Taiwan's state-owned electricity provider endures an average of 30,000 cyberattacks every day — a figure that ballooned to over three million across just three days when then-U.S. House Speaker Nancy Pelosi touched down in Taipei in August 2022. The disclosure, made publicly for the first time by a senior Taipower executive last weekend, lays bare the scale of digital warfare quietly targeting the island's most essential infrastructure.
Wu Chin-chung (吳進忠), Deputy General Manager and Chief Digital Officer of Taiwan Power Company (台灣電力公司, Taipower), made the remarks on Saturday, June 6, at the annual international forum of the Science, Technology, Democracy and Society Research Center (DSET), a think tank affiliated with the National Science and Technology Council. The event, the "Supply Chain Resilience Strategy International Summit," convened experts from Taiwan's public and private sectors alongside international partners to discuss cooperation on semiconductors, artificial intelligence, energy security, robotics, and drone supply chains free of Chinese components.
Pelosi's Visit as a Stress Test
Wu was standing in for Taipower Chairman Tseng Wen-sheng (曾文生) at a session examining Taiwan's energy resilience through the lens of cross-strait war-game scenarios and Ukraine's wartime experience. Responding to an audience question about the frequency of cyberattacks on the power grid, Wu laid out the numbers with unusual candor.
"The average daily attack count is 30,000," he said. "But during sensitive moments, the number climbs sharply. About three years ago, after Pelosi arrived in Taiwan, we faced more than three million attacks within three days — which is why we cannot treat power sector cybersecurity as an afterthought."
Wu attributed Taipower's heavy exposure in part to its unique position within Taiwan's critical infrastructure registry: it holds more designated assets than any other government-affiliated entity on the island. The company classifies its infrastructure across three tiers — A, B, and C — with national agencies conducting annual inspections of Tier A assets. Wu noted that attackers rarely go after hardened targets; instead, they probe for weak points, which is why Taipower concentrates its internal resources on Tier C, its most vulnerable systems.

A Multilayered Defense, With Allied Backup
Taipower's cybersecurity framework spans four domains: information technology (IT) security, operational technology (OT) security, international cybersecurity cooperation, and governance. Wu said that for critical infrastructure assets, both IT and OT systems operate under around-the-clock monitoring, seven days a week.
The company works closely with the Administration for Cyber Security (資通安全署) under the Ministry of Digital Affairs and the Cyber Command (資通電軍指揮部) under the Ministry of National Defense. Wu also singled out two allies. "We are particularly grateful to the United States and the United Kingdom for their significant assistance," he said, citing joint exercises, threat-hunting workshops, and security assessments conducted with both countries in recent years.
Taiwan in the Crosshairs of a Global Trend
The Taipower revelations arrive in a broader strategic context. Since Russia's annexation of Crimea in 2014, cyberattacks have become a standard precursor to — and companion of — geopolitical hostilities worldwide. Distributed Denial of Service attacks, or DDoS — which overwhelm target systems with massive volumes of traffic to knock them offline — have been deployed in conflicts stretching from eastern Ukraine to the Korean Peninsula.
Taiwan experienced a preview of this playbook in the days before Pelosi landed. Government websites, including those of the Presidential Office and the Ministry of Foreign Affairs, came under sustained DDoS fire from overseas. Traffic to the Presidential Office site reportedly hit 200 times its normal volume, temporarily taking it offline entirely.
The island is no stranger to this kind of pressure. In November 2019, Chien Hung-wei (簡宏偉), then-Director of the Executive Yuan's Department of Cybersecurity, told participants at the first large-scale joint Taiwan-U.S. government cyber defense exercise that Taiwan's government agencies absorb roughly 30 million foreign cyberattacks every month, with an estimated half traced to China.
Following Russia's full-scale invasion of Ukraine in February 2022, cybersecurity analysts across the Asia-Pacific have documented a marked rise in attacks on civilian infrastructure, with geopolitical instability providing both cover and incentive for state-linked hackers. Taiwan, sitting at the intersection of cross-strait tensions and Indo-Pacific competition, has long been treated as a high-value target for sophisticated cyber operations.
Wu's public remarks signal that Taiwan is no longer treating this as a classified matter — and that the island's defenders are not standing alone. (Related: Taiwan's Nuclear-Free Anniversary Is a Reckoning, Not a Celebration | Latest )



































