Taiwan’s National Institute of Cyber Security (NICS) told more than two dozen research universities Wednesday that spear-phishing campaigns are impersonating U.S. export-license renewal portals and domestic technology-transfer offices, a shift that puts dual-use paperwork and compliance contacts at risk—not only passwords—ahead of Golden Week when campus IT desks run thin.
Timeline
NICS issued a sector alert after incident reports from National Taiwan University, National Tsing Hua University, and National Cheng Kung University described messages that referenced “EAR attestation” deadlines and attached PDFs with spoofed Bureau of Industry and Security letterhead. The messages arrived on both faculty Gmail accounts and legacy .edu.tw inboxes, suggesting operators scraped public grant pages rather than breaching a single identity provider.
Campus security operations centers said at least nine messages across the three schools contained links to credential harvesters hosted on newly registered domains with Taiwan-focused WHOIS privacy. NICS did not attribute the activity to a named state actor, stressing that forensics remain incomplete. Ministry of Digital Affairs officials sat in on the briefing but did not announce new mandates.
Researchers in semiconductor materials and precision optics reported the lures most often. Several labs maintain export-controlled equipment lists that must be updated when students travel; the phishing templates quoted those list numbers accurately enough that two principal investigators forwarded the mail to compliance officers before IT intervened.
Impact
No university confirmed exfiltration of controlled technical data. NICS said three faculty accounts showed successful logins to fake portals before passwords were rotated. The exposure window matters because export-compliance inboxes often hold shipping addresses, end-user statements, and scanned license PDFs that attackers could reuse in downstream fraud.
National Science and Technology Council grant officers told InfoHandle they are cross-checking whether any pending U.S. commodity classifications were cited in the lures—a sign operators may be pairing open grant abstracts with compliance timelines. That pairing does not require a lab breach; much of the metadata is public in English on university sites.
Insurance brokers who cover research institutions said cyber policies increasingly exclude “regulatory misrepresentation” claims when stolen credentials are used to file fake export paperwork. Campus counsel at one Taipei university scheduled emergency training for technology-transfer staff Thursday, separate from the student-facing phishing modules rolled out each semester.
Response
NICS recommended universities block newly observed domains at recursive DNS resolvers, enforce FIDO2 on compliance mailboxes, and segregate export documentation on shares that do not accept external OAuth grants. The institute published indicators of compromise—including three TLS certificate fingerprints—on its threat-exchange portal for members.
MODA’s Administration for Cyber Security said it would extend a voluntary phishing-reporting hotline to .edu.tw domains that opt in, mirroring a finance-sector program launched in July. Participating schools receive anonymized click-rate benchmarks; NICS urged them to run tabletop exercises with technology-transfer offices, not only central IT.
U.S. embassy science counselors distributed a reminder that legitimate BIS notices arrive through registered government domains, not ZIP attachments from free mail hosts. NICS asked labs to verify any “license suspension” call by dialing published switchboard numbers rather than callback numbers in email footers.
Gaps
It is unclear how many regional universities and vocational labs with defense-adjacent machining programs received the same templates; NICS’s member list skews toward R1 institutions. Attribution remains open, and Taiwan prosecutors have not announced arrests tied to this week’s domains.
Smaller schools without 24-hour SOCs said they will rely on holiday on-call rotations that may delay takedown requests. Whether MODA will mandate multi-factor authentication on all export-compliance accounts by year-end is undecided; a consultation draft is expected after Golden Week.
For now, the measurable shift is tactical: attackers are phishing the paperwork that keeps dual-use labs legal, not just the credentials that keep laptops online—and universities are being asked to treat compliance officers as part of the security perimeter.
Student exchange offices that handle visitor badges for foreign collaborators said they will add callback verification steps before releasing floor plans tied to controlled tools. NICS plans a second bulletin after Golden Week with anonymized subject-line hashes so schools can tune filters without publishing live lure text.
Faculty unions asked whether phishing drills should count as work time during holiday weeks; university presidents deferred to HR policies but agreed missed drills would not block account recovery if credentials are compromised.







