www.theepochtimes.com Epoch Times Website Targeted by Massive DDoS Attack Ahead of Xi Jinping's Visit
Article Content
- •The Epoch Times faced two waves of DDoS attacks generating 50 billion requests.
- •Attackers used over 160,000 malicious IP addresses from more than 200 countries.
- •The attacks coincided with Xi Jinping's upcoming visit to the U.S.
The Chinese-language website of The Epoch Times experienced two significant cyberattacks lasting over 26 hours, generating approximately 50 billion malicious requests. The first wave began on September 10, 2026, and lasted 11 hours, while a second wave commenced later that day, continuing for more than 15 hours. Attackers utilized over 160,000 malicious internet addresses from more than 200 countries, overwhelming the website's processing capacity. The attacks were characterized as hyper-volumetric, with peak traffic exceeding 1 million requests per second. The Epoch Times has a history of being targeted, allegedly due to its reporting on the Chinese Communist Party (CCP). The attacks coincided with sensitive dates related to the CCP, specifically ahead of Xi Jinping's visit to the U.S. scheduled for September 23-25, 2026. The Epoch Times has reported the incident to federal authorities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track The Epoch Times in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…