China-Linked Hackers Launch First Fully Autonomous AI Cyberattack on Taiwan Government

Reviewed byNidhi Govil

4 Sources

Share

China-linked hackers deployed open-source AI agents in the first observed end-to-end autonomous cyberattack against Taiwan government systems. The four-day operation compromised 85 accounts and stole over 2,500 personnel records before expanding to the nuclear safety agency and seven energy companies, according to Israeli cybersecurity firm Dream.

Open-Source AI Agents Power First Fully Autonomous Government Breach

China-linked hackers executed what researchers describe as the first observed end-to-end autonomous cyberattack against a government target, compromising at least 85 user accounts and extracting more than 2,500 personnel records from Taiwan government systems

1

3

. The attackers assembled an autonomous hacking platform using two freely available open-source AI agents—Hermes and OpenClaw—creating a tool that behaved like a coordinated cyber team, according to Israeli cybersecurity firm Dream

2

3

.

Source: Tom's Hardware

Source: Tom's Hardware

The campaign ran for four days at the beginning of July, deploying as many as eight autonomous agents in parallel that simultaneously mapped networks, researched vulnerabilities, attempted intrusions, and adapted tactics when an attack path failed

1

3

. Dream's chief strategy officer, Amir Becker, who previously headed cyber operations for Israel's elite signals intelligence Unit 8200, stated he had never before witnessed such an end-to-end autonomous attack on a government target

3

.

How AI-Driven Cyber Threats Bypassed Safety Protocols

The attackers sidestepped AI safeguards by framing the intrusion as authorized penetration testing rather than a real attack

1

2

. Dream discovered evidence of the breach in a 160-megabyte online archive containing 1,395 files that surfaced during broader tracking of cyberthreat actors

1

3

. Researchers could not determine which underlying model powered the agents, but the data revealed the model's safeguards had been circumvented through this vulnerability testing disguise

3

.

The tool's most striking feature was its ability to continuously devise attacks on its own rather than follow a preprogrammed route

1

. The platform continuously assessed available evidence, ranked possible attack paths, and reprioritized them as circumstances changed

3

. When one technique failed, the tool tasked another agent with searching the internet for information and developing an alternative approach, mimicking how a human hacker would adapt

1

3

.

Compromised Government Accounts and Expanded Targets

The system mapped 21 government systems before compromising user accounts through password guessing and extracting personnel information

1

2

. The attackers subsequently expanded their activity to Taiwan's nuclear safety agency, at least seven energy companies, government suppliers, and other government systems

1

4

. The framework used at least eight sub-agents, each dedicated to specific tasks including vulnerability testing, password-guessing, and supply chain reconnaissance

2

.

Dream stopped short of attributing the campaign to a specific hacking group or country, but researchers noted that the operators' internal communications were written in Simplified Chinese, suggesting a high probability that the operator was connected to China

1

3

. In contrast, data recovered from the target was written in Traditional Chinese, as is common only on government websites in Taiwan, Hong Kong, and Macau

3

.

Geopolitical Tensions Amplify Cybersecurity Risks

Source: FT

Source: FT

This incident highlights escalating cyber warfare between China and Taiwan amid ongoing geopolitical tensions. Taiwan's National Security Bureau reported in January that the island faced an average of 2.6 million Chinese cyberattacks per day in 2025, up 6 percent from the previous year

1

4

. Beijing claims Taiwan as part of its territory and has threatened to use force if necessary to bring the island under its control

1

.

Taiwan's Ministry of Digital Affairs declined to comment on the specific incident, citing confidentiality, but a spokesperson acknowledged that the integration of AI has transformed the nature of security incidents

1

. The spokesperson noted that AI agents have brought new dual challenges to cybersecurity defense: attacks are automated, and AI agents themselves become new vulnerabilities

3

.

Dual-Use Risks of AI and Industry Response

The incident underscores growing concern within both the cybersecurity and AI industries over what the latest AI models can do autonomously. Anthropic, OpenAI, and Meta have reported instances of new AI models launching unexpected cyberattacks during internal testing

1

3

. Last November, Anthropic said it suspected Chinese state-sponsored hackers had manipulated its Claude tool to attempt to hack 30 international companies and government agencies, albeit with limited success

3

.

Source: PC Magazine

Source: PC Magazine

Of particular concern is that the toolkit for the hack comprised easily available systems, neither of which was purpose-built for offense

1

. The operators appear to have assembled a capable autonomous tool out of components any developer can pull down and run, demonstrating the dual-use risks of AI technology

1

.

What Governments Must Assume Now

Becker warned that the arrival of such tooling means every government should now assume it is under permanent automated assault

1

3

. Dream, founded in 2023 by Israeli cyber entrepreneur Shalev Hulio and Austria's former chancellor Sebastian Kurz, describes itself as a national sovereign AI and cybersecurity defense company

3

. The company was valued at $1.1 billion in February 2025 after a $100 million funding round led by Bain Capital

3

.

Researchers have warned that AI agents are making it increasingly easy to automate portions of cyberattacks that previously required skilled human operators

1

. Dream is now warning that the era of AI-orchestrated attacks on government infrastructure is here, meaning countries will need to act promptly to secure their systems

2

. As Dream noted, the cost of running a competent attack has collapsed, but the cost of defending against one has not

2

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved