<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>台灣產經新聞網 符合關鍵字"ASRC安全提醒" 最新訊息列表</title>
    <description>台灣產經新聞網 - Taiwan Business News 符合關鍵字「ASRC安全提醒」 最新訊息列表</description>
    <link>https://news.taiwannet.com.tw/rss.aspx?listType=search&amp;key=ASRC%E5%AE%89%E5%85%A8%E6%8F%90%E9%86%92</link>
    <atom:link href="https://news.taiwannet.com.tw/rss.aspx?listType=search&amp;key=ASRC%E5%AE%89%E5%85%A8%E6%8F%90%E9%86%92" rel="self" type="application/rss+xml" />
    <item>
      <guid isPermaLink="false">475DDDC9-96B8-4F57-BC45-552200C20E70</guid>
      <title>連假後「雲端發票中獎通知」激增，小心社交工程與網路釣魚攻擊！</title>
      <link>https://news.taiwannet.com.tw/news/201010/%E9%80%A3%E5%81%87%E5%BE%8C-%E9%9B%B2%E7%AB%AF%E7%99%BC%E7%A5%A8%E4%B8%AD%E7%8D%8E%E9%80%9A%E7%9F%A5-%E6%BF%80%E5%A2%9E-%E5%B0%8F%E5%BF%83%E7%A4%BE%E4%BA%A4%E5%B7%A5%E7%A8%8B%E8%88%87%E7%B6%B2%E8%B7%AF%E9%87%A3%E9%AD%9A%E6%94%BB%E6%93%8A%EF%BC%81.html</link>
      <pubDate>Wed, 08 Apr 2026 16:10:06 +0800</pubDate>
      <dc:creator>中華數位科技</dc:creator>
      <category>科技新訊</category>
      <description><![CDATA[<img src="https://news.taiwannet.com.tw/images/user_uploaded/201010_59fee724fd71422f9456107c894c7298.jpg" border="0" style="max-width: 100%;"><p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">四月的連續假期剛結束，當大眾正處於重返工作崗位的適應期時，往往是防備心較弱的時刻。詐騙集團利用此心理弱點，結合「發票中獎」等帶有利益誘惑的社交工程（</span><span lang="EN-US">Social Engineering</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）手法，發動大規模的網路釣魚（</span><span lang="EN-US">Phishing</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）攻擊。</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">近期，中華數位科技與</span><span lang="EN-US"> ASRC </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">研究中心發現主旨為「雲端發票中獎通知」的電子郵件大量爆發。先別急著高興，冷靜檢視訊息內容，就能透過以下四個明顯的「威脅特徵」來識破這場騙局：</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">破綻一：寄件者網域與宣稱單位不符</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">收到中獎通知時，首要步驟是展開「寄件者」的詳細資訊，檢視真實的電子郵件地址。攻擊者通常會將顯示名稱竄改為「財政部電子發票整合服務平台」，但背後的實際發信地址卻是無關的信箱，或遭到駭客入侵的跳板網域。政府機關的正式公務信件，網域必定具備官方的一致性</span><span lang="EN-US">(</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">例如：</span><span lang="EN-US">gov.tw</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">結尾</span><span lang="EN-US">)</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">。</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">破綻二：異常的發信主機與關聯網域活動</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">若進一步檢視電子郵件的原始資訊（如郵件標頭</span><span lang="EN-US"> Header</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）或網路連線紀錄，會發現這類釣魚信件的發送來源與關聯網域極度異常。例如，在此次攻擊活動中，發現了</span><span lang="EN-US"> tikoet.com</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">（偽造國外知名旅遊平台的錯字網域）以及</span><span lang="EN-US"> info-yuyan.com </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">等不明網域的蹤跡。這些網域通常被駭客用作發信跳板或惡意流量重導向（</span><span lang="EN-US">Redirector</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）的中繼站。一封台灣財政部的通知信，其底層傳輸卻關聯這些境外或免洗網域，是不合邏輯且極具風險的。</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">破綻三：利用短網址技術進行防護規避</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">為了繞過企業的電子郵件安全閘道與掩飾真實的惡意連結，攻擊者會在信件中使用如</span> <strong><span lang="EN-US">TinyURL</span></strong> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">等縮址服務。這是一種常見的網址混淆技術（</span><span lang="EN-US">Obfuscation</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）。政府機關發送重要通知時，基於資訊透明與安全性考量，原則上會直接提供完整的官方網址，極少要求民眾點擊來源不明的短網址。</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">破綻四：錯字網域（</span><span lang="EN-US">Typosquatting</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）與偽造政府層級</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">若使用者不慎點擊了短網址，流量在經過中繼站後，最終會被導向類似下方的惡意網址：</span><span lang="EN-US"> hxxps://gov.einvioce.com.tw/menghuan.html?c=aHR0cHM6Ly9nb3YuZWludmlvY2UuY29tLnR3Lw==</span></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">在我們進行調查的時間點，這個網頁已經關閉，但網址本身暗藏了兩個高階的欺騙手法：</span></p>
