Taiwan's National Police Agency has suspended a fingerprint-and-facial-recognition attendance system after Democratic Progressive Party Legislator Lin Chun-hsien (Tainan, DPP New Tide faction) revealed that the devices were made by China's ZKTeco, sold under a Taiwanese label (Taipei Times, July 16, 2026). The same equipment, procured for clocking employees in and out, was also installed at the Coast Guard Administration, the Customs Administration, and state-owned CPC Corporation — agencies that sit squarely inside Taiwan's national-security perimeter.
What Was Actually Found
Lin says National Communications Commission registration records identify the Taiwanese supplier's hardware as coming from Armatura Tech Co, a company that is 99.98% owned by ZKTeco, one of the world's largest biometric-terminal manufacturers. The rebranded devices were, in Lin's account, "visually identical" to ZKTeco's own products, and their instruction manuals still carried Chinese-language terminology. Over roughly the past decade, the supplier won 16 separate government procurement contracts on this basis. NPA Personnel Office Director Liu Yung-fu confirmed no breach has been identified so far, but the agency pulled the devices, demanded an explanation from the vendor, and opened a review.
This is not an isolated find. Less than seven months earlier, the Ministry of the Interior ordered the National Immigration Agency to halt use of a different facial-recognition timekeeping platform, Papago Face8, after reports that it ran on China-made motherboards and software — a system already deployed across more than 100 NIA units, with the ministry noting sister agencies at the Ministry of Economic Affairs had installed it too (Taipei Times, Jan. 1, 2026). Two unrelated vendors, two different agencies, the same underlying pattern: Chinese-origin hardware handling government employees' biometric data, discovered only after a legislator or a journalist went looking.
The Case for Caution Here Is Real
It is worth stating plainly why this matters and why Lin's concern deserves to be taken seriously rather than waved off as protectionist reflex. Biometric identifiers are the one credential category a person cannot rotate after a breach — a leaked fingerprint template or facial hash is compromised for life. A 2024 Kaspersky analysis of ZKTeco's hybrid biometric terminals found 24 distinct vulnerabilities, including SQL injection, arbitrary file writes, and remote-code-execution flaws that could let an attacker exfiltrate stored biometric data or plant persistent backdoors (Kaspersky, June 2024). Concentrating that risk inside police, coast guard, and customs facilities — bodies that handle enforcement, border control, and, in CPC's case, energy infrastructure — is a legitimate escalation from ordinary IT hygiene to a national-security question. Taiwan has been here before with Hikvision-style surveillance camera bans; the instinct to keep adversary-state hardware out of sensitive facilities is not paranoia, it is standard supply-chain practice that most democracies now follow in some form.
But the Diagnosis Points to a Procurement Failure, Not an Innovation Problem
Where this episode should push policy is toward fixing how Taiwan screens vendors, not toward broader suspicion of biometric or facial-recognition technology as such. Taiwan already has a rule that should have caught this: the Executive Yuan's December 2020 directive prohibiting government agencies from procuring mainland Chinese-brand ICT products, administered under the Cyber Security Management Act framework. The ZKTeco case shows that rule is being satisfied on paper while failing on substance — because it screens the brand on the box, not the silicon and firmware inside it. A domestic-sounding company name and a rebranded chassis were, per Lin's account, enough to pass 16 rounds of procurement review over ten years. New Bloom Magazine's reporting on the episode highlights the second structural driver: lowest-bidder tendering rules for government contracts create a direct financial incentive to source the cheapest available hardware, and cheap biometric hardware disproportionately comes from Chinese OEMs with global reseller networks (New Bloom Magazine, July 25, 2026).
The fix that follows from that diagnosis is narrow and achievable: extend Taiwan's existing ICT ban from a brand-name test to a components-and-supply-chain disclosure requirement, specifically for devices that touch biometric data at security-sensitive agencies, paired with an exception carve-out from lowest-bid rules for that narrow procurement category. That is a proportionate, evidence-based response — it targets the actual failure mode (opaque sourcing) rather than banning facial-recognition attendance systems outright, which remain a legitimate, efficient tool for workforce management when the hardware is trustworthy. Legislators reaching for a blanket moratorium on biometric attendance tech in government would be solving the wrong problem; the technology worked exactly as intended, right up until the procurement process failed to verify who actually built it.
What should follow now is transparent: publish the review's findings, disclose whether any of the 16 contracts involved data actually leaving Taiwan, and close the component-disclosure gap before the next rebrander wins contract number seventeen.