Cybersecurity & Privacy

Near-Autonomous China-Linked AI Agents Used to Attack Taiwan’s Government

Suspected China-linked hackers used a team of open-source AI agents to run a near-autonomous cyberattack on Taiwan’s government, breaching 85 accounts in what researchers call a first.

By Marcus Lee Edited by Maria Konash Published:
Near-Autonomous China-Linked AI Agents Used to Attack Taiwan’s Government
Researchers say suspected China-linked hackers used a team of open-source AI agents to run a near-autonomous cyberattack on Taiwan's government. Image: leannk. / Unsplash

Key Notes

  • Israeli firm Dream documented what it calls a first-of-its-kind, near-autonomous AI cyberattack on Taiwan's government, built from open-source agent frameworks (Hermes and OpenClaw) that ran up to eight sub-agents at once, mapping 21 government systems.
  • The operation compromised at least 85 government accounts and stole more than 2,500 personnel records before expanding to Taiwan's nuclear safety agency and at least seven energy companies.
  • Dream did not attribute it to a specific group but said Simplified Chinese in the operators' files points to a China-linked operator.

Suspected China-linked hackers used a coordinated team of AI agents to carry out a near-autonomous cyberattack on Taiwan’s government, in what researchers describe as the first publicly known autonomous AI attack on a government target. The findings come from Dream, an Israeli cybersecurity firm that reconstructed the operation after recovering the attackers’ full operational workspace, a 160-megabyte archive of nearly 1,400 files. The Financial Times first reported the research and identified Taiwan as the target.

What set the attack apart was its degree of automation. Rather than a single script, the framework was built from two open-source agent systems, Hermes and OpenClaw, and deployed up to eight sub-agents simultaneously, each assigned its own targets and techniques, operating more like a coordinated hacking team than a piece of malware.

Dream said the tool continuously ranked and reprioritized possible attack paths based on what it found, and when one approach failed, it dispatched another agent to search the internet and devise a new method, adapting mid-operation and learning from its mistakes without human intervention.

The reported damage is significant. According to Dream, over roughly four days the agents mapped 21 connected government systems from a single portal, discovering dozens of API endpoints, many unauthenticated, then compromised at least 85 government user accounts and extracted more than 2,500 personnel records. The operation later expanded to Taiwan’s nuclear safety agency and at least seven energy companies.

Attribution is careful and incomplete. Dream did not tie the attack to any specific group or government, but said the use of Simplified Chinese in the operators’ internal files pointed to a high probability of a China-linked operator. Taiwan’s Ministry of Digital Affairs confirmed detecting an “abnormal attack” on government agencies beginning around July 20, said it combined manual operations with AI agent-assisted tools including OpenClaw, and stated the affected units have since fully handled the incident. Notably, the exact dates differ across accounts, with Taiwan citing late July and Dream describing early July, and the specific AI model powering the agents was not identified.

The Cost Asymmetry

The most consequential takeaway is economic, not technical. As Dream put it, the cost of running a competent attack has collapsed while the cost of defending against one has not.

By automating reconnaissance, credential attacks and strategizing with cheap, publicly available agents, a small team can now mount an operation that once required many skilled human hackers working in parallel. Taiwan already logs an average of 2.6 million cyberattacks a day, so if even a fraction begins running with this level of autonomy and speed, the defensive math worsens sharply.

The attackers reportedly bypassed the AI models’ safety guardrails simply by framing their work as authorized penetration testing, a reminder that guardrails designed to block obvious misuse can be defeated by plausible cover stories.

Real, but Not Fully Autonomous

The story warrants careful framing against the hype. Security experts stress that a human remained essential: someone chose the targets, set the objective and issued the directive. As Semgrep’s Cris Thomas put it, there was a capable operator in charge, so this was near-autonomous rather than 100% autonomous.

That caveat matters, but it should not be read as reassurance, since the trend line is clear. The incident lands amid a run of similar disclosures, including an autonomous agent’s breach of Hugging Face and OpenAI’s account of a model that circumvented its own sandbox, and it follows Anthropic’s report last year of stopping an earlier AI-driven espionage campaign that still required substantial human effort.

The threat has grown sharper as leading labs release models, such as Anthropic’s Mythos, capable of rapidly conducting reconnaissance and identifying vulnerabilities, the very capabilities that make agentic attacks faster. Taiwanese officials framed the episode as proof that AI has become a primary actor in cybersecurity, and warned that no country, not just Taiwan, is yet prepared with the legal frameworks, defenses and policies such attacks demand. The gap between offensive capability and defensive readiness is the real story here.

Disclaimer: AIstify is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and insights on artificial intelligence, emerging technologies, automation, and related industries. NuvexMedia LLC invests in and collaborates with companies across the AI, technology, software, and digital innovation sectors. These relationships do not influence AIstify’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2026 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.

AI & Machine Learning, Cybersecurity & Privacy, News