Taiwan Stock Exchange Co. ran a coordinated phishing simulation this week against back-office staff at member brokerages, timing the drill before third-quarter earnings disclosures when settlement clerks and compliance aides—not just front-line traders—handle password resets and vendor file drops. TWSE summarized aggregate click rates in a memo to member firms reviewed by InfoHandle; individual broker names were withheld, but the exchange said more than one midsize house exceeded internal risk thresholds on the first-wave lure.
What the drill tested
Participating firms received spoofed messages mimicking TWSE file-transfer notices and accounting-system upgrade alerts, with links to cloned login pages hosted on short-lived domains. The scenario targeted credentials used for daily reconciliation uploads and margin batch jobs, systems that sit outside the flashy trading terminals investors see on TV. Anyone who entered usernames triggered an immediate in-browser training module; repeat clickers were flagged to CISOs for mandatory briefings before earnings week.
TWSE has run tabletop exercises before, but this cycle added voice-note follow-ups imitating IT help desks—a tactic Securities and Futures Bureau examiners warned about in a July circular after overseas broker incidents.
Why back offices matter
Retail trading apps get multi-factor authentication marketing, yet legacy settlement consoles often rely on password-only VPNs reachable from office desktops. A compromised clerk account cannot place customer orders directly in every architecture, but it can alter beneficiary lists on test payments, swap bank account metadata in pending wires, or exfiltrate client position files ahead of block trades.
Two Taiwan brokers disclosed minor phishing losses in 2025 filings; none matched this week's drill, but SFB supervisors treat cumulative near-misses as evidence that awareness training lagged hiring surges during the AI-stock rally.
What firms must rotate
Member memo language urged password rotation for any account touched during the drill, revocation of stale API keys on file-transfer appliances, and verification that third-party custodian portals require hardware tokens. TWSE asked CEOs to sign attestation letters confirming remediation tickets closed before October settlement cycles.
Insurance and legal teams were copied because directors' and officers' policies increasingly exclude losses where regulators find "foreseeable" phishing after documented drills.
Limits of simulations
Click rates drop when employees know a test is likely during earnings season—attackers do not send calendar invites first. TWSE cautioned that real adversaries will use compromised vendor inboxes, not obvious typos. The exchange is weighing allow-listed email authentication for official notices but has not mandated DMARC at strict enforcement for members yet.
Market structure context
Taipei markets enter a dense disclosure window when semiconductor and financial heavyweights report. GreTai OTC names follow similar calendars. A back-office outage delaying settlement batches can cascade to collateral calls even without a successful wire fraud.
Next steps from regulators
SFB observers attended the drill readout and may fold results into 2026 examination manuals. Taiwan Securities Association will host a member workshop on segregating settlement VLANs from general office browsing.
For customers, the practical takeaway is unchanged: brokers will never ask for passwords through email links. The drill's value is forcing back-office managers—who rarely make headlines—to treat phishing as a settlement risk, not an IT trivia question, before another earnings season moves real money through their queues.
Vendor and remote-access paths
Member firms also tested whether outsourced fund-accounting vendors received the same spoof messages through shared ticketing portals. TWSE data showed vendor click rates rivaled in-house staff, reinforcing SFB guidance to extend phishing metrics to subcontractors with settlement access. Several brokers told the exchange they will require hardware tokens for vendor VPN logins before October close books.
Reporting to the public
TWSE does not plan to publish firm-level drill scores, avoiding a competitive stigma that might discourage participation. Aggregate trends will appear in an annual market integrity report. Retail investors should still verify dividend notices inside authenticated apps; the exchange reiterated that material disclosures post only on its official announcement system, never through ad-hoc file links.
Compliance officers who missed the drill window can request a makeup cohort in early October, but SFB supervisors said repeat no-shows may factor into branch examinations next year when earnings-related fraud remains elevated across the region.








