Cybersecurity 2026

TAIWAN Law and Practice Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law

Financial Institutions on Material Incidental Events (Reporting Procedures) stipulate that when a bank encounters a material cybersecurity incident (mate - rial cybersecurity incident), the bank should, within 30 minutes after confirmation of the incident, notify the FSC through the designated channel. Within seven days upon reporting the incident, the bank should provide detailed information (eg, investigation result, handling and improvement mechanism) to the FSC. 3.4 Operational Resilience Enforcement Public information concerning enforcement actions involving critical ICT service providers remains limit - ed. Nonetheless, certain cases addressing operational resilience obligations merit consideration. Taishin International Bank Fined TWD6 Million for Internal Control Deficiencies in Debt Collection and Credit Card Billing On 8 May 2025, the FSC fined Taishin International Bank TWD6 million for violations of paragraphs 1 and 3, Article 45-1 of the Banking Act. The penalty was issued following a regulatory investigation into sys - temic errors that led to incorrect mailing addresses for debt collection letters and the misplacement of credit card billing data. The FSC stated in its disposition that Taishin Bank had failed to establish an adequate internal control system and had not effectively implemented its operational procedures. The investigation revealed that the bank lacked robust testing and verification mechanisms for information system changes and failed to provide effective oversight of its outsourced service providers. Specifically, in November 2024, an equipment mal - function at an outsourced vendor caused the trans - action details of 358 customers to be printed on the wrong billing statements. The FSC found that Taishin Bank had not ensured that the vendor maintained an effective error-verification mechanism prior to mailing. The FSC imposed the fine and demanded that the bank rectify its internal control and audit systems. Investigation of the First Commercial Bank Security Breach In July 2016, the ATM network of First Commercial Bank in Taiwan was hacked, which made selected

ATMs spew cash out to 12 waiting “bagmen”. More than USD2.63 million was stolen through the 41 ATMs. While the police department worked on finding the bagmen, the Investigation Bureau, under the Minis - try of Justice, which is responsible for investigating computer crimes, handled the digital forensics of the breached ATMs and located the installed malware. After the investigation wrapped up, about USD2.44 million was recovered by the police. Though 22 sus - pects from nine countries involved, only three were apprehended and indicted for fraud, in September 2016. The FSC pointed out that First Bank did not provide sufficient cybersecurity protection to its ATMs and network, and thus imposed a TWD10 million fine on the bank and suspended its cardless withdrawal ser - vices until it improved its system. Cathay United Bank Fined TWD12 Million for Repeated Electronic System Breakdowns On 29 December 2022, Taiwan’s FSC fined Cathay United Bank TWD12 million for breakdowns of its ATM and internet banking electronic systems. The FSC fur - ther reduced the salary for the bank’s president Lee Wei-cheng by 30% for a period of three months and is requiring the bank to increase operational risk capital. The FSC stated in its disposition that Cathay Unit - ed Bank had not properly prepared an emergency response mechanism in the event of an incident like a breakdown of electronic systems and had not prop - erly established or implemented an internal control system. Cathay United Bank has previously been fined TWD2 million for four ATM system failures that occurred between 2020 and 2021. The FSC increased the fine to TWD12 million for the current case, which repre - sents the highest penalty ever issued in Taiwan’s his - tory for the breakdown of a bank’s electronic system. 3.5 International Data Transfers According to Article 17 of the Outsourcing Regula - tions, financial institutions, when outsourcing services outside of Taiwan, should meet certain requirements. Key provisions include:

400 CHAMBERS.COM

Powered by