VOOZH about

URL: https://thenewstack.io/as-geopolitical-tensions-rise-so-do-opportunities-for-cybercriminals/

⇱ As Geopolitical Tensions Rise, So Do Opportunities for Cybercriminals - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2022-10-12 10:00:49
As Geopolitical Tensions Rise, So Do Opportunities for Cybercriminals
contributed,
Security / Tech Culture

As Geopolitical Tensions Rise, So Do Opportunities for Cybercriminals

Examining the threat landscape over time reveals the relationship between rising geopolitical tensions and DDoS activity.
Oct 12th, 2022 10:00am by Richard Hummel
👁 Featued image for: As Geopolitical Tensions Rise, So Do Opportunities for Cybercriminals
Image via Pixabay.

When several official government websites in Taiwan were taken down by a series of distributed denial of service attacks (DDoS) in early August, the timing was not random.

The attacks — which targeted the office of Taiwan’s President, its National Defence Ministry, and its Foreign Affairs Ministry — came as U.S. House Speaker Nancy Pelosi was set to visit the island. For Pelosi, the visit demonstrated an “unwavering commitment to Taiwan’s democracy.” For China, which claims Taiwan is a renegade province, the visit was a threat to the peace of the Taiwan Strait.

Hours before Pelosi’s plane touched down at Taiwan Taoyuan International, which was also targeted, the office of Taiwan’s president said it had received 200 times more traffic than on a normal day. As a result, the site was down for approximately 20 minutes.

These attacks are politically motivated, with strong evidence that they were launched by pro-China, patriotic threat actors rather than the government itself. Unfortunately, it is another example in which DDoS attacks are used as geopolitical protest, waged to impact governments and critical infrastructure worldwide. With this trend on the rise, organizations must act now to protect themselves.

DDoS Activity Follows Geopolitical Crises in APAC

Examining the threat landscape over time reveals the relationship between rising geopolitical tensions and DDoS activity. For example, while most geographical regions experienced a decline in the number of DDoS attacks during the last six months of 2021, one outlier saw an uptick in DDoS activity — Asia Pacific (APAC). As detailed in NETSCOUT’s 2H 2021 Threat Intelligence Report, this region accounted for more than 1.2 million attacks during the second half of 2021, representing a seven percent increase from the first half of the same year.

This uptick in attack activity mirrors the rising geopolitical tensions in the region, specifically between China, Hong Kong, and Taiwan. Historically speaking, China has engaged in the use of DDoS attacks as a tool to disrupt online traffic and activities. As such, the number of attacks in APAC increased alongside growing geopolitical unrest in the region is of little surprise, with threat actors operating in the area taking advantage of this unrest by launching DDoS attacks to cause maximum disruption.

To better understand how threat actors use cyberattacks in relation to geopolitical tensions, there are several examples of attacks and incidents relating to the APAC region during the second half of 2021. In July, China was widely condemned for launching a series of cyberattacks, ranging from cyber extortion and crypto-jacking to hacks and ransomware. Targets of the attack, including the U.S., UK, and other global allies, believed the attacks were aiming for the capture of trade secrets, business intelligence and vaccine studies.

In November 2021, the director of Taiwan’s cybersecurity department claimed that the island’s government agencies were targeted by an estimated 5 million cyberattacks and probes per day. Furthermore, Taiwan officials claimed that China had increased the number of cyberattacks launched against its government and organizations in direct correlation to China’s attempts to make the island a part of its own territory. Finally, at least 13 organizations in industries that included defense, healthcare, and transportation were targeted by a suspected Chinese cybersecurity campaign in December. Vulnerable software in more than 600 U.S. businesses played a significant role in this breach taking place.

Security for Organizations in Impacted Nations

When countries experience heightened geopolitical tensions, organizations within their borders can take several steps to prevent DDoS attacks from devasting their online infrastructure.

Perhaps most importantly, enterprises must implement a sturdy DDoS mitigation system to protect their online infrastructure. Secondly, service providers and companies with business-critical public-facing internet properties must maintain a high degree of situational awareness, and continually assess potential risks. During periods of geopolitical unrest, the situation constantly shifts, requiring organizations to keep abreast of what’s happening and how events may impact the threat landscape.

Regular testing of online infrastructure is crucial to prove that updates and adjustments to applications, assets, and services integrate with the DDoS mitigation strategy. Conversely, when the DDoS protection system is adjusted or optimized, those updates must be tested against all of the infrastructural components. A robust testing and validation regime ensures that mission-critical, public-facing features aren’t impacted by an attack.

Because they are relatively inexpensive and easy to pull off, protestors and activists will continue to rely on DDoS attacks to disrupt businesses and governments on behalf of their own nations. And even if they don’t have the approval of their government themselves, these actors are more likely to take advantage of political chaos. Organizations, whether government or business, don’t need to be collateral damage, because the tools and services to mitigate DDoS attacks are widely available.

TRENDING STORIES
Richard Hummel has over a dozen years of experience in the intelligence field and is currently the Threat Intelligence Research Lead for NETSCOUT's ASERT Research Team. Previously, he served as Manager and Principal Analyst on the FireEye iSIGHT Intelligence’s Financial...
Read more from Richard Hummel
SHARE THIS STORY
TRENDING STORIES
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.