移至主內容

Hidden Threats to National Security:

Critical Infrastructure and Cybersecurity

Business Today
作者
Mattel Chien-Jung Hsu
expand_circle_down

Research Affiliate, Chinese Studies, Monash University

  • Cyberattacks on critical infrastructure carry outsized returns for attackers, as even a modest intrusion can escalate into a serious political crisis with wide social repercussions.
  • Cybersecurity for critical infrastructure goes far beyond information security. While IT security prioritizes confidentiality, critical infrastructure security prioritizes availability and safety.
  • In response to sustained infiltration and the threat of disruption by state actors such as China and Russia, countries are shifting from point-based defenses toward system-wide governance.
     

Early this year, Taiwan's National Security Bureau (NSB) released its "Analysis of China's Cyber Threats to Taiwan's Critical Infrastructure in 2025," reporting that Chinese state-backed actors launched an average of 2.63 million attacks per day against Taiwan, a 6% increase over 2024. The attacks were attributed to five major advanced persistent threat (APT) groups: BlackTech, Flax Typhoon, Mustang Panda, APT41, and UNC3886, targeting critical infrastructure in the energy, healthcare, communications, government, and technology sectors.

The appeal of targeting critical infrastructure lies in its outsized returns, even a modest intrusion can escalate into a full-blown political crisis with far-reaching social consequences. Importantly, attackers do not always strike in peacetime. They often infiltrate networks, lie dormant, and wait for a crisis to emerge or intensify before acting. Chinese hacking group Volt Typhoon's intrusion into critical infrastructure linked to U.S. military bases in Guam illustrates this pattern: the group remained embedded within Guam's networks for years without launching overt attacks, quietly pre-positioning itself to lay the groundwork for a potentially devastating strike should tensions escalate into conflict.

Differences Between CI/OT Cybersecurity and Traditional IT Cybersecurity

Taiwan has formally designated nine critical infrastructure (CI) sectors: energy, water resources, communications and transmission, transportation, finance, emergency rescue and hospitals, government administration, science and industrial parks, and food. Together, these sectors underpin the country's governance, economic operations, and social stability. An attack on any one of them can ripple across society, affecting multiple systems and institutions at once, setting CI cybersecurity apart from traditional IT cybersecurity as a matter of national security and societal resilience, not merely information security.

CI cybersecurity encompasses operational technology (OT), industrial control systems (ICS), and supervisory control and data acquisition (SCADA) systems. The core distinction between CI/OT and IT security lies in the values each is designed to protect. IT security prioritizes confidentiality, followed by integrity and availability; CI/OT security prioritizes availability and safety. Systems cannot be arbitrarily shut down, restarted, or updated in ways that disrupt control logic or production stability. Industrial control equipment tends to have long service lives, relies on proprietary protocols, and is often locked to a single vendor. Patching and upgrades are constrained by downtime costs, authentication procedures, and regulatory requirements, so legacy systems, weak authentication, and flat networks (in which all devices share the same switch) often persist for years, creating ideal conditions for attackers.

The attack paths targeting CI frequently span both IT and OT. Attackers may first compromise office networks (IT) to obtain credentials and administrative access, then move into production or control networks (OT), and finally strike controllers, operator stations, engineering workstations, or remote maintenance channels. In recent years, Western governments have repeatedly warned that Chinese state-linked actors strategically set the stage through OT network infiltration and pre-positioning—footholds that, when needed, can be escalated into attacks that disrupt or paralyze essential services.

Consequences and Impacts of Cyberattacks on Critical Infrastructure

Cyberattacks on CI do not merely result in data breaches or ransom demands; they can derail public services, threaten public safety, and trigger social panic and national governance crises. Damage to or manipulation of electrical dispatching systems or substations could cause regional blackouts, traffic signal failures, strain on hospital backup systems, and disruptions to cold-chain logistics and supply chains. Compromised water systems threaten public supply, interfere with chemical treatment processes, and erode public trust. Infiltration of telecommunications systems can disrupt government communications, financial transactions, emergency response coordination, and defense mobilization command chains.

When critical infrastructure comes under attack, the impact is rarely confined to a single system or institution. Because technological and social systems are deeply interconnected, an attack can trigger chain reactions that significantly affect public services, economic order, and national security.

