Scworld Taiwan Student Disrupts High-Speed Rail with Radio Hack
Article Content
- •A university student halted four high-speed trains in Taiwan using a radio hack.
- •The attack exploited outdated TETRA communication parameters, allowing unauthorized access.
- •Lin faces up to 10 years in prison, highlighting serious security vulnerabilities in rail systems.
A 23-year-old university student in Taiwan, surnamed Lin, was arrested for halting four high-speed trains for 48 minutes on April 5, 2026. He used software-defined radio (SDR) equipment to transmit a false General Alarm signal, triggering emergency braking procedures on the Taiwan High-Speed Rail (THSR) network. The attack exploited a vulnerability in the TETRA communication system, which had not updated its parameters in 19 years, allowing Lin to bypass multiple security layers. Police discovered that Lin had decoded TETRA parameters and cloned signals using equipment purchased online. An accomplice provided critical parameters for the attack. Lin faces potential imprisonment of up to 10 years under Taiwan's Criminal Law and is currently out on NT$100,000 ($3,280) bail. The incident has raised concerns about the safety and security of critical infrastructure in Taiwan.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track Taiwan High-Speed Rail in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…