2026-07-22
Added · Updated
Taiwan Shin Kong Securities Co., Ltd. is fined New Taiwan Dollars 3.6 million and issued a warning for failing to implement its internal control system, which resulted in multiple cybersecurity incidents following its merger with Yuan Fuh Securities Co., Ltd. The company must double its operational risk equivalent amount for its adequate capital ratio until cybersecurity deficiencies are rectified and approved by the Taiwan Stock Exchange Corporation. Additionally, the respondent is ordered to submit a comprehensive system improvement plan and engage a third-party cybersecurity institution for verification within three months, while also imposing disciplinary actions on relevant personnel.
Regulatory Information
Back to Homepage
Announcement Information
Penalty Cases
Penalty Cases
FACEBOOK Line Twitter Print-friendly Back to Previous Page
Taiwan Shin Kong Securities Co., Ltd. Violation of Securities Management Regulations Penalty Case (Jin Guan Zheng Quan Fa Zi No. 1150383460)
2026-07-22
Financial Supervisory Commission Ruling Document
Addressee: As per original/copy Date of Issue: July 21, 2026 (Republic of China Year 115) Document Number: Jin Guan Zheng Quan Fa Zi No. 1150383460 Respondent: Taiwan Shin Kong Securities Co., Ltd. Unified Business Number: Redacted Address: Redacted Legal Representative or Manager: Chen XX Address: Redacted
Subject: The Respondent failed to properly plan and test information systems prior to the merger, resulting in multiple major cybersecurity incidents after the merger. This constitutes a failure to implement the internal control system, violating Article 2, Paragraph 2 of the Rules Governing Securities Dealers. Accordingly, a fine of New Taiwan Dollars 3.6 million is imposed under Article 178-1, Paragraph 1, Item 4 of the Securities and Exchange Act, along with a warning under Article 66, Item 1 of the same Act. Additionally, under Article 66, Item 5, the Respondent is ordered to: increase the operational risk equivalent amount for its adequate capital ratio by 1x until the cybersecurity deficiencies are rectified; submit a specific short-, medium-, and long-term system improvement plan within three months from the day following service of this ruling, reporting improvement measures and execution status to the Board of Directors of the Respondent and its financial holding company parent until rectification is complete; engage a credible third-party cybersecurity professional institution for verification; and impose disciplinary actions on relevant personnel involved in the violations, reporting to the Commission within three months.
Facts: The Taiwan Stock Exchange Corporation (hereinafter "TSE") conducted an inspection regarding cybersecurity incidents that occurred on the first day of business (April 7, 2026), April 14, 2026, April 20, 2026, and May 21, 2026, following the merger of the Respondent with Yuan Fuh Securities Co., Ltd. on April 6, 2026. The inspection found that the Respondent failed to implement cybersecurity incident reporting, experienced system interruptions exceeding the tolerable limit of 1 hour, failed to verify data correctness in programs, had incomplete testing scenarios before program launch, did not verify system changes after launch, did not conduct stress tests, used incorrect program versions, had inadequate business continuity plans, did not conduct business continuity drills, and had insufficient monitoring of important software and hardware equipment. These deficiencies indicate that the Respondent failed to implement its internal control system, violating Article 2, Paragraph 2 of the Rules Governing Securities Dealers.
Reasons and Legal Basis:
According to Article 66, Items 1 and 5, and Article 178-1, Paragraph 1, Item 4 of the Securities and Exchange Act: "If a securities dealer violates this Act or orders issued pursuant to this Act, in addition to penalties under this Act, the competent authority may, depending on the severity of the circumstances, impose the following dispositions and order improvement within a specified period: 1. Warning. ... 5. Other necessary dispositions." and "Securities dealers ... committing any of the following acts shall be fined between New Taiwan Dollars 300,000 and 6,000,000, and may be ordered to improve within a specified period; if not improved upon expiration, repeated fines may be imposed: ... 4. Failure to properly implement the internal control system." Furthermore, Article 2, Paragraph 2 of the Rules Governing Securities Dealers stipulates: "The operation of securities dealer business shall be conducted in accordance with laws, regulations, articles of association, and the internal control system specified in the preceding paragraph."
The TSE inspection revealed the following deficiencies in the Respondent:
(1) On April 7, 2026, at 9:05 AM, an anomaly occurred in the electronic trading system login and inventory query services. The Respondent failed to report the cybersecurity incident within 30 minutes of becoming aware, violating Item 1, Part IV of the Guidelines for Reporting and Responding to Information Security Incidents in the Securities and Futures Markets.
