Taiwan's National Communications Commission on Tuesday issued an urgent consumer alert about fake mobile-carrier SMS messages that mimic typhoon evacuation and shelter instructions as counties begin synchronized drill week, according to a bulletin carriers received and reviewed by InfoHandle. The messages use legitimate-looking sender labels and Traditional Chinese copy lifted from past CWA advisories, but deep links route to credential harvesters or donation scams—not county disaster dashboards.

What is confirmed

NCC incident logs show more than forty spoof strings reported since Sunday across four major operators, with spikes in New Taipei, Taoyuan, and Kaohsiung districts that scheduled public evacuation exercises. What is confirmed: attackers are not compromising carrier billing systems; they push messages through grey-market SMS aggregators that still display carrier trade names on some Android handsets. What is not confirmed: any single syndicate name—Chih-Wei Cheng's desk treats attribution as unknown until prosecutors file indictments.

How the lures work

Typical scripts tell recipients a "level-two shelter assignment" changed and demand taps to confirm attendance—harvesting LINE logins or payment-app credentials. Others promise fuel subsidies for generators if users "register" bank cards before drill day. Real county alerts increasingly use push notifications inside government apps with registered sender IDs; they do not ask for card numbers in SMS bodies.

NFA staff told operators to whitelist official shelter URLs on customer-care pages and to block newly reported spoof strings at the SMS gateway within four hours. MODA's CERT is feeding hashes to Meta and Google because parallel Facebook ads promote the same fake shelter maps.

Who is liable and what firms must do

Carriers face escalating fines if unregistered strings impersonating disaster keywords leave their networks after a November registry deadline NCC reiterated in the alert. County governments must publish drill schedules on open data portals—not only through social posts that scammers copy. Banks were copied because some lures name lender co-branding on "emergency cash" scams.

Technical limits

Sender registration does not stop offshore SIM-box floods or iMessage channels. iOS users who disable government app notifications remain vulnerable to SMS-only fraud. Evacuation drills themselves do not trigger automatic location tracking; any message claiming GPS confirmation is fake.

Timeline

Drill week runs through Friday in participating municipalities; CWA may hoist typhoon sea warnings independently of exercises. NCC will publish updated blocklists nightly during the period. Public comment on disaster-keyword sender rules closes next month.

What residents should do

Verify shelter assignments through county disaster apps or voice hotlines printed on official notices—not SMS links. Report spoof strings to the 165 anti-fraud line so gateways update blocks. If you already submitted credentials, call your bank's fraud desk and rotate passwords from a clean device.

Typhoon season turns every drill into a social-engineering calendar event. Closing the spoof lane requires registered sender plumbing and citizens who treat urgent SMS like strangers at the door—even when the font looks like Chunghwa Telecom.

Operator coordination

Chunghwa Telecom and Taiwan Mobile told NCC they will push bilingual in-app banners before each county drill window, repeating that SMS shelter links are not authoritative. Smaller regional carriers asked for shared template copy from the National Fire Agency so customer-service scripts match county wording and reduce panic callbacks.

County cyber teams will run tabletop exercises comparing official app push latency against SMS spoof arrival times—a metric NCC may publish after drill week to justify faster gateway blocks during real storm warnings.