Taiwan cybersecurity institute deputy director indicted over 207,938 document scrapes and Azure LLM use

Taiwan cybersecurity institute deputy director indicted over 207,938 document scrapes and Azure LLM use

N
News Editor
2026-09-18 10:33:11
Prosecutors in Taipei have indicted four people tied to Taiwan’s National Institute of Cyber Security, including deputy director Hsu Shih-chang of its forward-looking research and procurement center, over allegations that they exploited internal system flaws to scrape official documents, personnel data, and workflow forms 207,938 times over nine months. According to the indictment, some of the scraped documents were then sent to Microsoft Azure’s large language model API to analyze procurement amounts and expected reimbursement schedules. Prosecutors said the scraping activity accounted for 85% of all document reads by institute staff and was used to build an internal budget system called XMAS. The case also alleges that after the institute cut VPN connectivity between internal and external networks in May 2025, one of the defendants used an institute-issued internal laptop with Cloudflare Tunnel to keep the crawler connected. Prosecutors said the scraped material included personal data and some classified documents, but added that there is currently no evidence the information was leaked to anyone outside current or former institute employees.

Taipei prosecutors have indicted four people at Taiwan’s National Institute of Cyber Security, including Hsu Shih-chang, deputy director of the institute’s forward-looking research and procurement center, over allegations that they used internal system flaws to run crawlers that scraped official documents, personnel data, and workflow forms 207,938 times over nine months. Prosecutors also said some of the documents were sent to Microsoft Azure’s large language model API to analyze procurement amounts.

On Sept. 18, the Taipei District Prosecutors Office concluded its investigation and charged Hsu, director Peng Min-chun, and associate researchers Ding Bo-feng and Li Yu-hsun with offenses including violations of personal data protection rules and unlawful computer use.

Prosecutors say crawler traffic made up 85% of institute-wide reads

According to the indictment, the four used the scraped data to build an internal budget system for the center called XMAS. After the system went live in late June 2025, the crawler logged 207,938 retrievals by March this year, averaging one request every 2.6 seconds. Prosecutors said those reads accounted for 85% of all reads by institute staff, exceeding the combined total of all other employees.

Proposal for a new finance system was rejected

The indictment says Hsu, then serving as R&D group director, believed in January 2025 that the institute’s project funding management was inefficient and proposed that the center develop a new financial management system. Then-president Lin Ying-da did not approve the plan.

Prosecutors traced the case back further to January 2024, when Peng allegedly obtained personal data for institute staff through a flaw in the personnel system and sent it to Hsu via LINE. Ding later found that access controls in the institute’s EIP system were insufficient: submitting any form number could return funding application content. He then wrote a crawler to download the material on a schedule. Because large procurement cases had to go through official document workflows, he also wrote a separate crawler for those documents and sent them to Microsoft Azure’s large language model API to analyze procurement amounts and expected reimbursement installments.

Cloudflare Tunnel allegedly used after VPN cutoff

The institute cut VPN connectivity between internal and external networks in May 2025, temporarily interrupting the crawler. Prosecutors said Li then used an institute-issued internal-network laptop to install Cloudflare Tunnel as a relay, allowing the crawler to reconnect to the internal network.

The report described Cloudflare Tunnel as a connection tool from Cloudflare that can expose internal services externally without opening the firewall.

Scraped material included personal data and classified documents

The data allegedly taken included employee ID numbers, health insurance bracket information, and other personal data. Some documents and attachments involved personnel security vetting and national core technology research projects, and were classified or above. The institute handles national core technology research projects and supports cybersecurity protection for sensitive government agencies.

No evidence so far of leaks beyond current or former staff

Prosecutor Liao Yen-chun said the four exceeded the scope of their job authorization by scraping large volumes of data. He added that there is currently no evidence the information was leaked to anyone other than current or former institute employees. Prosecutors said that if the four admit guilt during trial, the court should take their post-offense attitude into account in sentencing. Other employees investigated in the same case were not indicted because prosecutors found insufficient evidence.

Case was uncovered in an internal audit

The case was discovered during an internal audit at the institute in January this year. The institute then reported the matter to the Investigation Bureau. After two rounds of investigation, three employees involved had been dismissed under labor law, and four others were suspended from duty. Lin resigned as president on June 22 to take administrative responsibility.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
4300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.