Ads_970x250

AI Agents Used in Near-Autonomous Cyberattack on Taiwan Government

Researchers reconstruct a four-day campaign in which up to eight AI agents mapped government systems, stole credentials and expanded reconnaissance into nuclear safety and energy targets.

Topics

  • Suspected China-linked hackers used a network of artificial intelligence agents to carry out a largely automated intrusion into Taiwanese government systems, in an attack that shows how AI is beginning to move beyond assisting cyber operators toward executing substantial parts of an intrusion itself.

    Israeli cybersecurity firm Dream said the operation ran from July 1 to July 4 and involved as many as eight AI agents working simultaneously across 12 attack waves. 

    Dream said the agents mapped 21 connected government systems, identified software weaknesses and altered their tactics when initial approaches failed.

    The attackers compromised 85 government accounts and extracted more than 2,500 personnel records, according to the research. The operation later expanded its reconnaissance to Taiwan’s nuclear safety agency, government technology suppliers and at least seven energy companies.

    Dream reconstructed the operation from a 160 MB archive containing 1,395 files. The company publicly described the target only as government entities in Asia, but the Financial Times and The Register identified Taiwan as the victim.

    Taiwan’s digital ministry subsequently confirmed that government agencies were targeted in July by an overseas campaign combining manual operations with AI agents.

    Researchers did not attribute the operation to the Chinese government or a specific hacking group. They said operational messages were written in simplified Chinese, while stolen data used traditional Chinese, providing one indication of a mainland-linked operator.

    The attack framework combined publicly available Hermes and OpenClaw agents. Dream said the agents first extracted URLs, authentication configurations and API endpoints from a government portal before identifying weaknesses across connected services.

    Among them were unauthenticated APIs exposing employee information and endpoints that could create authenticated sessions without valid credentials. The agents then used harvested usernames and predictable password patterns to compromise accounts, Dream said.

    The breach also exposed database credentials, single-sign-on secrets and internal network information, allowing the operation to move beyond its initial target.

    Dream Chief Strategy Officer Amir Becker told the Financial Times he had not previously seen a government attack conducted with this level of automation.

    Topics

    More Like This

    You must to post a comment.

    First time here? : Comment on articles and get access to many more articles.