The National Communications Commission told major mobile operators and retail banks on Friday to register alphanumeric SMS sender IDs used for fraud warnings and one-time passwords before a November compliance deadline, after a Mid-Autumn phishing wave spoofed lender short codes well enough to fool customers who had just received legitimate holiday transfer alerts. NCC staff briefed carriers in a closed session reviewed by InfoHandle; the order stops short of banning SMS banking outright but shifts liability toward issuers that broadcast from unregistered strings.
What broke during the holiday
Security teams at three Taiwanese banks logged a spike in smishing links sent from sender names visually similar to official fraud hotlines—extra characters, homoglyphs, or recycled marketing headers that still displayed as the bank's trade name in some Android inboxes. Victims clicked because they had genuine OTP texts minutes earlier from family reunion payments. MODA's national CERT tallies for the week are not public yet; bank association bulletins cited "double-digit percent" growth in reported SMS fraud attempts compared with the prior Mid-Autumn, without naming institutions.
What is confirmed: attackers did not need to compromise core banking switches. They abused commercial SMS aggregators and grey-market SIM farms that can push arbitrary sender labels until the NCC's registry rejects them at the gateway.
What registration changes
Under the draft enforcement memo, only pre-approved sender strings tied to a financial institution's unified business number may carry words like "alert," "verify," or institution abbreviations in Traditional Chinese or English. Carriers must reject outbound messages that fail registry lookup and log attempts for FSC review. Banks that still blast promotional SMS from unregistered marketing IDs must split those streams onto separate short codes—a operational headache compliance officers have postponed for years.
Smaller credit unions and regional lenders get a phased onboarding list through the Taiwan Association of Banks, which will host a shared portal for proof-of-ownership uploads. Foreign card issuers texting roaming customers in Taiwan must appoint a local agent or route through a Taiwanese bank's registered ID.
Who must patch and disclose
Mobile network operators Chunghwa Telecom, Taiwan Mobile, Far EasTone, and Taiwan Star face the first fines if unregistered bank traffic leaves their SMS centers after the deadline. Banks face FSC scrutiny on customer reimbursement policies when spoofed messages precede losses. Insurance tail questions—whether cyber riders cover SMS social engineering—were raised in the briefing but left to policy wording, not the NCC rule.
Sam Rivera's desk tracks attribution carefully: no regulator has publicly tied the holiday wave to a named APT group. Incident responders should assume commodity phish kits until law-enforcement indictments say otherwise.
Technical limits
Sender ID registration does not stop SIM-box flooding from overseas routes that never touch Taiwanese gateways, and iMessage or RCS channels bypass SMS entirely. Banks are still urged to push high-risk actions through app push with device binding. The NCC acknowledged Apple and Google OS display quirks that truncate sender names—registry entries will include maximum display lengths per carrier.
Timeline and penalties
Carriers must stand up registry APIs by late October; banks get a two-week grace period if they show migration plans. Fines start at NT$500,000 per day of continued unregistered sends for operators, with lower tiers for first-time bank violations. Public comment on the order opens Monday on the NCC site.
What customers should do now
Until registration goes live, treat any SMS link as untrusted even if the sender name matches your bank. Use official apps or dial numbers on the back of your card. Report spoof strings to 165 anti-fraud hotline so CERT can feed the registry blocklist.
The Mid-Autumn wave was a reminder that Taiwan's digital holiday economy runs on SMS receipts—and that fraudsters schedule campaigns when families move money. Registering sender IDs is a plumbing fix, not a cure, but it closes the easiest spoof lane before the next long-weekend transfer rush.
Bank CISOs said they will publish customer-facing FAQs distinguishing registered alert strings from marketing SMS, a small step that only works if call-center scripts use the same vocabulary. MODA staff noted that future audits will sample whether lenders still send mixed-purpose messages from legacy short codes after the grace period ends.








