Taiwan has disclosed that government agencies were targeted in July by a new form of AI-assisted cyberattack in which hackers combined human operations with autonomous AI agents capable of chaining together multiple attack techniques, rapidly probing systems and using secondary infrastructure as stepping stones.
Taiwan’s Ministry of Digital Affairs said on August 13 that cybersecurity monitoring units detected abnormal activity against government agencies during July and began issuing alerts from July 20. Its investigation found clear signs that the attacks originated overseas and involved a hybrid approach combining hacker activity with AI agents, including OpenClaw. The affected government bodies have since completed remediation measures, according to the ministry.
The disclosure follows research from Israeli cybersecurity company Dream describing what it calls a near-autonomous cyber campaign against government infrastructure in Asia. Dream said the attack framework operated over roughly four days in early July, deployed as many as eight AI agents simultaneously, cracked 85 government credentials, extracted more than 2,500 personnel records and expanded reconnaissance towards a nuclear safety agency and at least seven energy-sector companies. Reuters and the Financial Times linked the affected infrastructure to Taiwan.
Taiwan’s government did not publicly attribute the operation to China. Its Ministry of Digital Affairs described the source only as overseas, while China’s Taiwan Affairs Office had not immediately responded to Reuters when the disclosure was published. Dream also stopped short of formally identifying a government sponsor, although its researchers said internal campaign documentation used Simplified Chinese while target-facing material used Traditional Chinese, pointing to a Chinese-language operator.
That distinction is important. The strongest confirmed conclusion at this stage is that Taiwan suffered an overseas AI-assisted cyber campaign. Claims linking the operation specifically to China remain attribution assessments rather than an official Taiwanese finding.
How did AI agents change the July cyberattack against Taiwanese government systems?
The most significant feature of the July campaign was not simply that hackers used an AI chatbot to generate code or research vulnerabilities. Dream’s reconstruction suggests AI agents were integrated into the operational machinery of the attack itself.
The framework was built around Hermes and OpenClaw agent systems and could deploy up to eight specialised sub-agents concurrently. Different agents were assigned tasks such as credential theft, application testing, vulnerability research and reconnaissance, allowing multiple attack paths to be pursued simultaneously rather than sequentially by a small human team.
Dream documented 12 attack waves between July 1 and July 4. The system produced 1,395 files during that period and continuously fed the results of each wave into subsequent operations. When one approach failed, the AI framework could research other vulnerabilities, reprioritise targets and attempt different techniques.
Taiwan’s Ministry of Digital Affairs independently described the attack as a hybrid operation combining human hackers with AI-agent assistance. It warned that agents can rapidly connect different attack methods, exploit backup or testing systems as entry points and give attackers advantages in speed, cost and scale.
That represents an important shift from conventional automation. Traditional hacking scripts generally perform predefined tasks repeatedly. Agentic AI systems can potentially decide which task should happen next based on what they discover during the intrusion.
What did Dream researchers say the attackers actually compromise and steal?
Dream said its researchers recovered an operational archive exceeding 160 megabytes that allowed them to reconstruct how the attack framework worked and what it achieved.
The campaign first mapped a government digital ecosystem by analysing publicly accessible web applications and their underlying code. From one starting point, the agents identified 21 connected government systems and mapped components of a national single sign-on architecture.
The attackers then found several weaknesses. Dream said some government web applications contained debugging endpoints that remained accessible in production, while another API accepted improperly signed authentication tokens. The system also harvested employee usernames and carried out automated password spraying against government accounts.
Dream said 85 accounts were compromised, and 84 of those credentials subsequently worked when tested against another internal system connected through single sign-on. That gave the attackers access to internal dashboards, equipment-management interfaces and personnel information.
The company said the framework ultimately extracted at least 2,564 personnel records, including employee names, departments and account identifiers. It also obtained internal technical information including database credentials, network addresses and details about government authentication infrastructure.
Reuters reported that Dream separately identified stolen personnel information from Taiwan’s justice ministry and reconnaissance against the island’s nuclear safety agency. Dream itself described expansion towards a nuclear safety body, government email infrastructure, IT suppliers and at least seven energy companies.
Why does the Taiwan attack look different from earlier AI-assisted hacking campaigns?
AI has already been used extensively by cybercriminals and state-linked groups for phishing messages, malware development, reconnaissance and translation. The Taiwan incident matters because the AI appears to have taken responsibility for much more of the operational workflow.
Dream described the campaign as near-autonomous rather than merely AI-assisted. Its reconstructed framework could determine which vulnerabilities deserved additional effort, allocate agents to several attack chains at once and conduct what it called learning cycles when initial techniques failed.
Those learning cycles searched vulnerability databases, GitHub repositories and security research for techniques applicable to the target environment. The system then incorporated promising approaches into later attack attempts.
The agents also appeared capable of correcting some of their own mistakes. Dream documented an instance in which the system initially classified a server delay as evidence of a successful database injection attack. Subsequent automated verification found that the delay actually came from an email-server timeout, and the framework discarded the original finding as a false positive.
