China-Linked Hackers Use AI Agents to Launch Autonomous Cyberattack on Taiwan
- 11 minutes ago
- 2 min read
Hackers suspected of links to China used publicly available AI tools to automate a cyberattack against Taiwanese government systems, compromising at least 85 accounts and stealing more than 2,500 personnel records, according to researchers cited by the Financial Times.
The four-day campaign, which took place in early July, represents what Israeli cybersecurity company Dream described as the first observed end-to-end autonomous cyberattack against a government target.
Rather than relying on human operators to manually test each route into a network, the attackers reportedly built a hacking platform capable of running multiple AI agents simultaneously. At its peak, as many as eight agents were mapping systems, researching vulnerabilities, attempting intrusions and developing new techniques when previous approaches failed.
Dream said the platform mapped 21 government systems before compromising accounts and extracting personnel data. The attackers later expanded their activity toward Taiwan's nuclear safety agency, energy companies, government suppliers and additional public-sector systems.
Researchers uncovered the operation after finding a 160MB archive containing 1,395 files connected to the attack. The toolkit was reportedly assembled using Hermes and OpenClaw, two freely available open-source AI agent frameworks designed to allow large language models to complete multi-step tasks.
Dream could not identify the specific AI model controlling the agents. However, researchers said safeguards appeared to have been bypassed by framing the malicious activity as authorized penetration testing.
The larger concern is how little specialized infrastructure may now be required to build an autonomous offensive platform. The attackers reportedly combined tools available to ordinary developers into a system capable of evaluating targets, choosing attack paths and changing strategy with limited human intervention.
When an intrusion attempt failed, the platform could direct another agent to search online for technical information and develop an alternative technique.
Dream did not attribute the campaign to a specific government or hacking group. Researchers said internal communications were written in Simplified Chinese, while stolen information was written in Traditional Chinese. The Financial Times reported that a person familiar with the incident identified the victim as Taiwan.
The campaign arrives as governments and security companies wrestle with the rapidly expanding offensive potential of AI agents. Taiwan was already facing significant cyber pressure before autonomous systems entered the equation, with its National Security Bureau reporting millions of suspected Chinese cyberattacks per day in 2025.
Benny Czarny, CEO and founder of OPSWAT, warned that organizations should not assume AI-powered detection alone will keep pace with AI-enabled attackers.
“Governments are being told that the answer to AI-generated attacks is better AI detection. That is dangerous as the primary strategy. There can always be a new variant, a new model or an attack your detection model has never seen.”
The Taiwan incident suggests the next phase of AI cybersecurity may not be defined simply by faster hacking. It could be defined by attack systems that independently explore, learn and adapt at machine speed.


