Taiwan High Speed Rail has announced that a cybersecurity incident involving its TETRA Radio System occurred in April 2026. The event brought four trains to a standstill for 48 minutes. A 23-year-old college student exploited the system using Software Defined Radios. The suspect was arrested in Taichung after answering a radio transmission awkwardly.
Hack bypassed seven verification layers on the network
The hack bypassed seven layers of verification on the communication network. RTL-SDR speculates that the system used the now-broken TEA1 encryption standard. The TETRA system had not rotated its cryptographic keys in 19 years. The suspect claims the intrusion was an accidental button press from a radio in his pocket.

The student is currently out on $3,200 bail. He faces a potential judgment that could send him to prison for 10 years. Ho Shin-chun, a Democratic Progressive Party Legislator, questioned the safety of other rail systems. He asked what would happen if a similar breach occurred at the Taiwan Railway Corp.
This incident highlights significant vulnerabilities in critical infrastructure security. The long duration without key rotation allowed a single individual to disrupt operations. The ability to stop multiple trains demonstrates the physical impact of digital failures. The case underscores the risks associated with outdated cryptographic protocols in public transport.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.