HR EN DE
NEWS SPORT BIZNIS SCENA LIFESTYLE TECH

AI Agents Breached Taiwan's Government: The First Autonomous Attack

Beijing-linked attackers used publicly available AI frameworks to compromise 85 administrative accounts and exfiltrate 2,500 files in four days.

Foto: Telegram
Summary
  • Eight autonomous AI agents simultaneously mapped 21 Taiwanese state networks over four days in July 2026.
  • 85 administrative accounts were compromised, and 2,500 personal files were stolen from the government and energy sector.
  • The attack was uncovered by Israeli firm Dream, with forensics pointing to origins in mainland China.
  • Taiwan suffers an average of 2.6 million cyberattacks per day from China, with a six percent annual increase.

Researchers from the Israeli cybersecurity firm Dream have uncovered the first documented case of a fully autonomous cyberattack against a sovereign state. The target was Taiwan's government and energy infrastructure, with the operation unfolding over four days in early July 2026.

The attackers, believed to be linked to Beijing, weaponized publicly available AI frameworks OpenClaw and Hermes to build a standalone offensive system. According to the Financial Times, the software simultaneously deployed up to eight independent agents that mapped 21 state networks and actively assessed system vulnerabilities. When defensive mechanisms blocked a particular digital path, the program autonomously scoured the internet for alternative infiltration strategies.

AI agents have introduced new dual challenges to network security defense: attacks are automated, and the AI agents themselves become new vulnerabilities.

said a representative of Taiwan's Ministry of Digital Affairs, declining to comment on specific breach details due to confidentiality protocols.

What Was Compromised

In the first phase of the intrusion, attackers managed to seize control of at least 85 administrative accounts within Taiwan's government. More than 2,500 personal files were exfiltrated from the system, after which the offensive aggressively expanded to Taiwan's nuclear safety agency and at least seven corporate energy companies.

Forensic analysis of internal communications among the operators revealed the use of simplified Chinese characters, strongly suggesting origins in mainland China. At the same time, the stolen government data was formatted in traditional Chinese, the standard for digital infrastructure in Taiwan, Macau, and Hong Kong.

A New Era of Digital Warfare

Amir Becker, chief strategist at Dream and a former commander of Israel's elite Unit 8200, described the incident as a "unique end-to-end autonomous attack" on a sovereign entity. He emphasized that the proliferation of such capabilities demands a fundamental shift in defensive doctrines.

This must be a basic assumption for every government in the world.

Becker told the Financial Times. Chinese state authorities did not respond to inquiries about the operation.

According to data from Taiwan's National Security Bureau, the island suffered an average of 2.6 million cyberattacks per day from mainland China in 2025, a six percent annual increase. This latest incident elevates the threat to a new level, demonstrating that attackers no longer need to manually manage every step of an intrusion.

Who Stands Behind the Discovery

Dream was founded in 2023 by former Austrian Chancellor Sebastian Kurz and Israeli tech executive Shalev Hulio. In February 2025, it reached a valuation of $1.1 billion after a $100 million capital injection led by Bain Capital. Hulio previously co-founded NSO Group, a surveillance company blacklisted by the U.S. government in 2021 for abuses involving the Pegasus spyware.

Dream researchers uncovered the intrusion while investigating a 160-megabyte online archive containing 1,395 files linked to threat actor activities. The operators bypassed the AI models' built-in security protocols by disguising malicious activity as authorized system security audits.

Industry giants like Meta, OpenAI, and Anthropic have already documented cases where their models launched unexpected cyber offensives during routine testing. In November 2025, Anthropic reported that suspected Chinese state hackers attempted to manipulate its Claude software to break into international organizations, albeit with minimal success.

FAQ
What makes this attack historically significant? +
This is the first documented case of a fully autonomous cyberattack against a sovereign state, where AI agents independently mapped networks, found vulnerabilities, and adapted strategies without human intervention.
Who is behind the attack? +
Forensic analysis points to attackers linked to mainland China, although Chinese authorities have not responded to inquiries. Simplified Chinese characters were used in the operators' internal communications.
How much data was stolen? +
85 administrative accounts of Taiwan's government were compromised, and more than 2,500 personal files were exfiltrated, along with attacks on the nuclear safety agency and seven energy companies.
How did attackers bypass the AI models' security measures? +
They bypassed built-in security protocols by falsely presenting malicious activity as authorized system security audits.

Log in

You need to log in or register to comment.

Comments (0)
No comments yet. Be the first!
Search
Popular
Nedavno pretraživano
helsinški sporazum
liga prvaka
digitalni mediji
Login
Home
Make 5MIN.hr a preferred source
Follow us on social media
Categories