Taiwan

Country

Taiwan’s High-Speed Railway, THSR, Shut Down

April 5, 2026

Four trains in Taiwan ended up stopped for 48 minutes last month by an attacker using software-defined radio (SDR) communications and handheld radios to transmit a high-priority “General Alarm” signal. That signal triggered emergency braking procedures.
As a result of that incident, a 23-year-old university student in Taiwan is now under arrest suspected of interfering with the TETRA communication system April 5 used by the country’s high-speed railway network (THSR).
THSR is a high-speed railway network in Taiwan that runs a single 350 km (217 miles) two-way line along the western coast of the country, with trains reaching speeds of up to 186 mph (300 km/h).

read more

Ransomware Attack at Circuit Board Maker Unimicron

January 30, 2025

Unimicron Technology ransomware attack impacted its China-based subsidiary. Unimicron did not confirm a data breach, stating the impact of the attack is limited. The manufacturer engaged an external cyber forensic team to conduct incident analysis. Sarcoma ransomware group has claimed the attack and listed the attack on its Tor-based leak website on February 11.

The cybercriminals are threatening to make the stolen data public in less than a week unless a ransom is paid. The samples leaked on its extortion portal appear authentic.

read more

Taiwan United Renewable Energy Corporation Confirms Cyberattack

April 11, 2024

Taiwan United Renewable Energy Corporation announced that due to a cyberattack on some information systems, the factory is currently shut down and the impact on the company’s finances is still being evaluated.

The company’s information department has fully launched relevant defense mechanisms and recovery operations, and is coordinating with technical experts from external information security companies.

read more

RansomHub Breaches Network of Taiwanese Laptop Manufacturer

June 4, 2024

Clevo, a leading manufacturer of customizable gaming laptops, was claimed Monday by RansomHub, the cybercriminal gang recently involved in publishing stolen data from UnitedHealth Group’s Change Healthcare hack.
RansomHub claims to have breached the Taiwanese laptop maker by social engineering and phishing an employee.

“All network and backups are fully encrypted. We took care of it. The company has no chance to recover. Only our decryptor will help them to get back to work, nothing else will help them, “ the hacker group posted on their leak site.

read more

Acer Confirms Employee Data on Hacker Platform

March 12, 2024

Acer Philippines confirmed that employee data was stolen in an attack on a third-party vendor who manages the company’s employee attendance data. “Earlier today a threat actor known as ‘ph1ns’ published a link to download a stolen database containing Acer employee data for free on a hacking forum.”

read more

Taiwan Semiconductor Manufacturer Hit by Lockbit Ransomware Gang

January 17, 2024

One of Taiwan’s biggest semiconductor manufacturers has fallen victim to a cyberattack, supposedly carried out by the notorious LockBit ransomware gang. The hackers posted a threatening message on Foxsemicon’s website, stating that they had stolen its customers’ personal data and would publish it on their darknet website if the company refused to pay. The company’s website, however, could not be accessed as of Wednesday afternoon Eastern U.S. time, while Google search results still display the hackers’ message

The tactic used in the attack on Foxsemicon is atypical for LockBit: Usually, they post the names of the victims on their extortion website rather than deface the company’s web page.

read more

TSMC Hit by WannaCry Variant

August 3, 2018

The cyber attack on iPhone supplier TSMC was apparently caused by a WannaCry variant, the company has revealed. The severity of the attack caused the company to shut down some of its factories while the issue was fixed, which meant some plants were out of action for days. Although the problem has mostly been rectified now, it says it’s still expecting shipments to be delayed for some time.

The virus was injected into TSMC’s systems when a supplier reportedly installed infected software onto some of its machines, without running an antivirus scan. The infection then spread to other locations within the company’s network in Tainan, Hsinchu and Taichung, which caused the majority of its facilities to close down temporarily.

The attack may have cost the iPhone component manufacturer up to 3% of revenues and could cost Apple over $255M

read more

Employee of Taiwanese D-Link Falls for Phishing Leading to Data Breach

October 10, 2023

D-Link Corporation, a Taiwanese networking equipment, confirmed a data breach linked to information stolen from its network and put up for sale on BreachForums earlier this month.
The intrusion vector was likely an employee who unintentionally fell victim to phishing. The attacker claims to have stolen source code for D-Link’s D-View network management software, along with millions of entries containing personal information of customers and employees, including details on the company’s CEO.

read more

Confusion About $70M Ransom Demand: Kinmax or TSMC ?

June 29, 2023

“In the morning of June 29, 2023, the Company discovered that our internal specific testing environment was attacked, and some information was leaked,” reads the Kinmax statement.
“The leaked content mainly consisted of system installation preparation that the Company provided to our customers as default configurations.”

The Lockbit ransomware group claimed to have hacked chipmaker giant TSMC. TSMC stated its supplier Kinmax was attacked. Kinmax is not the corporate giant that TSMC is, so LockBit’s demands for a $70 million ransom payment will likely be ignored.

While there appears to be a mixup as to who was compromised in this attack, the $70 million ransom demand is one of the largest seen to date.

read more

Lockbit Demands $70M of TSMC Chipmaking Giant

June 28, 2023

Chipmaking giant TSMC denied being hacked after the LockBit ransomware gang demanded $70 million not to release stolen data.

On Wednesday, a threat actor known as Bassterlord, who is affiliated with LockBit, began to live tweet what appeared to be a ransomware attack on TSMC, sharing screenshots with information related to the company. While this Twitter thread has since been deleted, the LockBit ransomware gang created a new entry for TSMC yesterday on their data leak site, demanding $70 million or they would leak stolen data, including credentials for their systems.

A TSMC spokesperson told BleepingComputer that they were not breached, but rather the systems of one of their IT hardware suppliers, Kinmax Technology, were hacked. “Upon review, this incident has not affected TSMC’s business operations, nor did it compromise any TSMC’s customer information.”

Apart from validating that its systems had not been impacted in any way, TSMC states that it also stopped working with the breached supplier until the situation cleared up.

read more