On paper, a batch of high-end Nvidia-powered AI servers left factories in Taiwan bound for a data centre on the island. Most of them never got there. Taiwanese customs stopped dozens at the border. The rest quietly changed course, some routed through Indonesia, a handful through Japan, and ended up plugged in at customers in China.
On Monday, prosecutors in the port city of Keelung indicted nine people over the scheme, Al Jazeera reported. The list of the accused is what makes this case sting: it includes an employee of Nvidia's Taiwan unit and two staff from Super Micro Computer's Taiwan operation. Eight face charges of breach of trust and document forgery for dressing China-bound shipments up as local deliveries. Three are accused of embezzlement. Of 130 servers involved, 56 were seized at the border and 74 reached China, 50 of them transshipped through Indonesia. The machines carried Nvidia chips, the same restricted silicon Washington has spent two years trying to keep out of Chinese data centres.

Table of Contents
Why Taiwan's Nvidia case worries Malaysia
Malaysia was not named in this indictment. It keeps turning up in the wider story anyway. When investigators trace how restricted chips reach China, the maps almost always run through Southeast Asia, and Malaysia sits in the middle of the region's data-centre boom. The route does not even need a physical shipment now. Chinese groups including ByteDance, Alibaba and Tencent have reportedly rented Nvidia computing power remotely through third countries, CNBC reported, with one arrangement using a cloud provider's Nvidia chips sitting inside Malaysia. A proposed United States law, the Remote Access Security Act, is aimed squarely at closing that gap.
Kuala Lumpur has already felt the pressure. In July 2025 Malaysia's Ministry of Investment, Trade and Industry (MITI) ruled that anyone exporting, transshipping or moving US-origin AI chips through the country must hold a trade permit and give authorities 30 days' notice, a step that coverage at the time described as a direct attempt to block transshipments to China. That was Malaysia trying to get ahead of exactly the kind of case Taiwan has just brought.
The reputation Malaysia is protecting

The stakes are bigger than one permit form. Malaysia has courted more than RM140 billion in data-centre and cloud investment, and Johor is now one of the fastest-growing data-centre markets in the region. That growth rests on Malaysia being seen as a trusted place to park sensitive computing, not a convenient back door. Every smuggling case that touches the region chips away at that trust, and every remote-access loophole invites tighter scrutiny from Washington on the very customers Malaysia wants to attract.
There is an awkward symmetry here too. Malaysia is spending heavily to design its own chips by 2030 while policing everyone else's, and the same surge in AI demand that is pricing local buyers out of graphics cards is what makes a smuggled server worth the risk in the first place.
For now, Malaysia's job is the unglamorous one: enforce the permit rule it wrote, show the remote-access route is watched, and keep its name out of the next indictment. The Taiwan case is a reminder of how fast a data-centre hub can turn into a smuggling headline.
Images courtesy of Tyler, Nazarizal Mohammad and Jason Leung on Unsplash.