First, cyberattacks on CI pose direct risks to public safety and human life. Unlike traditional IT incidents, which typically result in data breaches or service outages, OT security failures can have direct physical consequences. A ransomware attack on a hospital's systems could force the halt of surgeries or delay emergency care, directly endangering patients. Exploited water, power, or traffic control systems could lead to contaminated water supplies, large-scale blackouts, traffic accidents, or even industrial explosions and toxic leaks—resulting in environmental damage and casualties.

Second, economic losses and supply chain disruptions carry severe spillover effects. CI underpins every industry. Disruptions to power grids, telecommunications networks, ports, airports, or financial systems can escalate economic losses within hours. Even brief power outages can cause enormous losses in high-tech manufacturing. Hacked logistics or port systems can leave raw materials and goods backlogged, halting upstream and downstream operations, raising prices, and increasing pressure on households. Failures in financial clearing and payment systems could trigger market panic and capital flight.

Third, breakdowns in routine social operations and public panic are often the most immediate consequences of CI attacks. Prolonged power outages, water shortages, or telecommunications failures can quickly erode public confidence, triggering panic buying and hoarding and fueling social instability. If the government cannot promptly restore services, communicate clearly, and maintain control, public trust in the state's governing and protective capacities may deteriorate rapidly—an environment ripe for disinformation and cognitive warfare.

Fourth, because critical infrastructures are deeply interdependent, risks are far more difficult to predict and contain. Power outages do not just disrupt electricity supply; they can also disable telecommunications stations, rendering emergency communication systems inoperable. Energy disruptions can, in turn, affect transportation, healthcare services, and the deployment of emergency responders. This kind of cross-sector cascade can exceed the response capacity of any single institution or industry.

Finally, critical infrastructure is increasingly exploited by state-level adversaries in gray-zone operations, giving CI attacks serious national security and geopolitical implications. Through long-term infiltration and pre-positioning, attackers can paralyze essential services during a crisis, weaken military and governmental response capabilities, or collect high-level communications and decision-making intelligence, ultimately undermining a nation's autonomy in diplomatic and security affairs.

Chinese and Russian Cyber Operations Need Close Monitoring

The first documented cyberattack on critical infrastructure was the 2000 Maroochy Shire sewage treatment incident in Australia, in which the attacker gained unauthorized access to the industrial control system, remotely manipulated equipment, and repeatedly released untreated sewage—causing tangible harm to the environment and public health. The breach demonstrated that cyberattacks were already capable of affecting physical infrastructure. The 2010 discovery of Stuxnet, which used highly sophisticated malware to sabotage Iran's nuclear facilities, marked another turning point, widely regarded as the beginning of state-level cyber weapons. It fundamentally reshaped global perceptions of threats to CI and transformed how governments approach cybersecurity.

Geopolitical tensions have only intensified since then. Over the past decade, Russian cyberattacks on Ukraine's critical infrastructure have become one of the most representative cases of hybrid warfare, running parallel to military action to weaken state functions and societal resilience. Russia began targeting Ukraine's CI in 2015, when hackers used BlackEnergy 3 malware to infiltrate Ukrainian power companies and remotely manipulate substations; the resulting outages affected approximately 230,000 people in western Ukraine—the first known instance of a cyberattack-induced blackout. In 2016, the more advanced Industroyer malware, purpose-built to target power grids, caused outages in parts of Kyiv, signaling the emergence of automated attacks on industrial control networks. In 2017, NotPetya spread through the supply chain of a Ukrainian tax accounting software provider; although aimed primarily at Ukrainian government and infrastructure targets, it spiraled out of control and caused more than US$10 billion in damages worldwide.

Cyber operations intensified further in the lead-up to and aftermath of Russia's full-scale invasion of Ukraine in 2022. On the eve of the invasion, multiple wiper malwares, including HermeticWiper, were deployed to cripple Ukrainian government and financial systems. About an hour before the invasion began, Viasat's satellite network was hacked, disrupting early-stage command and communications. That April, Russia attempted to deploy Industroyer2 to manipulate a high-voltage substation, though the attack was detected and thwarted. From 2023 to 2024, Russian operations expanded to target telecommunications and transportation, including a large-scale outage at Kyivstar and prolonged disruption to railway and logistics systems. These developments suggest Russia has made cyberattacks on critical infrastructure a long-term strategic tool.