(2) From 9:05 AM to 11:48 AM on April 7, 2026, and from 9:04 AM to 12:14 PM on April 14, 2026, the core system was interrupted for more than the stipulated tolerable interruption time of 1 hour. This violated the internal control system (hereinafter "Internal Control System") CC-20000 Business Continuity Management (15) as prescribed by the Respondent under the Standards for Internal Control Systems of Securities Dealers.
(3) Programs related to declarations and manual correction of wrong account numbers were not tested before launch, data input correctness was not verified after launch, and the correctness of system changes due to the merger was not verified. This led to system processing anomalies and erroneous execution results, causing delayed declaration of settlement data to the TSE between April 7 and April 19, 2026. This violated Internal Control System CC-19000 System Development and Maintenance (6) 5, (14) 7, and (16) 2.
(4) The securities back-office system did not adequately conduct system stress tests considering post-merger operational scenarios before the merger launch. Consequently, the system could not handle the post-merger usage volume, causing system anomalies and affecting investor rights. This violated Internal Control System CC-17020 Computer System and Operation Security Management (6).
(5) During the declaration of credit transaction balance details after market close on April 7, 2026, the program did not implement version control properly. An incorrect version was deployed during updates, resulting in incorrect data output formats and delayed declaration of data to the TSE. This violated Internal Control System CC-19000 System Development and Maintenance (14) 4.
(6) The prescribed business continuity plan was inadequate. It did not consider reporting anomalies, error account handling, or the impact of the merger on business continuity. Consequently, there were no effective countermeasures when related anomalies occurred, affecting investor rights. This violated Internal Control System CC-20000 Business Continuity Management (8).
(7) Business continuity drills were not conducted prior to the merger, leading to insufficient operational response and affecting business continuity. This violated Internal Control System CC-20000 Business Continuity Management (8).
(8) The mobile order application's memory resources were fully loaded due to its own monitoring program, causing an impact on some clients' ability to log in and place orders or query information from 12:00 PM until market close on April 20, 2026. This violated Internal Control System CC-17010 Network Security Management (1) 4.
(9) Testing for the accounting middle-office program version update before launch was incomplete, causing anomalies in electronic trading platform order reporting starting at 9:28 AM on May 21, 2026. This violated Internal Control System CC-19000 System Development and Maintenance (6) 5.
(1) To strengthen the Respondent's operational risk bearing capacity, the operational risk equivalent amount for its adequate capital ratio shall be increased by 1x. The Respondent must complete the increase in operational risk capital provision and calculate the adequate capital ratio and its impact by the 10th of the month following the receipt of this ruling. Upon completion of rectification of the relevant cybersecurity deficiencies and approval by the TSE (copy recipient), the original operational risk provision ratio may be restored from the following month.
(2) The Respondent is ordered to comprehensively review the company's system deficiencies and submit a specific short-, medium-, and long-term system improvement plan within three months from the day following service of this ruling. When necessary, engage an information security consultant, and report improvement measures and execution status to the Board of Directors of the Respondent and its financial holding company parent until rectification is complete.
(3) To ensure transaction safety and system stability, the Respondent is ordered to engage a credible third-party cybersecurity professional institution for verification and submit the verification opinion to the TSE (copy recipient) for forwarding to this Commission.
(4) The Respondent is ordered to impose disciplinary actions on relevant personnel involved in the violations and report to the Commission within three months from the day following service of this ruling.
Payment Method:
Notes:
Original: Taiwan Shin Kong Securities Co., Ltd. (Addressee: Legal Representative Mr. Chen XX) Copy: Taiwan Stock Exchange Corporation (Representative Mr. Lin XX), Taiwan OTC Securities Center (Representative Mr. Jian XX), Securities Dealers Association (Representative Mr. Chen XX), Accounting Office of the Securities and Futures Bureau, Secretariat of the Securities and Futures Bureau, Securities Dealers Management Group of the Securities and Futures Bureau.
Page Views: 70 Last Updated: 2026-07-22
Privacy Policy Statement | Information Security Policy Statement | Website Data Open Declaration | Subscribe to Newsletter | Latest Newsletter
Financial Supervisory Commission Copyright 220232 18th Floor, No. 7, Section 2, Xianmin Avenue, Banqiao District, New Taipei City
FSC Electronic Map
Telephone: (02)8968-0899 Fax: (02)8969-1215
FSC New York Representative Office: 1 E.42 Street, 13F, New York, NY 10017, U.S.A. Contact Phone: (1-212) 317-7326
FSC London Representative Office: 46-48 Grosvenor Gardens London SW1W 0EB, UK Contact Phone: (44-20)7628-1501
If you have specific suggestions for improving our global website, please email us. Thank you.
Last Updated: 2026-07-21
Visitor Count: 61490248
Back to Top