<ol style="margin-top: 0cm;" start="1" type="1">
<li class="MsoNormal" style="mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">偽造政府網域層級：</span></strong> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">台灣政府單位的官方網站，其頂級網域（</span><span lang="EN-US">TLD</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）必定是</span> <strong><span lang="EN-US">.gov.tw</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">。該釣魚網址的結尾是</span><span lang="EN-US"> .com.tw</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">（一般商業註冊），攻擊者只是刻意在最前面加上了</span><span lang="EN-US"> gov. </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">作為「子網域（</span><span lang="EN-US">Subdomain</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）」，企圖混淆視聽。</span></li>
<li class="MsoNormal" style="mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">錯字網域攻擊：</span></strong> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">財政部電子發票的正確英文拼寫為</span><span lang="EN-US"> einvoice</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">。駭客刻意將網址註冊為</span><span lang="EN-US"> einvioce</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">（將</span><span lang="EN-US"> o </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">和</span><span lang="EN-US"> i </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">順序對調），利用人類大腦在快速閱讀時會自動腦補修正的視覺錯覺，成功騙過受害者的眼睛。</span></li>
</ol>
<p class="MsoNormal"><span lang="EN-US">&nbsp;</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">資安防護建議與應對措施</span></strong></p>
<p class="MsoNormal"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">當您被引導至該釣魚網站後，攻擊者會可能要求您輸入身分證字號、平台密碼，甚至以「匯入獎金」為由，誘騙您填寫<strong>信用卡卡號與背面末三碼（</strong></span><strong><span lang="EN-US">CVV</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，進而造成嚴重的財務損失與個資外洩。</span></p>
<p class="MsoNormal"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">為保障您的資訊與財產安全，請落實以下防護原則：</span></strong></p>
<ul style="margin-top: 0cm;" type="disc">
<li class="MsoNormal" style="mso-list: l1 level1 lfo2; tab-stops: list 36.0pt;"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">零信任原則（</span><span lang="EN-US">Zero Trust</span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）：</span></strong> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">「永不信任，始終驗證」（</span><span lang="EN-US">Never Trust, Always Verify</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">），對於任何帶有超連結的主動通知（無論是簡訊或</span><span lang="EN-US"> Email</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">）保持高度懷疑。絕對不要直接在點擊不明連結後開啟的網頁中，輸入任何機敏個資或金融資訊。</span></li>
<li class="MsoNormal" style="mso-list: l1 level1 lfo2; tab-stops: list 36.0pt;"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">自主查證：</span></strong> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">若需確認發票是否中獎，請略過信件中的連結，自行開啟官方推出的「<strong>統一發票兌獎</strong></span><strong><span lang="EN-US"> APP</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">」，或於瀏覽器手動搜尋並進入「財政部電子發票整合服務平台」查證。</span></li>
<li class="MsoNormal" style="mso-list: l1 level1 lfo2; tab-stops: list 36.0pt;"><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">落實通報機制：</span></strong> <span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">若收到此類帶有惡意網址的詐騙訊息，建議可撥打</span> <strong><span lang="EN-US">165 </span></strong><strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">反詐騙諮詢專線</span></strong><span style="font-family: '新細明體',serif; mso-ascii-font-family: Aptos; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Aptos; mso-hansi-theme-font: minor-latin;">，或透過警政相關管道進行檢舉通報，協助將該惡意網域列入阻擋清單，降低整體網路環境的資安風險。</span></li>
</ul>
<p class="MsoNormal"><span lang="EN-US">&nbsp;</span></p>]]></description>
    </item>
  </channel>
</rss>