Safeware Glasswall APAC Partner
Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Control alignmentAPAC regulatory landscape
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongolia

More

Trust & certificationsInsightsPartnersAboutDocumentation Book a demo

Language

EnglishBahasa Indonesia日本語한국어Bahasa MelayuไทยTiếng Việt简体中文繁體中文

File-borne breach events · East Asia

Taiwan: documented file-borne breach events

Taiwan's record runs from the 2016 First Commercial Bank ATM heist, traced by investigators to a spear-phishing email, to D-Link's own 2023 confirmation that a phished employee was the route into its systems.

Overview

What the record shows

Taiwan investigates and prosecutes cyber incidents more visibly than most of the region, through the Ministry of Justice Investigation Bureau, and the 2016 First Commercial Bank heist is its best documented file-borne case. Investigators traced initial access to a spear-phishing attack on a call centre serving the bank's London branch, months before the attackers pivoted into the Taiwan network and dispensed cash from 41 ATMs through the bank's own software update server.

Precision matters here: the MJIB's published brief documents the intrusion chain from the compromised London server onward, while the spear-phishing entry and its Office exploit attachments come from investigators' accounts carried in reputable reporting. The entry below says exactly that. Other Taiwanese headliners stay off this record: the 2017 Far Eastern International Bank heist's entry point was never documented, the 2020 CPC Corp ransomware vector was never determined, and the 2018 TSMC infection travelled on equipment rather than through a content channel.

Documented events

File-borne incidents in Taiwan

Most recent first. Every entry cites the public record it is drawn from.

  1. Phishing link in emailContext

    D-Link Corporation: Networking manufacturer confirmed a phished employee as the route into its systems

    After data purporting to come from D-Link was offered for sale in October 2023, the company investigated with an external incident response firm and confirmed unauthorised access traced to a phished employee. D-Link says the exposed records came from an outdated product registration system and covered approximately 700 low sensitivity records.

    The documented vector. Phishing email against an employee; D-Link's advisory does not specify the message mechanics further. D-Link's own support announcement states the incident was caused by an employee falling victim to a phishing attack. The advisory does not specify whether the message carried an attachment or a link, and this entry carries that limit rather than filling it in.

    How this class of vector is removed

    The vector class the company named, a phishing message reaching an employee, crosses the boundary as a file: the email itself. A CDR hop on inbound mail applies policy outcomes, warn, quarantine or block, and rebuilds carried content to a known good specification before delivery. Glasswall does not claim to detect deceptive hyperlinks, so where the compromise ran through a credential page rather than carried content the mapping is held at low confidence and says so.

    Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • manufacturing

    Source: D-Link Corporation · Source: BleepingComputer

  2. Email attachmentHigh impact

    First Commercial Bank: ATM heist cashed out through the bank's own update server after spear-phishing entry

    In July 2016 the Cobalt group withdrew about NT$83 million from 41 First Commercial Bank ATMs in Taipei, using malware distributed through the bank's own ATM software update server after a months earlier network intrusion first observed in firewall logs on 31 May 2016. The MJIB investigated, three money mules were convicted in Taiwanese courts and most of the cash was recovered.

    The documented vector. Spear-phishing email; investigators describe attachments exploiting a Microsoft Office vulnerability. Investigators from the Ministry of Justice Investigation Bureau, in accounts carried by AmCham Taiwan's reporting, traced initial access to a spear-phishing attack against a call centre worker serving the bank's London branch, with emails delivering attachments built to exploit a Microsoft Office vulnerability. The MJIB's published brief documents the chain from the compromised London call recording server onward, so the attachment detail rests on the investigators' account rather than the brief itself.

    How this class of vector is removed

    The class of vector investigators described, a document attachment built to exploit its own parser, is removed by deterministic CDR rebuild: every inbound attachment is reconstructed to the format's known good specification, so a file whose value to the attacker is its malformed construction does not survive delivery, with no dependence on a signature for the exploit. The Email CDR Relay applies that rebuild on the mail path, and Foresight scores exactly this kind of anomalous construction before anything runs. The mapping is held at medium confidence because the attachment detail rests on investigators' accounts rather than the published brief.

    Content Disarm and ReconstructionEmail CDR RelayForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight

    • banking

    Source: Ministry of Justice Investigation Bureau · Source: Taiwan Business TOPICS (AmCham Taiwan) · Source: Group-IB

Scope

How to read this page

Every event on this page meets three tests before it is published. It is documented by reliable public sources: a regulator, an official inquiry, the affected organisation's own disclosure, or reputable press with named confirmation, and each entry links to those sources. The initial access or payload delivery travelled as a file, as the public record states it. An email is itself a file, so malicious code in a message and deceptive-hyperlink phishing carried by a message both count; credential attacks and pure network exploits are excluded. And the prevention analysis is conditional: where we say a capability removes a class of vector, that is a statement about how the control treats that class of content, not a claim about what any organisation ran, and not a judgement on the people who dealt with the incident.

This page is a working reference, not an incident report or legal advice. Details reflect the public record on the review date and organisations named here are cited from that record alone.

Elsewhere in the region

Other APAC territories

Files cross your boundary every day