Taiwan's 2.6 million daily cyberattacks test cover boundaries
Attribution rules may determine whether policies respond
Taiwan's 2.6 million daily cyberattacks test cover boundaries
CYBER
By Mav Rodriguez
23 Sep 2026

Taiwan’s claim that it faces 2.6 million cyberattacks a day is putting state-backed attack exclusions under fresh scrutiny, particularly for businesses that may be targeted for geopolitical rather than purely financial reasons.

Digital Affairs Minister Lin Yi-jing disclosed the figure as Taiwan launched an annual Cyber Day on Sept. 21, aligning digital preparedness with the country’s National Disaster Prevention Day.

“Hackers, particularly in China, North Korea, Iran and Russia, show a special interest in Taiwan and launch online attacks daily,” Yi-jing said.

Taiwan’s Ministry of Digital Affairs has previously cited the same daily attack volume, saying the sustained pressure has given its cybersecurity industry extensive experience in responding to live threats.

The figure does not mean that 2.6 million systems are breached each day. No methodology was published alongside it, and the count could include scans, probes and attacks blocked before causing damage. The more consequential questions are what happens when defenses fail and whether the resulting loss falls inside the policy.

A growing but uneven insurance market

Taiwan’s cyber insurance market has expanded alongside that threat. Financial Supervisory Commission data show that premiums rose from NT$89.08 million in 2018 to NT$512 million in 2025. Semiconductor companies generated the largest share last year at 28.87%, followed by computer and peripheral equipment businesses and financial institutions.

The composition of that premium is as important as its growth. Data-protection liability policies accounted for NT$448 million of the 2025 total, while comprehensive cyber cover generated NT$46 million and policies covering unlawful intrusion into information systems contributed NT$18 million.

That mix suggests much of the market remains weighted toward third-party liability arising from personal-data breaches rather than broader protection for ransomware, operational interruption and other first-party losses. Sixteen non-life insurers offered cyber products in Taiwan last year, according to the regulator.

State links put exclusions in focus

Cyber policies commonly contain war or state-backed attack exclusions, but establishing a government’s role can take time. The treatment of collateral damage and attacks that spread beyond an intended target can also vary between wordings.

Debate over state-backed cyber exclusions has centered on how attribution should be established and whether insureds could be left waiting for a coverage decision while an investigation continues.

Under Lloyd’s requirements for state-backed cyber wording, noncompliant clauses cannot be used on new or renewed business, while cover for cyberattacks carried out as part of a conventional war must be provided through a clear and separate affirmative grant.

A placement therefore needs to be tested beyond whether it contains a war exclusion. The operative questions include how it defines a state-backed attack, what evidence is required for attribution, whether a threshold of harm must be met and how collateral damage is treated.

Taiwan’s reporting rules add time pressure to that review. Designated critical-infrastructure providers must report cyber incidents within one hour of becoming aware of them. Failure to report can attract fines of between NT$300,000 and NT$10 million.

That timetable leaves little room to determine responsibilities after an event. Notification requirements, access to insurer-approved response specialists and coordination among legal, forensic and insurance teams need to be established before a breach.

Deepfake scams cross policy lines

Taiwan’s threat environment is not confined to network intrusion. National Security Bureau data cited at the Cyber Day launch showed scammers combining deepfake videos, fraudulent billing information and text messages to deceive users.

The trend extends across the region. INTERPOL found that deepfake discussions on criminal forums rose 600% between February and June 2024, while Asia-Pacific users clicked phishing links at roughly twice the global average.

Those tactics can blur the boundary between cyber and crime cover. A compromised network, impersonated executive and authorized transfer may engage separate clauses, sublimits or exclusions governing computer fraud, social engineering and voluntary payments. Payment verification and call-back procedures can therefore matter as much as technical controls.

Cyber Day is intended to push security beyond government agencies and corporate IT departments. Digital Trust Association chair Nicole Chan said “a mobile phone and a password are the first lines of defense for national security in the digital world.”

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB ASIA.