooperationLee said Taiwan wants closer cybersecurity cooperation with the United States, Australia, Britain, Canada, and other democratic partners, particularly on critical infrastructure protection.He said exchanging threat intelligence is not sufficient by itself.Countries must also share practical defensive skills and build working relationships before an emergency occurs, he said.Ogles said the same principle applies among governments, intelligence agencies, companies, and universities.“Somebody’s going to see it first,” he said of a future major attack. “We’ll have seconds or minutes to react to it and to communicate.”Chen said Taiwan’s experience facing sustained cyber activity gives it material that could help security researchers and allied governments prepare for similar attacks.“Taiwan, we don’t have many natural resources,” he said. “But we have tons of malware samples.”
Taiwan Adviser Warns Major Cyberattack Could Foreshadow Chinese Invasion
Date:






