Taiwan's NCSIST procurement site breach traced to overseas IP
Taiwan's top military research institute has walked back its claim that a mass mailing glitch was harmless, now admitting an overseas attacker triggered it — bad news for confidence in the island's defense supply chain security.
- The National Chung-Shan Institute of Science and Technology's procurement site blasted old purchase notices to suppliers in late August.
- The institute first blamed an AI agent overstepping its permissions during internal testing, saying it was not a hack.
- It now says the original software vendor left a hidden scheduling interface in the system, and an overseas IP cracked it and set off the mass send.
- Lawmakers accused the institute of downplaying the incident after the digital ministry described it as a brute-force login break-in; investigators in Taipei have opened a case.
- The system dates to 2019 and was never checked under the institute's new software bill-of-materials policy, a gap it now admits.
Outlook: The investigation will look at who is responsible for the management lapse, and the institute is adding alerts and automatic traffic blocking to its public-facing systems.