The Ministry of Data and Information Technology fined EVERY8D messaging platform NT$2 million and ordered it to make corrections within a time limit
Quick Look
- The Ministry of Digital Development determined that Interactive Communications, a subsidiary of the corporate messaging platform EVERY8D, violated the Personal Data Protection Act, and fined the company and its representatives each NT$1 million, for a total of NT$2 million, and ordered corrections within a time limit.
- The incident originated from service anomalies and suspected personal information leakage at the end of May, involving hacker attacks and insufficient information security protection.
AI-generated summary
Why It Matters
Corporate messaging platform EVERY8D is a domestic messaging service provider. It is said to rank first in the country in terms of number of users and sending efficiency. Its services are widely used in finance, e-commerce and digital identity verification.
Corporate messaging platform EVERY8D reported service anomalies and suspected personal information leakage in May this year. The Digital Development Department’s investigation results and fines were released. The company and its representatives were fined NT$1 million each and ordered to make corrections within a time limit. (Downloaded from PEXELS)
[Reporter Qiu Qiaozhen/Taipei Report] In May this year, corporate messaging platform EVERY8D experienced service anomalies and suspected personal information leakage, and the Digital Development Department’s investigation results and penalties were released. The Ministry of Digital Development determined that Interactive Information Co., Ltd., to which EVERY8D belongs, violated Article 27, Paragraph 1, of the Personal Data Protection Act. On July 22 this year, in accordance with Article 48, Paragraph 2 and Article 50 of the same law, the company and its representative were each fined NT$1 million, for a total of NT$2 million, and ordered to make corrections within a time limit.
EVERY8D is a domestic enterprise messaging platform. According to the company's official website, it is a national messaging system, ranking first in the country in terms of number of users and sending efficiency. Since SMS verification has become a common identity verification method in finance, e-commerce and various digital services, EVERY8D's services cover a wide range of areas. This incident has also drawn attention to the information security and personal information protection mechanisms of corporate SMS platforms.
Please read on...
The incident occurred at the end of May this year. The EVERY8D text messaging platform owned by domestic information service provider Teamplus was suspected of being attacked by hackers. In addition to causing a temporary service interruption, it was also reported that user personal data was suspected to be leaked.
After the incident, the Ministry of Digital Development launched a response mechanism, and the Digital Industry Agency required Interactive Information to provide relevant information in accordance with Article 22 of the Personal Data Protection Act. On June 2, it conducted an on-site administrative inspection with the National Communications Commission (NCC) to clarify the cause of the incident and whether the operator's personal data protection and incident response measures complied with relevant laws and regulations.
At that time, the Digital Industry Agency required Interactive Information to take contingency measures. If there is a personal data leakage, it should notify relevant affected businesses and the public as soon as possible, so that the parties concerned can understand the possible infringement of personal data, and take timely remedial measures to reduce the expansion of damage.
In addition, the Information Security Administration of the Ministry of Digital Development simultaneously issued an information security alert, notifying government agencies and key infrastructure units to assess risks, confirm whether to use interactive information-related services, and conduct follow-up notifications and disposals in accordance with the "Information Security Management Act" and the "Personal Data Protection Act".
After follow-up investigation, it was finally determined that Interactive Information violated Article 27, Item 1 of the Personal Data Protection Law. According to the provisions of this article, the Ministry of Digital Development imposed a fine of 1 million yuan on the Interactive Information Company and its representative in accordance with the law, totaling 2 million yuan, and required corrections within a time limit.
Grasp the economic pulse with one hand. Click here to subscribe to Free Finance Youtube channel
What to Watch
AI outlook — possibilities, not facts
Interactive Information will complete information security improvements within a deadline and accept review
Likely · Within weeks
Similar messaging platforms will strengthen their own data security protection and personal data compliance inspections
Possible · Within months
Open Questions
- Exactly how many user profiles were leaked?
- What is the type and sensitivity of the leaked data?
- Have the sources and methods of hacker attacks been identified?
- Has Interactive Information completed all necessary security improvement measures?




