Home Cyber Attack Taiwan High Speed Rail Hit by Radio Signal Spoofing Attack That Stopped...

Taiwan High Speed Rail Hit by Radio Signal Spoofing Attack That Stopped Three Trains

0
Taiwan High Speed Rail Hit by Radio Signal Spoofing Attack That Stopped Three Trains

During the Qingming Festival holiday, Taiwan High Speed Rail (THSR) suffered a significant cybersecurity incident when three trains were suddenly forced into emergency stops, stranding passengers for nearly 48 minutes.

Authorities have since confirmed that the disruption was not a mechanical failure but a targeted radio signal spoofing attack carried out by a 23-year-old college student who exploited vulnerabilities in the railway’s communication infrastructure.

The incident marked one of the most disruptive cyber-physical attacks on Taiwan’s transit network in recent memory, raising urgent questions about the security of critical transportation systems that rely on radio-based operational technology.

How the Attack Was Executed

The cyberattack specifically targeted THSR’s internal operational technology (OT) and communication infrastructure, which coordinates real-time train movements and emergency alerts across the network.

According to investigators, the attacker first exploited a vulnerability in the railway’s core computer systems to gain unauthorized access to the network.

Once inside, the suspect used electromagnetic interference tools and specialized wireless broadcasting hardware to impersonate an authorized Tetra mobile communication device.

Tetra devices are highly restricted hardware issued exclusively to duty personnel operating in controlled transit zones.

They include a built-in General Alarm (GA) emergency function designed for life-threatening situations, and when triggered, the system automatically forces all train drivers in the surrounding area to switch into manual emergency stop mode.

The attacker cloned a legitimate high-speed rail radio signal and broadcast a malicious GA alert that appeared to originate from a Tetra device stationed at Taichung Station.

The THSR operations control center detected the signal and, following standard safety protocol, initiated immediate emergency stops across three trains.

The spoofed alert was indistinguishable from a genuine distress signal, bypassing the railway’s standard safety verification checks entirely.

This type of attack blends traditional cyber intrusion with physical-layer radio frequency manipulation a technique increasingly known as a cyber-physical attack, making detection and attribution exceptionally difficult in real time.

Immediately after the emergency stops, THSR’s control center identified a digital anomaly in the signal’s origin.

To rule out insider threats or physical device theft, facility managers conducted an urgent inventory audit of all internal Tetra communication equipment.

Once they confirmed no authorized devices were missing, operators concluded the GA signal had been artificially generated from outside the network.

After ruling out internal employee error, THSR officially reported the breach to local police on April 6.

A formal legal complaint was filed on April 24, triggering a joint investigation by the Railway Police Bureau and the Criminal Investigation Bureau’s Telecommunications Investigation Division.

Using signal tracking and digital forensics, investigators traced the broadcast back to the suspect within days.

Armed with a court-issued search warrant, law enforcement officers raided three locations on April 28, including the suspect’s home and workplace seizing multiple electronic devices and the wireless broadcasting hardware used to execute the attack.

Following interrogation, the 23-year-old was released on NT$100,000 bail.

He now faces serious charges under both the Railway Act and Taiwan’s Criminal Code, covering endangerment of public transportation, unauthorized system intrusion, and illegal use of communication-interference equipment. Convictions under these statutes carry substantial prison terms.

The Taoyuan District Prosecutors’ Office issued a clear warning that any attempts to disrupt critical public infrastructure through hacking or radio signal manipulation will be aggressively prosecuted.

The case highlights a growing vulnerability in transit systems worldwide: as railways depend more heavily on radio-based OT networks for real-time coordination, the attack surface for signal spoofing and electromagnetic interference expands significantly.

Security experts are now calling on transit authorities globally to implement stronger signal authentication protocols and anomaly detection systems to prevent similar incidents.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here