During the recent Qingming Festival holiday, the Taiwan High Speed Rail (THSR) experienced a severe cybersecurity incident that disrupted major transit operations.
Three trains were suddenly forced into emergency stops, causing a 48-minute delay for passengers.
Authorities have now determined that the disruption was not a mechanical failure but a targeted radio signal spoofing attack carried out by a lone threat actor.
Taiwan High Speed Rail Spoofing Attack
The cyberattack specifically targeted the railway’s internal operational technology (OT) and communication infrastructure.
According to investigators, the attacker successfully cloned a high-speed rail radio signal to broadcast a malicious system alert. The operations control center detected a General Alarm (GA) signal that appeared to originate from a Tetra mobile phone located at the Taichung Station.
Tetra communication devices are highly restricted hardware issued primarily to duty personnel operating within controlled transit areas. These devices feature a built-in emergency reporting function designed for critical, life-threatening situations.
When a General Alarm is triggered, the system automatically dispatches an alert and forces all train drivers in the immediate vicinity to switch into a manual emergency stop mode.
Prosecutors revealed that the suspect exploited a computer system vulnerability to initially breach the railway’s core network.
Once inside, the attacker utilized electromagnetic interference and specialized broadcasting equipment to impersonate an authorized Tetra device, effectively spoofing the distress signal and bypassing standard safety protocols.
Immediately following the sudden train halts, the THSR control center recognized the digital anomaly. To rule out physical theft, facility managers conducted an urgent inventory audit of all internal communication equipment.
Once they verified that no authorized devices were missing or stolen, operators realized the signal had been artificially generated.
After confirming the incident was not caused by an internal employee error, THSR officials reported the breach to local police on April 6.
A formal legal complaint was filed on April 24, prompting a joint investigation by the Railway Police Bureau and the Criminal Investigation Bureau’s Telecommunications Investigation Division, as reported by Newtalk.
Through signal tracking and digital forensics, the task force identified the suspect as a 23-year-old college student.
Armed with a court-issued search warrant, officers raided three separate locations on April 28, including the suspect’s home and workplace. Law enforcement seized multiple electronic devices and wireless broadcasting hardware used to execute the spoofing attack.
Following his arrest and interrogation, the suspect was released on NT$100,000 bail. He faces severe charges under both the Railway Act and the Criminal Code for endangering public transportation, unauthorized system intrusion, and the use of illegal communication-interference equipment.
The Taoyuan District Prosecutors’ Office issued a stern warning that any attempts to disrupt critical public infrastructure through hacking or signal manipulation will be aggressively prosecuted to protect transit safety.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





