Eight Taiwan lenders ran a synchronized phishing exercise Monday and Tuesday, sending fake payment notices and travel-refund texts to thousands of employees who had volunteered as targets, the Taiwan Bankers Association said. The drill was timed for the week before Golden Week, when fraud desks historically see a spike in SMS and LINE lures that mimic banks.
Timeline
On Monday at 9:00 a.m. Taipei time, participating banks pushed messages that referenced pending wire holds and “security upgrades” tied to holiday travel. Recipients who clicked were routed to a controlled landing page that recorded the event without harvesting credentials. By Tuesday afternoon, the association said roughly 12% of volunteers had clicked at least once—lower than last autumn’s 17% but high enough that several chief information security officers extended internal awareness campaigns through October.
CTBC Bank, Cathay United Bank, and Taiwan Cooperative Financial Holding confirmed participation. A spokesperson for one state-linked lender said the exercise used the same short-link patterns seen in live scams reported to the Financial Supervisory Commission in August, including domains that swapped Latin “l” for numeral “1.”
Messages arrived on both corporate-issued iPhones and Android handsets enrolled in mobile device management, mimicking how attackers spray numbers without knowing each user’s OS. Security teams measured time-to-report as well as click-through: volunteers who forwarded screenshots to the internal abuse mailbox within ten minutes were counted as passes, a metric several CISOs said they would publish internally even though the association aggregated only clicks.
Impact
No customer accounts were touched. The association stressed that only staff who had opted in received messages, and that production fraud systems remained in monitoring mode. Still, two banks told InfoHandle they filed internal tickets to tighten SMS gateway allowlists after testers bypassed a legacy filter by encoding URLs in QR codes attached to email.
Golden Week travel bookings rose 9% year over year through mid-September, according to Tourism Administration figures cited by lenders. Fraud units worry that rushed passengers will tap links promising itinerary changes or baggage-fee refunds.
Incident data from 2025 shared at the briefing showed phishing kits increasingly reference Taiwan High Speed Rail and domestic carriers by name, even when the malicious domain was registered abroad. Banks said they cannot block those brand strings without catching legitimate marketing, which is why the drill focused on employee reflexes and gateway rules rather than keyword bans alone.
Response
The Financial Supervisory Commission said it “welcomed” the drill but did not mandate participation. FSC officials have urged banks since July to report phishing templates within 24 hours so industry groups can share indicators. Monday’s exercise added three new domain hashes to the bankers’ shared watchlist.
Retail branches received updated counter scripts asking tellers to pause large holiday transfers when customers mention SMS “verification.” Several lenders also pushed in-app banners describing the drill so real customers would not confuse test messages with fraud.
The association said it will share anonymized click heatmaps with the FSC’s bank examination unit, a step toward making drills part of supervisory reviews rather than voluntary club exercises.
Gaps
It remains unclear how many contractors and call-center staff were included; the association did not break out vendor participation. Attribution for live scams is still rare—banks see the lures, not the operators. No government agency has published arrest data tied to this week’s templates.
Smaller rural credit cooperatives were not in the exercise, leaving a coverage hole where older customers rely on branch staff rather than apps. Whether the FSC will require annual drills for all licensed banks is undecided; a consultation paper is expected after Golden Week.
Insurance brokers attending the association debrief asked whether cyber policies cover simulated phishes that accidentally reach non-volunteers; counsel said the drill’s opt-in roster should shield institutions, but misaddressed SMS remains a disclosure risk. No lender reported such a leak this week.
For now, the measurable outcome is a click rate that confirms holiday-themed social engineering still works on trained employees—and a reminder that customer education slides are not a substitute for gateway controls.







