Chunghwa Information Security Clarifies Role in FortiBleed Cybersecurity Incident
Translated from Chinese, summarized and contextualized by DistantNews.
At a glance
- Chunghwa Information Security (CIS) has clarified its involvement in the global 'FortiBleed' cybersecurity incident.
- CIS stated its internal systems are secure and have not been compromised.
- The company explained its name appeared in threat intelligence due to past registration of a Fortinet partner account for customer support.
Chunghwa Information Security (CIS), a subsidiary of Chunghwa Telecom, has issued a clarification regarding its connection to the recent global cybersecurity incident known as 'FortiBleed.' The company emphasized that its internal information systems are operating normally and have not experienced any intrusions, data breaches, or security impacts.
CIS explained that its name appeared in threat intelligence reports because, in the past, it registered a FortiSupport Partner account on Fortinet's Partner Portal. This account was used for product registration and technical support services when CIS assisted clients in selling Fortinet equipment. Consequently, CIS's domain information was included in external intelligence data, reflecting a registration association with the original manufacturer's product, not an internal security compromise.
The threat intelligence mentioned our company name because in the past, when assisting Fortinet's original manufacturer in selling equipment to customers, we used our company's FortiSupport Partner account in the original manufacturer's Partner Portal registration process to provide subsequent product registration and technical support services, causing our company's domain information to appear in external intelligence data.
Proactively addressing the situation, CIS highlighted that its cybersecurity intelligence team had been monitoring relevant information from international sources since mid-June. The company promptly investigated devices under its management and notified affected clients. CIS provided clear emergency response procedures and enhanced protection guidelines, including credential resets, multi-factor authentication (MFA) activation, and firmware updates, to help clients secure their equipment.
Furthermore, as a precautionary measure, CIS conducted a comprehensive review of its own internal cybersecurity and network equipment, confirming all systems are secure. The company reiterated its commitment to maintaining the highest standards of information security for itself and its clients, leveraging its expertise and collaborative advantages to provide robust security support.
As a leading cybersecurity service provider, we always maintain information security for ourselves and our clients to the highest standards. We will continue to leverage our professional intelligence and joint defense advantages to be the most solid cybersecurity support for our clients.
Originally published by Liberty Times in Chinese. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.