Taiwan accused China-linked hackers of infiltrating Taiwanese companies that provide info services to government bodies, to steal citizens' personal data
Context & Ripple Effects
This 2020 accusation is the early entry point of a campaign Taiwan has been documenting ever since: China-linked hackers are not attacking government systems head-on but working through the private info-services firms that sit inside them. Five years on, Taiwan's National Security Bureau put numbers on the escalation, reporting that daily cyberattacks on government departments had doubled year over year to 2.4M in 2024, attributing most to Chinese cyber forces.
The method has also matured. By mid-2026, researchers found suspected Chinese hackers using open-source AI agents to build an autonomous tool that compromised Taiwanese government websites — the same target set, now with machine-speed tooling instead of manual intrusion.
First-order effects
- Taiwanese info-service providers to government bodies become both victims and vectors — their systems hold citizens' personal data, and every agency they serve inherits the exposure.
- Taiwan's security apparatus must shift its defense perimeter outward from ministries to the commercial contractors feeding them data.
Second-order effects
- Government procurement in Taiwan faces pressure to impose breach-audit and hardening requirements on IT vendors, turning supplier security into a condition of public contracts.
- The playbook is not Taiwan-specific: the same attribution pattern surfaced when Chinese hackers breached the US Treasury and accessed 400+ computers, signaling that Western governments' vendor ecosystems are targets under identical logic.
Third-order effects
- If supply-chain infiltration stays the preferred route, the structural consequence is that any company holding a government data contract becomes part of the national attack surface — blurring the line between civilian IT services and critical infrastructure defense.
- The trajectory across the corpus runs from human-operated intrusions in 2020 toward autonomous AI-built hacking tools by 2026, suggesting the constraint on such campaigns shifts from operator capacity to tooling availability.
The trend: State-linked cyber operations against Taiwan are scaling along two axes at once — from direct government attacks to supply-chain compromise of service providers, and from manual intrusion to AI-automated tooling.