Ex-cyber official indicted
DATABASE WORKAROUND? Prosecutors alleged that Hsu Hsih-chung and others used a software tool to obtain data amid frustration over system shortcomings
By Liu Yong-yun and Jonathan Chin / Staff reporter, with staff writer
The Taipei District Prosecutors’ Office yesterday indicted a former official of the National Institute of Cyber Security’s research and acquisition center for allegedly hacking into a classified institute database.
Hsu Hsih-chung (許世璋), a former deputy director of the center, and three of his subordinates are accused of breaking into the institute’s database to obtain classified information, the office said.
The defendants face charges over alleged contraventions of cybersecurity and digital privacy rules in the Criminal Code and the Personal Data Protection Act (個人資料保護法), it said.
The Ministry of Digital Affairs, the agency in charge of the National Institute of Cyber Security, is pictured in Taipei in an undated photograph.
Photo: Hsu Tzu-ling, Taipei Times
Hsu allegedly built an unauthorized crawler to access administrative information, bypassing the organization’s budget management system, which he believed to be inefficient, the indictment said.
Using the crawler, Hsu and his accomplices compromised the institute’s internal budget documents, as well as national identification and National Health Insurance numbers of institute employees, among other privileged information, it said.
In January 2024, Hsu inadvertently discovered a back door into the institute’s human resource system and obtained personal data of all of the employees, which he allegedly shared with the three codefendants, it said.
Believing that the organization’s project budget management system was inadequate, Hsu in March last year asked the institute to adopt a new system, but his proposal was rejected, prosecutors said.
Hsu allegedly told subordinate Peng Ming-chun (彭敏君) to bypass the internal system’s authorization mechanisms by exploiting the loophole he had previously identified in handling the center’s budget documents, the office said.
Hsu allegedly instructed Ting Po-feng (丁柏楓) to design a crawler capable of extracting internal documents without authorization, a task Peng facilitated by advising Ting on a programing language and other technical matters, it said.
Ting discovered that any document could be accessed by entering the document’s serial number on the enterprise information portal, enabling him to design the crawler Hsu had specified, it said.
Ting saved the institute’s entire payroll in his private cloud storage and internal documents on a personally owned computer, it said.
Ting regularly used Microsoft Azure to summarize confidential budget documents, including budgets and timelines, which he saved into a folder shared with the other defendants, the indictment said.
Hsu and his accomplices used the crawler and illegally obtained data to establish an alternate budget platform on the Internet, from which he managed the center’s funding, it said.
The institute in May last year banned virtual private networks from accessing the internal system, prompting Hsu to order subordinate Lee Yu-hsuan (李昱勳) to use the latter’s personal laptop as the crawler’s relay, it said.
Given that there is no evidence that the defendants leaked information to a third party, the office said it sought a reduced sentence for the defendants on account of mitigating circumstances, the indictment said.
The crawler on average accessed the internal system once every 2.6 systems for a total of 207,938 times by March, or 85 percent of all traffic to the institute’s network by employees, it said.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.