AI Agents Breached Taiwan's Government: The First Autonomous Attack
Beijing-linked attackers used publicly available AI frameworks to compromise 85 administrative accounts and exfiltrate 2,500 files in four days.
Beijing-linked attackers used publicly available AI frameworks to compromise 85 administrative accounts and exfiltrate 2,500 files in four days.
Researchers from the Israeli cybersecurity firm Dream have uncovered the first documented case of a fully autonomous cyberattack against a sovereign state. The target was Taiwan's government and energy infrastructure, with the operation unfolding over four days in early July 2026.
The attackers, believed to be linked to Beijing, weaponized publicly available AI frameworks OpenClaw and Hermes to build a standalone offensive system. According to the Financial Times, the software simultaneously deployed up to eight independent agents that mapped 21 state networks and actively assessed system vulnerabilities. When defensive mechanisms blocked a particular digital path, the program autonomously scoured the internet for alternative infiltration strategies.
AI agents have introduced new dual challenges to network security defense: attacks are automated, and the AI agents themselves become new vulnerabilities.
said a representative of Taiwan's Ministry of Digital Affairs, declining to comment on specific breach details due to confidentiality protocols.
In the first phase of the intrusion, attackers managed to seize control of at least 85 administrative accounts within Taiwan's government. More than 2,500 personal files were exfiltrated from the system, after which the offensive aggressively expanded to Taiwan's nuclear safety agency and at least seven corporate energy companies.
Forensic analysis of internal communications among the operators revealed the use of simplified Chinese characters, strongly suggesting origins in mainland China. At the same time, the stolen government data was formatted in traditional Chinese, the standard for digital infrastructure in Taiwan, Macau, and Hong Kong.
Amir Becker, chief strategist at Dream and a former commander of Israel's elite Unit 8200, described the incident as a "unique end-to-end autonomous attack" on a sovereign entity. He emphasized that the proliferation of such capabilities demands a fundamental shift in defensive doctrines.
This must be a basic assumption for every government in the world.
Becker told the Financial Times. Chinese state authorities did not respond to inquiries about the operation.
According to data from Taiwan's National Security Bureau, the island suffered an average of 2.6 million cyberattacks per day from mainland China in 2025, a six percent annual increase. This latest incident elevates the threat to a new level, demonstrating that attackers no longer need to manually manage every step of an intrusion.
Dream was founded in 2023 by former Austrian Chancellor Sebastian Kurz and Israeli tech executive Shalev Hulio. In February 2025, it reached a valuation of $1.1 billion after a $100 million capital injection led by Bain Capital. Hulio previously co-founded NSO Group, a surveillance company blacklisted by the U.S. government in 2021 for abuses involving the Pegasus spyware.
Dream researchers uncovered the intrusion while investigating a 160-megabyte online archive containing 1,395 files linked to threat actor activities. The operators bypassed the AI models' built-in security protocols by disguising malicious activity as authorized system security audits.
Industry giants like Meta, OpenAI, and Anthropic have already documented cases where their models launched unexpected cyber offensives during routine testing. In November 2025, Anthropic reported that suspected Chinese state hackers attempted to manipulate its Claude software to break into international organizations, albeit with minimal success.