Inside the Taiwan autonomous AI cyberattack: How open-source agents bypassed security controls to extract government personnel data.
Hackers used an AI system to launch sophisticated cyberattacks against Taiwan, in what cybersecurity experts believe is the first fully autonomous attack targeting government agencies.
Over four days in July, the AI agents mapped 21 government systems, compromised 85 user accounts and extracted 2,500 personnel records, according to Israeli AI firm Dream, which first discovered the breach.
Although researchers suspect Chinese involvement based on internal data clues, neither Taiwan’s government nor Dream officially confirmed the origin of the July attack.
In a Thursday statement, Taiwan’s Ministry of Digital Affairs confirmed that the attacks originated overseas, employing a hybrid strategy that paired conventional hacking with AI agents like OpenClaw.
The attackers built their system around open-source AI frameworks to automate and coordinate key stages of the breach including initial reconnaissance, credential harvesting and mapping out lateral attack paths, according to Dream. The Financial Times first broke the story on Wednesday.
The incident comes amid growing reports of advanced AI models acting without human authorization, heightening fears over AI-driven cyber threats and spurring calls for stricter government oversight.
Kenny Huang, chairman of the Taiwan Network Information Center, noted that this is believed to be the first publicly disclosed case of a fully automated AI attack targeting a government.
While using AI for coding assistance and vulnerability scanning has become commonplace in cyberattacks, this incident represented a major shift moving from human-led assistance to operational autonomy.
Instead of merely assisting human operators, an autonomous system coordinated up to eight AI agents to execute the intrusion and decide subsequent moves without human intervention effectively running the entire hacking campaign.
“It spells out one thing loudly,” cybersecurity firm Dream noted in a blog post “the cost of running a competent attack has collapsed but the cost of defending against one has not.”
Amir Becker, Dream’s chief business and strategy officer, noted that the AI system’s level of operational autonomy in this latest attack was deeply alarming.
“Like a human team, when an approach gets blocked, it researches new techniques in real time and adapts” Becker said. “It’s an attacker that strategizes, learns, and adjusts on its own.”
The attack also targeted Taiwan’s nuclear safety agency, government IT vendors and at least seven companies across the energy sector.
The AI agents rapidly combined hacking techniques and exploited secondary system vulnerabilities, enabling faster, cheaper and far larger-scale attacks, according to Taiwan’s Ministry of Digital Affairs.
The use of simplified Chinese characters in internal files linked to the operation strongly suggests the attackers whether state-sponsored or private are connected to China, according to cybersecurity experts.
In response to an inquiry, a spokesperson for China’s Ministry of Foreign Affairs stated the ministry was unfamiliar with the situation. Requests for comment sent to China’s Taiwan Affairs Office and Cyberspace Administration were not immediately answered.
Cyberattacks are a persistent threat for Taiwan, which faces continuous digital pressure from China as Beijing asserts its claim over the island. A government report revealed that Taiwan absorbed an average of 2.6 million Chinese cyberattacks daily last year a 6% increase from 2024.
As Beijing intensifies pressure on Taipei, Taiwanese officials warn that their democracy sits on the frontline of China’s “hybrid warfare” facing continuous cyberattacks, disinformation campaigns, and near-daily military drills.
See also: Google Launches Gemini 3.7 Flash to Power Coding and Business Workflows
According to Kenny Huang, chairman of the Taiwan Network Information Center, the July incident proves that AI has evolved from an assistant handling routine automation tasks into a central player in modern cyberattacks.
The incident raises fundamental questions about whether global defense strategies including legal frameworks, technical capabilities, and policy oversight are prepared to counter autonomous AI threats.
“I believe there are still significant gaps,” Huang said. “Every country not just Taiwan, remains unprepared in this respect.”





