Friday, September 11, 2026

Taiwan High Speed Rail Hit by Spoofing Attack That Stops Three Trains

During the recent Qingming Festival holiday, the Taiwan High Speed Rail (THSR) experienced a severe cybersecurity incident that disrupted major transit operations.

Three trains were suddenly forced into emergency stops, causing a 48-minute delay for passengers.

Authorities have now determined that the disruption was not a mechanical failure but a targeted radio signal spoofing attack carried out by a lone threat actor.

Taiwan High Speed Rail Spoofing Attack

The cyberattack specifically targeted the railway’s internal operational technology (OT) and communication infrastructure.

According to investigators, the attacker successfully cloned a high-speed rail radio signal to broadcast a malicious system alert. The operations control center detected a General Alarm (GA) signal that appeared to originate from a Tetra mobile phone located at the Taichung Station.

Tetra communication devices are highly restricted hardware issued primarily to duty personnel operating within controlled transit areas. These devices feature a built-in emergency reporting function designed for critical, life-threatening situations.

When a General Alarm is triggered, the system automatically dispatches an alert and forces all train drivers in the immediate vicinity to switch into a manual emergency stop mode.

Prosecutors revealed that the suspect exploited a computer system vulnerability to initially breach the railway’s core network.

Once inside, the attacker utilized electromagnetic interference and specialized broadcasting equipment to impersonate an authorized Tetra device, effectively spoofing the distress signal and bypassing standard safety protocols.

Immediately following the sudden train halts, the THSR control center recognized the digital anomaly. To rule out physical theft, facility managers conducted an urgent inventory audit of all internal communication equipment.

Once they verified that no authorized devices were missing or stolen, operators realized the signal had been artificially generated.

After confirming the incident was not caused by an internal employee error, THSR officials reported the breach to local police on April 6.

A formal legal complaint was filed on April 24, prompting a joint investigation by the Railway Police Bureau and the Criminal Investigation Bureau’s Telecommunications Investigation Division, as reported by Newtalk.

Through signal tracking and digital forensics, the task force identified the suspect as a 23-year-old college student.

Armed with a court-issued search warrant, officers raided three separate locations on April 28, including the suspect’s home and workplace. Law enforcement seized multiple electronic devices and wireless broadcasting hardware used to execute the spoofing attack.

Following his arrest and interrogation, the suspect was released on NT$100,000 bail. He faces severe charges under both the Railway Act and the Criminal Code for endangering public transportation, unauthorized system intrusion, and the use of illegal communication-interference equipment.

The Taoyuan District Prosecutors’ Office issued a stern warning that any attempts to disrupt critical public infrastructure through hacking or signal manipulation will be aggressively prosecuted to protect transit safety.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News