Taipei prosecutors have indicted four people at Taiwan’s National Institute of Cyber Security, including Hsu Shih-chang, deputy director of the institute’s forward-looking research and procurement center, over allegations that they used internal system flaws to run crawlers that scraped official documents, personnel data, and workflow forms 207,938 times over nine months. Prosecutors also said some of the documents were sent to Microsoft Azure’s large language model API to analyze procurement amounts.
On Sept. 18, the Taipei District Prosecutors Office concluded its investigation and charged Hsu, director Peng Min-chun, and associate researchers Ding Bo-feng and Li Yu-hsun with offenses including violations of personal data protection rules and unlawful computer use.
Prosecutors say crawler traffic made up 85% of institute-wide reads
According to the indictment, the four used the scraped data to build an internal budget system for the center called XMAS. After the system went live in late June 2025, the crawler logged 207,938 retrievals by March this year, averaging one request every 2.6 seconds. Prosecutors said those reads accounted for 85% of all reads by institute staff, exceeding the combined total of all other employees.
Proposal for a new finance system was rejected
The indictment says Hsu, then serving as R&D group director, believed in January 2025 that the institute’s project funding management was inefficient and proposed that the center develop a new financial management system. Then-president Lin Ying-da did not approve the plan.
Prosecutors traced the case back further to January 2024, when Peng allegedly obtained personal data for institute staff through a flaw in the personnel system and sent it to Hsu via LINE. Ding later found that access controls in the institute’s EIP system were insufficient: submitting any form number could return funding application content. He then wrote a crawler to download the material on a schedule. Because large procurement cases had to go through official document workflows, he also wrote a separate crawler for those documents and sent them to Microsoft Azure’s large language model API to analyze procurement amounts and expected reimbursement installments.
Cloudflare Tunnel allegedly used after VPN cutoff
The institute cut VPN connectivity between internal and external networks in May 2025, temporarily interrupting the crawler. Prosecutors said Li then used an institute-issued internal-network laptop to install Cloudflare Tunnel as a relay, allowing the crawler to reconnect to the internal network.
The report described Cloudflare Tunnel as a connection tool from Cloudflare that can expose internal services externally without opening the firewall.
Scraped material included personal data and classified documents
The data allegedly taken included employee ID numbers, health insurance bracket information, and other personal data. Some documents and attachments involved personnel security vetting and national core technology research projects, and were classified or above. The institute handles national core technology research projects and supports cybersecurity protection for sensitive government agencies.
No evidence so far of leaks beyond current or former staff
Prosecutor Liao Yen-chun said the four exceeded the scope of their job authorization by scraping large volumes of data. He added that there is currently no evidence the information was leaked to anyone other than current or former institute employees. Prosecutors said that if the four admit guilt during trial, the court should take their post-offense attitude into account in sentencing. Other employees investigated in the same case were not indicted because prosecutors found insufficient evidence.
Case was uncovered in an internal audit
The case was discovered during an internal audit at the institute in January this year. The institute then reported the matter to the Investigation Bureau. After two rounds of investigation, three employees involved had been dismissed under labor law, and four others were suspended from duty. Lin resigned as president on June 22 to take administrative responsibility.