That ability to test, reject and replace unsuccessful hypotheses is one reason the campaign has attracted attention. It suggests offensive AI systems are progressing from tools that accelerate human hackers towards systems capable of managing substantial portions of an intrusion independently.
Human operators still appear to have played an important role, and Taiwan itself explicitly described the operation as a hybrid human-and-AI attack. Calling the campaign completely autonomous would therefore go beyond what Taiwanese authorities have established publicly.
How did the attackers use OpenClaw and Hermes during the government intrusion?
OpenClaw and Hermes served as agentic frameworks rather than individual exploits.
Dream found workspace identifiers associated with both systems inside the recovered operational archive. The framework assigned lettered identities to individual agents and sent several agents out simultaneously with different missions.
Up to eight could operate during one wave. Across the wider campaign, Dream observed agents identified by letters from A through Q, although not all operated at the same time.
The significance is that attackers do not necessarily need to build every component of an AI hacking system from scratch. Open-source agent frameworks can provide planning, memory, tool use and task orchestration, while operators connect those capabilities to conventional cyber tools.
Dream said the attack framework even attempted to bypass model safety restrictions by framing malicious activity as authorised penetration testing.
For defenders, this creates a difficult asymmetry. A sophisticated offensive campaign once required several specialists coordinating reconnaissance, credential attacks, vulnerability research and exploitation. Agent systems could allow a much smaller number of operators to orchestrate those functions concurrently.
Why are Taiwan’s nuclear safety and energy systems particularly sensitive cyber targets?
Taiwan occupies an unusually sensitive geopolitical and technological position. It is a major global semiconductor centre and sits at the heart of longstanding tensions with China, which considers the democratically governed island part of its territory.
Taiwan says it faces sustained cyber pressure alongside military activity, disinformation and other forms of what Taipei describes as hybrid warfare. Reuters reported that cyberattacks against important Taiwanese infrastructure averaged about 2.63 million per day during 2025, up 6% from the previous year, according to Taiwan’s National Security Bureau. Some attacks were reported to coincide with Chinese military exercises around the island.
Against that background, reconnaissance involving a nuclear safety regulator and energy-sector companies carries consequences beyond ordinary data theft.
Power grids, energy suppliers and nuclear-safety systems can contain operational information that could become valuable during a military or political crisis even when hackers do not immediately disrupt those systems.
Cyber reconnaissance can also establish knowledge that remains useful months or years later. Attackers may map network architecture, identify suppliers, collect credentials or discover poorly protected systems without immediately exploiting their access for destructive purposes.
Dream said the July campaign expanded beyond the initial government targets towards IT suppliers, a nuclear safety agency, a government email system and at least seven energy-sector companies. Its report did not say those organisations all suffered successful destructive compromises, making it important to distinguish confirmed intrusion activity from scanning and attempted expansion.
Did Taiwan accuse China of carrying out the AI-agent cyberattack?
No.
Taiwan’s Ministry of Digital Affairs said its investigation identified clear characteristics of an overseas source but did not name China or another country.
Reuters likewise noted that Taiwan’s official statement did not attribute the July operation to Beijing and that China’s Taiwan Affairs Office had not immediately responded to a request for comment.
Dream’s researchers found linguistic indicators suggesting a Chinese-language operator. Internal reports contained Simplified Chinese while material relating to Taiwanese targets used Traditional Chinese. That is useful attribution evidence but does not independently prove sponsorship by the Chinese government.
The Financial Times reported the hackers as suspected China-linked actors, but that description should therefore remain qualified.
Cyber attribution can be particularly difficult because attackers can deliberately plant linguistic clues, route traffic through other countries and use widely available software. Reliable state attribution normally combines technical evidence with intelligence that private researchers may not possess.
Taiwan has repeatedly accused Chinese-linked hacking groups of targeting its government and critical infrastructure in other incidents, but that wider history does not automatically establish responsibility for this specific attack.
What has Taiwan changed after discovering the July AI-assisted cyber campaign?
Taiwan says the affected agencies have completed remediation and that the government has created new protective guidance specifically addressing AI-derived cyber threats.
The Ministry of Digital Affairs said agencies are strengthening system monitoring and sharing threat intelligence across government bodies. The goal is to identify suspicious activity earlier and block attacks before AI agents can move from initial access into interconnected systems.
Taiwan is also continuing to investigate whether other potential intrusion pathways exist based on technical indicators gathered during the July campaign.
One lesson from Dream’s report is that relatively ordinary security weaknesses remained crucial even in an unusually advanced AI attack.
The AI agents did not need to invent futuristic hacking techniques. They benefited from exposed debugging interfaces, weak authentication, predictable passwords, unauthenticated APIs and single sign-on relationships that allowed one compromised account to provide access elsewhere.
That means organisations do not necessarily need equally futuristic technology to stop every AI-powered attack. Strong identity controls, multifactor authentication, removal of exposed test systems, properly configured APIs, network segmentation and rapid patching can still eliminate many of the opportunities AI agents exploit.
