In two cyberattacks lasting more than 26 hours, the Chinese-language website of The Epoch Times was recently targeted with tens of billions of automated attempts to connect to the website or load its pages, using internet addresses around the world.
The distributed denial-of-service attacks were designed to overwhelm the website with traffic and disrupt access. Despite attackers repeatedly changing tactics, the website remained available to readers worldwide and no readers’ or subscribers’ personal information was accessed.
The first wave began at 5:42 p.m. ET on Sept. 10 and lasted about 11 hours. A second, larger wave began later that morning and continued for more than 15 hours, according to The Epoch Times’ IT department.
Together, the attacks generated about 50 billion malicious requests involving roughly 160,000 internet addresses identified as malicious across more than 200 countries and territories.
The Epoch Times informed federal authorities of the attack.
Prior Attack
The Epoch Times has previously been targeted in an operation that U.S. prosecutors allege was carried out by a Chinese regime contractor working with Chinese police and intelligence agencies.
In March 2025, the Justice Department charged eight employees of Shanghai-based Anxun Information Technology, known as i-Soon, and two officers of China’s Ministry of Public Security.
The Epoch Times has confirmed it was a target in the operation.
Prosecutors alleged that a Ministry of Public Security officer directed i-Soon to launch a DDoS attack against the newspaper in December 2016, temporarily knocking its website offline.
The indictment also alleges that i-Soon later accessed the email accounts of two senior Chinese-language Epoch Times executives and sold Chinese police a list of IP addresses used by readers inside China in an effort to help locate dissidents.
Attackers Changed Tactics
During th e latest incident, the attackers used several methods and changed tactics, according to the newspaper’s IT department.
One method flooded the server with a large number of incomplete connection requests, tying up resources needed by legitimate visitors. Attackers also sent a large number of ordinary-looking page requests to overwhelm the website’s processing capacity.
At the peak, malicious traffic exceeded 1 million requests per second.
Cloudflare, a major internet infrastructure and security company, classifies attacks above that level as “hyper-volumetric.” It also reported in August that media, production, and publishing were its most targeted industries for HTTP DDoS traffic—a digital traffic jam—during the first half of 2026.
Hackers can also route malicious traffic through compromised internet-connected devices in many countries, making the apparent source of an attack difficult to trace.
The National Security Agency (NSA) and allied cybersecurity agencies warned in April that China-linked threat groups were increasingly using such networks to conceal their operations.
The Epoch Times was founded in the United States in 2000 by Chinese Americans and has long reported on the Chinese Communist Party’s human rights abuses.
The newspaper’s IT department has recorded repeated attacks around dates and topics considered sensitive by the CCP.
The latest attacks occurred ahead of CCP leader Xi Jinping’s visit to the United States, scheduled for Sept. 23 to 25.






