There are growing indications that China and Russia are increasingly aligned in cyber operations and online disinformation campaigns. China fields several APT groups that target CI, including Volt Typhoon, known for prolonged, stealth operations. Western governments assess that Volt Typhoon has pre-positioned itself within the IT networks of critical infrastructure in democratic countries, positioning it to disable essential services during periods of geopolitical tension or conflict. Another group identified by Microsoft, Flax Typhoon, has targeted multiple countries including Taiwan, affecting government agencies, educational and research institutions, and technology and telecommunications organizations. Meanwhile, Salt Typhoon has focused on telecommunications and network equipment across various countries.

Among Russia's APT groups, Sandworm is the most well-known. Linked to the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU), its operations closely overlap with destructive campaigns such as the Ukrainian power outages and the deployment of the Industroyer and Industroyer2 malware.

How Chinese and Russian CI APT Attacks Relate to Geopolitics and National Security

State-sponsored hacking groups in China and Russia target not only their primary geopolitical rivals, such as Taiwan and the United States, but also countries with no clear or direct conflict of interest. Singapore, for example, has identified long-term infiltration of its critical infrastructure by Chinese APT actors.

According to analysis by Mandiant, Google's cybersecurity subsidiary, recent cyberattacks on Singapore's critical infrastructure are primarily attributed to the Chinese APT group UNC3886. The group's highly covert operations and long-term infiltration go well beyond ordinary cybercrime, specifically targeting entities of significant strategic value. Mandiant notes that UNC3886 is particularly adept at exploiting zero-day vulnerabilities and edge devices—such as firewalls, VPNs, virtualization platforms, and routing equipment—to bypass traditional security monitoring. The group then quietly establishes stable, sustained access to target networks in telecommunications, energy, and government—key components of critical infrastructure. Its primary objective is not financial gain but long-term intelligence collection and strategic pre-positioning amid geopolitical competition.

The Singapore government has publicly identified these threats as a national security risk, signaling that the activities are understood as part of broader geopolitical and gray-zone competition. Overall, Google's analysis indicates that China-linked APT operations targeting Singapore's critical infrastructure are centered on long-term infiltration, control over critical nodes, and building capabilities that could be leveraged to exert influence during future crises.

A New Normal: Cybersecurity, Geopolitics, and Hybrid Warfare

China and Russia's substantial investment in cyber operations against foreign critical infrastructure must be understood in the context of contemporary geopolitical tensions and the evolving nature of warfare. Compared to conventional military measures, cyberattacks are a low-cost, controllable, and strategically valuable asymmetric tool.

First, cyberattacks are the cheapest form of asymmetric deterrence. Missiles and military operations can cost tens of millions of dollars and risk triggering direct armed conflict. Large-scale cyberattacks that disable power grids or communications networks require far less investment while producing comparable social and political impact. Such attacks are also difficult to attribute, allowing China and Russia to pressure democratic states without provoking full-scale war.

Second, cyberattacks are a crucial tool for paralyzing an adversary's logistical and support networks. Modern warfare depends heavily on civilian power, transportation, and communications systems. Crippling these at the outset of a conflict could severely hinder troop movement and allied support, delaying military operations.

Finally, critical infrastructure is a key testing ground for societal resilience under hybrid warfare. When disruptions to essential services trigger public panic, adversaries can pair disinformation with cognitive operations to convert social unrest into political pressure, compelling governments to concede without a shot fired.

Given this geopolitical climate, cybersecurity for critical infrastructure can no longer be addressed through technical measures alone—it must be treated as a matter of national security. A resilient critical infrastructure makes for a resilient nation. Facing sustained infiltration and attacks by state-level actors such as China and Russia, countries are gradually shifting from point-based defenses to systemic governance: conducting asset inventories and network segmentation, proactively identifying threats, managing supply chains and remote operations, running cross-sector exercises and recovery planning, and treating continuous operations as sensitive information.

Ultimately, the cybersecurity of critical infrastructure concerns societal resilience, democratic governance, and national security alike. Systems will inevitably be targeted and infiltrated. Future security strategies must therefore emphasize rapid recovery, implement zero-trust architectures to limit lateral movement, and foster regional cooperation and intelligence-sharing among democratic nations. With critical infrastructure now at the heart of geopolitical competition, cybersecurity has become a core element of national governance and societal readiness.

The battle for survival on the digital frontier has only just begun. Beyond power switches and data packets, it is strategic foresight and political resolve that will ultimately determine a nation's survival.