Central News Agency Report
(Taipei, July 15 — Reporter Wang Cheng-chung) Democratic Progressive Party (DPP) legislator Lin Chun-hsien today raised concerns that Taiwan's Ministry of the Interior National Police Agency (NPA) and Coast Guard Administration have procured biometric attendance management systems suspected of using products from China's ZKTeco. This could expose vast amounts of civil servants' biometric data to cybersecurity risks, creating national security vulnerabilities. The NPA stated that it has already fully discontinued using the equipment and has not detected any cybersecurity incidents.
Lin held a press conference at the Legislative Yuan titled 'Facial and Fingerprint Data Fully Exposed! Government Attendance Devices Could Become National Security Crises,' revealing that a Taiwanese vendor may have rebranded ZKTeco's biometric devices as its own. Over the past decade, such devices have won 16 government procurement bids, including facial and fingerprint recognition systems used for attendance management in government agencies.
Lin emphasized that procurement agencies include critical national security bodies such as the NPA, Coast Guard Administration, Customs Administration, and CPC Corporation. If biometric data were to be misused, the consequences would be severe.
Citing the NPA's 2023 'Biometric Attendance Device Procurement Project,' Lin compared device appearances, product descriptions from the Taiwanese vendor, and ZKTeco's official product brochures. He noted that not only do the photos match exactly, but the Taiwanese vendor's manual retains Chinese-specific terms like 'U-disk' and 'firmware,' raising serious doubts about the product's origin.
Furthermore, Lin reviewed National Communications Commission (NCC) type-approval records and found that the Taiwanese vendor's product test report appears to be a rebranded version of ZKTeco's identical product. Public records show that the listed manufacturer, 'ARMATURA TECH CO., Ltd.,' is a subsidiary 99.98% owned by ZKTeco, suggesting the product is Chinese-made but labeled otherwise to circumvent procurement regulations.
Lin also pointed out inconsistent standards among agencies in determining whether biometric devices fall under 'sensitive or national security (including cybersecurity)-related procurement.' While the NPA classifies such devices as sensitive, the Coast Guard Administration, Customs Administration, and NPA's First Security Corps do not.
Lin demanded that all government agencies that procured such devices immediately conduct comprehensive audits of their origins and ensure no data leaks have occurred. He urged the Digital Ministry's Cybersecurity Administration to clearly define all personal data-collecting devices as sensitive procurements, eliminating agencies' discretion in classification.
He also called on the Executive Yuan's Public Construction Commission to review procurement policies, advocating for the 'most advantageous bid' principle in sensitive procurements to prevent low-cost rebranded products from entering government systems.
Liu Yung-fu, Director of the NPA's Personnel Division, attending the press conference, stated that the NPA's attendance system operates on an internal network with no external connections. No cybersecurity incidents have been detected. The agency has fully discontinued using the devices, requested full origin documentation from the vendor, and submitted it to the Cybersecurity Administration for verification. The NPA will conduct a comprehensive review and ensure all subordinate units comply with procurement laws and regulations. (Edited by Su Chih-tsung) 1150715
FACT BOX
- Source: CNA (Central News Agency)
- Category: Taiwan
- Organizations: ARMATURA TECH CO., Ltd.