In a significant escalation of cyber warfare tactics, attackers linked to China have executed a fully autonomous cyberattack on Taiwanese government websites and critical infrastructure. This operation, identified by Israeli AI and cyber defense firm Dream, marks the first known instance of an AI-driven intrusion operating with the coordination and adaptability traditionally associated with human hacking teams.
The attackers utilized open-source artificial intelligence tools, specifically AI agent frameworks known as Hermes and OpenClaw, to construct an autonomous hacking platform. Over a four-day period in early July, this system deployed up to eight agents simultaneously. These agents systematically mapped 21 government systems, identified vulnerabilities, adapted their strategies when encountering obstacles, and navigated through networks with minimal human intervention.
The breach resulted in the compromise of at least 85 government accounts and the extraction of over 2,500 personnel records. The attackers extended their reach to Taiwan’s nuclear safety agency and at least seven energy companies, highlighting the operation’s broad scope and strategic targeting.
Dream researchers uncovered evidence of this campaign through a 160MB online archive containing 1,395 files, inadvertently exposed during routine threat-tracking activities. Analysis of the archive revealed that the AI agents continuously evaluated and reprioritized attack paths. When one approach failed, another agent was tasked with gathering new intelligence and devising alternative strategies, enabling the operation to progress without constant human oversight.
Notably, the attackers circumvented safeguards within the AI models by framing their activities as authorized penetration tests. This prompt-engineering technique allowed the agents to interpret destructive actions as legitimate security research. The specific large language model powering the agents remains unidentified.
Internal communications associated with the operation were conducted in Simplified Chinese, while data extracted from the targets appeared in Traditional Chinese, commonly used on government sites in Taiwan, Hong Kong, and Macau. Although Dream has not formally attributed the campaign to a specific group, a source familiar with the matter identified Taiwan as the target.
Amir Becker, Dream’s chief strategy officer and a former head of cyber operations at Israel’s Unit 8200, described the incident as an unprecedented “end-to-end autonomous attack” on a government entity. He emphasized that the system operated with the coordination of a cyber team rather than a single automated script.
This breach underscores the evolving landscape of cyber threats, where readily available open-source AI agents lower the barrier to executing sophisticated, large-scale operations. Tasks that once required teams of skilled operators can now be orchestrated by software capable of mapping networks, stealing credentials, identifying vulnerabilities, and adapting in real time.
In response, defenders are racing to develop comparable AI systems capable of detecting and mitigating such autonomous campaigns before they inflict significant damage. The incident serves as a stark reminder of the dual-use nature of AI technologies and the pressing need for robust cybersecurity measures to counteract emerging threats.