CSIDB logo
Incident

Taiwan

Incident posture

Attack window
Jan 2018
Location
Taiwan
Status
Historical
CIA posture
Available to members
Updated
2025-11-30 00:00

Linked entities

Victim
Taiwan
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
Jan 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Chinese hackers compromised over 6,000 email accounts across multiple government agencies in Taiwan as part of a cyber espionage campaign linked to groups such as Blacktech and Taidoor. Officials described the infiltration as causing significant damage, prompting public disclosure to mitigate further harm. The incident occurred amid heightened geopolitical tensions, with Taiwan attributing persistent cyber incursions to China following political leadership changes and disputes over sovereignty claims.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Chinese hackers compromised approximately 6,000 email accounts across at least 10 Taiwan government agencies in a cyber espionage campaign first detected in 2018. Taiwan's Investigation Bureau Cyber Security Investigation Office attributed the attacks to China-linked threat groups tracked as Blacktech and Taidoor, which systematically targeted government entities and information service providers. Deputy Director Liu Chia-zung confirmed the email breaches while acknowledging ongoing damage assessments, stating the infiltration caused "not small" harm. The government disclosed the incident publicly to raise awareness and mitigate further compromise. This campaign formed part of sustained cyber operations against Taiwan since 2016, coinciding with President Tsai Ing-wen's election and her administration's refusal to recognize Beijing's "one China" sovereignty claim over the self-governed island.

Taiwanese officials characterized the attacks as an escalation of Chinese cyber aggression accompanying increased diplomatic pressure, economic sanctions, and military exercises near Taiwan. While investigators confirmed the email account compromises, they continued evaluating the full operational impact on government systems. The Cybersecurity Investigation Office maintained active monitoring of Blacktech and Taidoor activities while coordinating response efforts across affected agencies. Historical context indicated Beijing intensified cyber operations following Tsai's 2016 inauguration, with this incident representing a confirmed continuation of that pattern through at least 2020. No specific data exfiltrated or subsequent misuse of breached accounts was detailed in public disclosures.

Sources

Sources available to members: 1 source.

CSIDB