College Student Hacks Taiwan High-Speed Rail TETRA System, Stopping Four Trains

A 23-year-old student hacked Taiwan High-Speed Rail's TETRA system using Software Defined Radios, stopping four trains for 48 minutes due to outdated encryption.

College Student Hacks Taiwan High-Speed Rail TETRA System, Stopping Four Trains

Taiwan High Speed Rail has announced that a cybersecurity incident involving its TETRA Radio System occurred in April 2026. The event brought four trains to a standstill for 48 minutes. A 23-year-old college student exploited the system using Software Defined Radios. The suspect was arrested in Taichung after answering a radio transmission awkwardly.

Hack bypassed seven verification layers on the network

The hack bypassed seven layers of verification on the communication network. RTL-SDR speculates that the system used the now-broken TEA1 encryption standard. The TETRA system had not rotated its cryptographic keys in 19 years. The suspect claims the intrusion was an accidental button press from a radio in his pocket.

TETRA Radio System diagram showing seven verification layers bypassed by TEA1 encryption exploit
The breach exploited a TETRA system that had not rotated cryptographic keys in 19 years.

The student is currently out on $3,200 bail. He faces a potential judgment that could send him to prison for 10 years. Ho Shin-chun, a Democratic Progressive Party Legislator, questioned the safety of other rail systems. He asked what would happen if a similar breach occurred at the Taiwan Railway Corp.

This incident highlights significant vulnerabilities in critical infrastructure security. The long duration without key rotation allowed a single individual to disrupt operations. The ability to stop multiple trains demonstrates the physical impact of digital failures. The case underscores the risks associated with outdated cryptographic protocols in public transport.

Discussion

0 comments

Log in to join the thread with a thoughtful take, question, or correction.

Add to the discussion