What changes is the speed at which attackers can search for those mistakes.
Could AI agents allow smaller hacking groups to conduct operations previously requiring large teams?
Potentially, and that may be the most important strategic implication of the Taiwan incident.
A conventional sophisticated cyber campaign requires personnel to perform reconnaissance, vulnerability research, credential attacks, exploitation, lateral movement and data analysis. Those activities impose labour costs that historically limited how many organisations could be targeted intensively at the same time.
AI agents can reduce that constraint by performing several functions in parallel.
Dream’s reconstruction showed as many as eight agents operating simultaneously and producing a large quantity of operational material within four days. The company concluded that the cost of conducting competent cyber operations was falling much faster than the cost of defending against them.
That does not mean an inexperienced attacker can simply launch an AI program and compromise a national government. Dream itself stressed that building an effective system still required sophisticated orchestration, coordination and attack logic.
The more realistic risk is leverage. Skilled operators who previously managed a handful of simultaneous attack paths may increasingly be able to supervise dozens, while AI systems handle repetitive research and testing.
For governments defending thousands of websites, servers and contractor networks, that changes the economics of cybersecurity.
What are the key takeaways from Taiwan’s disclosure of an overseas AI-agent cyberattack on government agencies?
- Taiwan’s Ministry of Digital Affairs confirmed on August 13 that government agencies were targeted during July by overseas hackers using a hybrid approach combining human operations with AI agents including OpenClaw.
- Taiwan began issuing cybersecurity warnings from July 20 and says the affected agencies have completed remediation, while government monitoring and cross-agency intelligence sharing have been strengthened.
- Cybersecurity company Dream separately reconstructed a near-autonomous campaign lasting roughly four days in early July that used Hermes and OpenClaw frameworks and deployed as many as eight AI agents simultaneously.
- Dream says the framework cracked 85 government credentials, extracted at least 2,564 personnel records and mapped 21 connected government systems while exploiting authentication and API weaknesses.
- The attackers expanded reconnaissance towards a nuclear safety agency, government email infrastructure, technology suppliers and at least seven energy-sector companies, although Dream did not say every target was successfully compromised.
- Taiwan has not officially blamed China for this specific attack. Dream identified linguistic evidence pointing to a Chinese-language operator, while the Financial Times described the attackers as suspected China-linked hackers.
- The campaign is significant because its AI agents could pursue several attack paths, research new vulnerabilities, reprioritise targets and reject some false findings without requiring constant human direction.
- The incident suggests AI may reduce the manpower required for sophisticated cyber operations, increasing pressure on governments to automate monitoring and close routine security weaknesses before autonomous systems can exploit them at scale.
Why Taiwan’s July attack could mark a bigger cybersecurity shift than another government data breach
The most consequential element of Taiwan’s disclosure is not the number of stolen credentials or personnel records. Governments have suffered larger conventional cyber breaches before. What makes this incident important is the possibility that the economics and tempo of sophisticated hacking are beginning to change.
Dream’s reconstruction depicts a system that could operate several agents at once, evaluate competing attack paths, search for new techniques when blocked and feed discoveries from one stage into the next. Taiwan’s own investigation independently confirms that hackers combined human operators with AI-agent tools and warns that these systems can make attacks faster, cheaper and easier to scale.
The incident also demonstrates that advanced AI does not eliminate the importance of basic cybersecurity. Many of the successful attack paths described by Dream depended on familiar problems such as weak passwords, exposed development interfaces, poorly configured authentication and APIs that revealed information without adequate controls. AI made those weaknesses easier to discover and exploit rapidly rather than creating them.
For Taiwan, the geopolitical context makes that acceleration especially important. The island already operates under sustained military, political, information and cyber pressure. A technology that allows attackers to scan government agencies, suppliers and infrastructure simultaneously could become particularly dangerous during a crisis, when defenders are already dealing with disinformation, military movements and attempts to disrupt communications.
Attribution nevertheless needs to remain precise. Taiwan has not said China carried out the July attack, and the evidence disclosed publicly does not justify presenting Chinese state responsibility as established fact. The Chinese-language indicators described by Dream and the wider history of China-linked operations against Taiwan make attribution an important line of investigation, but not a settled conclusion.
The broader cybersecurity warning does not depend on resolving that question. AI agents capable of coordinating reconnaissance, credential attacks, vulnerability research and lateral movement are now being observed in real-world intrusions against government infrastructure. The operational barrier between an AI assistant helping a hacker and an AI system actively managing parts of the attack is becoming increasingly thin.
Taiwan’s July campaign may therefore be remembered less for the specific records that were stolen than for what it demonstrated. Cyber defenders are beginning to confront attackers that can operate with machine speed while retaining enough adaptive decision-making to change tactics when blocked. The security race is moving from human hackers using AI towards humans supervising teams of digital hacking agents, and governments will have to adjust their defensive systems accordingly.
Discover more from Business-News-Today.com
Subscribe to get the latest posts sent to your email.