AI Fuels Ransomware Attacks: ACS Urges Implementation of Four Key Protective Measures
Date: 27 July 2026
Media Contact:
Director Lee, Yu-Wei
Tel: +886 920-072-628
Ransomware attacks continue to escalate. The Administration for Cyber Security (ACS), Ministry of Digital Affairs, has stated that in recent years hackers’ tactics have evolved from traditional file-encryption extortion into a “double extortion” model that combines data theft with the threat of public disclosure. Coupled with generative AI technology, which has made attacks more automated and more precise, this shift has driven a rapid increase in incidents worldwide. The ACS is urging members of the public, businesses and government agencies to make regular system backups, keep software up to date, strengthen account and password security, and guard against social engineering as part of their everyday practice. It further advises victims never to pay a ransom, noting that building sound cyber security awareness and maintaining routine protective measures can effectively reduce the impact of an attack.
The ACS states that ransomware commonly gains entry through phishing emails, malicious websites, system vulnerabilities or illegal software, and that advances in generative artificial intelligence (AI) have substantially increased both the precision and speed of attacks, driving a sharp rise in incidents worldwide. Manufacturing, the service sector and healthcare institutions are the principal targets; once compromised, organisations may face serious consequences such as data loss, service disruption, financial losses and reputational damage. To reduce the risk of infection, the ACS recommends raising cyber security awareness on an ongoing basis and bearing in mind the following key points:
Maintain regular system backups: Establish a habit of regular backups using the “3-2-1 rule” (at least three copies of data, stored on two different types of media, with one copy kept off-site), ensuring that data remains available for rebuilding and recovery in the event of an encryption attack.
Keep systems and software up to date: Keep operating systems, applications and antivirus software updated, patching vulnerabilities promptly to close off potential points of entry.
Strengthen account and password security: Use more complex passwords and avoid reusing the same password across different platforms. Enabling two-step verification, or using a password manager to generate and manage passwords, is also recommended.
Guard against social engineering: Remain alert to unfamiliar text messages, emails and links; avoid clicking on them or downloading attachments without due care, particularly given the risk posed by highly convincing AI-generated lures.
Should a ransomware attack be suspected, the following measures should be taken immediately:
1. Immediate response
(1) Disconnect from the network / isolate the infected device immediately: Cut off network connections (e.g. unplug network cables, disable Wi-Fi and Bluetooth) to prevent the ransomware from spreading further.
(2) Do not pay the ransom: Payment offers no guarantee that data will be recovered, and may only encourage further criminal activity.
(3) Preserve screenshots and evidence: Retain ransom notes, email records and related files, as these will assist any subsequent investigation and tracing.
(4) Seek assistance from cyber security experts: Engage cyber security specialists or vendor teams to help identify how the intrusion occurred and determine whether any data has been leaked.
2. Post-incident recovery
(1) Report the incident and notify the relevant authorities: File a report with the police and notify TWCERT/CC, providing supporting evidence to assist with the investigation.
(2) Change passwords for important accounts: Immediately change the passwords for all important accounts and enable two-factor authentication to reduce further risk.
(3) Rebuild systems and restore from backup: Reinstall a clean system and restore data from backups that have not been compromised, confirming both data integrity and system security.
The ACS notes that ransomware forcibly encrypts important files on a victim’s computer (such as documents, images and databases), rendering them inaccessible to the user. The attacker then demands payment of a ransom in exchange for the decryption key. Recent attack patterns show that attackers frequently steal sensitive information before encrypting files, then threaten to publish the data in order to place further psychological and financial pressure on victims. According to the FBI’s 2025 Internet Crime Report, published by the US Federal Bureau of Investigation, 3,611 ransomware complaints were received in 2025, an increase of around 14% on the 3,156 complaints recorded in 2024. Direct financial losses rose sharply from approximately USD 12.47 million to more than USD 32.32 million, an increase of around 160%, indicating that ransomware attacks are becoming both more frequent and more economically damaging.
According to publicly available information from Taiwan’s competent authorities and material announcements made by listed companies, at least seven named businesses and medical institutions in Taiwan publicly disclosed being affected by ransomware or ransomware-virus attacks in 2025, with the affected parties spanning the healthcare, electronic components, automotive parts, pharmaceutical and plastics manufacturing sectors. As of 22 July 2026, at least a further five companies had publicly disclosed ransomware-virus attacks, across industries including paper manufacturing, biotechnology manufacturing, semiconductor equipment and electronic components.
The ACS stresses that ransomware techniques are constantly evolving, and that only by keeping information and communication systems secure and performing regular backups can organisations effectively prevent compromise or mitigate losses. It calls on members of the public, government agencies and businesses to implement the relevant cyber security protective measures, so as to jointly strengthen Taiwan’s overall cyber resilience.