Taiwan cybersecurity institute deputy director charged over rogue web crawler that scraped 200,000 internal records

Sep 17, 2026

Four staff at Taiwan's National Institute of Cyber Security have been indicted for secretly scraping internal documents and personnel data, an embarrassing security failure for the agency meant to protect the government's most sensitive systems.

  • Deputy director Hsu Shih-chang proposed building a new budget system, was turned down, and built it anyway by exploiting a permissions hole in the institute's own website.
  • A crawler pulled documents, personnel records, and workflow forms over 200,000 times, one read every few seconds, and some documents were fed into a large language model for analysis.
  • The data included staff ID numbers and health insurance details, plus classified material on security clearances and national core technology research programs.
  • When the institute shut down its VPN, the team set up a Cloudflare Tunnel on a work laptop to reconnect the crawler from outside.
  • Prosecutors charged Hsu and three colleagues under the personal data and computer crime laws, but say there is no evidence so far that the data leaked beyond current and former staff.

Outlook: The case heads to trial, with prosecutors signaling lighter sentences if the four confess; the bigger question is how the agency in charge of national cybersecurity left such holes open for over a year.

← Latest · Archive