The nation’s government agencies reported 726 cybersecurity incidents last year, of which nearly 69 percent were unauthorized intrusion cases, Administration for Cybersecurity data showed.
In accordance with the Regulations Governing the Reporting and Response of Cybersecurity Incidents and Exercises (資通安全事件通報應變及演練辦法), government agencies classify reportable cybersecurity incidents into levels 1 through 4, from least to most severe, based on the severity of the incident’s impact on confidentiality, integrity and availability.
Last year, 726 cybersecurity incidents were reported by government agencies, down from 755 in 2024, administration data showed.
Photo: Reuters
Among the incidents, 87.33 percent were level 1 cases, 9.78 percent were level 2 cases and 2.89 percent were level 3 cases.
No level 4 cases were reported.
Regarding the types of cybersecurity incidents, 68.6 percent were unauthorized intrusion cases, followed by equipment malfunctions (15.43 percent), service disruptions (4.96 percent) and Web page attacks (2.48 percent), the data showed.
The administration also identified the major cybersecurity threats faced by government agencies.
First, backdoor programs could be installed on newly acquired government computers if users download maliciously spoofed messaging applications.
Second, blackmailers could gain unauthorized access to the mainframe and avoid detection by using a “bring-your-own-driver” technique to disable security protections.
Third, system maintenance contractors could install remote access software on the Web server, allowing attackers to gain access to the agency’s Web site through a brute-force password attack.
Fourth, vulnerabilities or configuration risks in network edge devices could result in malicious connection activities.
To counter these threats, government agencies should require approval for all software, hardware and application installations, the administration said, adding that they should regularly conduct vulnerability scans and patch any found, deploy Web application firewalls, and maintain updated endpoint protection and threat detection mechanisms.
The administration also urged government bodies to improve supplier security management — including access control, data protection, vulnerability management and incident reporting — while conducting regular cybersecurity audits and compliance checks.
Government agencies could also adopt a whitelist for external connections, blocking unnecessary ports, and regularly updating and verifying network edge device firmware to ensure timely patching of vulnerabilities, the administration said.
Agencies should deploy e-mail filtering and sandboxing systems to block malicious attachments and links, while restricting cloud-sharing permissions and scanning uploaded files and cloud links for threats, the administration added.
They must also maintain backups for their data, ensure they have redundancy and recovery capabilities, and regularly conduct Business Continuity Plan drills to ensure rapid switchover to backup systems during emergencies, it said.
The Ministry of Digital Affairs is promoting encrypted distributed backups for critical public infrastructure systems across multiple public cloud environments to reduce single-point failure risks and enhance resilience, the administration said.
Fast food chain McDonald's is to raise prices by up to NT$5 on some products at its restaurants across Taiwan, starting on Wednesday next week, the company announced today. The prices of all extra value meals and sharing boxes are to increase by NT$5, while breakfast combos and creamy corn soup would go up by NT$3, the company said in a statement. The price of the main items of those meals, if ordered individually, would remain the same. Meanwhile, the price of a medium-sized lemon iced tea and hot cappuccino would rise by NT$3, extra dipping sauces for chicken nuggets would go up
Nvidia Corp CEO Jensen Huang (黃仁勳) arrived in Taiwan yesterday ahead of upcoming AI and technology events, saying he plans to meet with clients and Taiwan Semiconductor Manufacturing Co Chairman C.C. Wei (魏哲家) during his visit. After landing at Taipei Songshan Airport, Huang posed for photos with fans and handed out Yakult drinks to reporters and supporters waiting at the scene, saying he has “a lot to do” during the trip. Asked about reports that Nvidia’s planned headquarters site in Taipei’s Beitou Shilin Technology Park could break ground on May 27, Huang said that if the company holds an event, he would
FUKUOKA SITUATION: Japanese media reported that the pathogen is expected to be identified by the summer, while the CDC downplayed the idea that it was hMPV A “mysterious cold-like illness” reported in Japan’s Fukuoka Prefecture does not seem to be a new disease, but Japanese authorities have been asked about the situation, the Centers for Disease Control (CDC) said yesterday. The Fukuoka Prefectural Medical Association on Wednesday told a news conference that a “mystery cold” that has become a hot topic on social media is “highly likely to be caused by some kind of viral infection,” Japan’s KBC News reported. “Many people are experiencing symptoms starting with a sore throat, followed by a runny nose, phlegm and a severe cough,” KBC News reported, citing association officials. Health authorities are
Carrefour Taiwan is to begin using a new name from the start of July, but it cannot divulge the name until then, the chairman of the supermarket chain's parent company said today. President Chain Store Co chairman Lo Chih-hsien (羅智先) was asked by reporters after a shareholders' meeting to confirm whether the company has settled on a new name for the supermarket brand. In March, the government-registered name of two Carrefour Taiwan branches was quietly changed to "Le Chia Kang" (樂家康) in Chinese, raising speculation that has been selected as the name. Lo said that because of local regulations and contractual obligations, the