A four-day breach exposed how quickly autonomous systems can probe defenses, change tactics and reach sensitive government networks without constant human direction.

A cyberattack on Taiwan’s government institutions became one of the first publicly known cases in which autonomous artificial intelligence agents did not merely assist hackers but independently carried out a significant part of the operation. Experts believe the incident may mark a new stage in the evolution of cyber threats targeting governments and critical infrastructure.

The incident was discovered by Israeli AI company Dream. According to its data, over four days in July, AI agents scanned 21 Taiwanese government systems, compromised 85 government employee accounts, and accessed 2,500 records containing personal data.

The source of the attack has not been officially identified. However, experts believe there may be a connection to China: simplified Chinese was found in internal documents related to the breach. Taiwan’s Ministry of Digital Affairs stated that technical indicators point to the operation having originated abroad.

The investigation found clear signs that the attacks originated overseas and involved a hybrid approach, with hackers combining conventional operations with AI agents such as OpenClaw.

– Taiwan’s Ministry of Digital Affairs

How AI agents managed the cyberattack on Taiwan

According to Dream’s assessment, the attackers used open AI agents to coordinate and automate the intrusion. The system conducted reconnaissance of the digital infrastructure, attempted to obtain credentials, identified possible routes for further penetration, and changed tactics without constant instructions from an operator.

The autonomous platform could coordinate up to eight AI agents simultaneously. This sets it apart from the usual use of artificial intelligence in cybercrime, where AI is primarily used to write code, create phishing messages, or identify potential vulnerabilities. In this case, the system effectively managed the course of the entire hacking campaign.

This makes one thing abundantly clear: the cost of carrying out a sophisticated attack has dropped sharply, but the cost of defending against it has not.

– Dream

Amir Becker of Dream explained that the AI system behaved similarly to a team of experienced specialists. If one method lost effectiveness or was blocked by defenses, the agents searched for alternatives, tested new techniques, and adjusted their strategy in real time.

Like a human team, when one approach is blocked, it explores new techniques in real time and adapts. This is an attacker that develops its own strategy, learns, and adjusts its actions independently.

– Amir Becker

Which systems were at risk

The attack affected government institutions and companies connected to Taiwan’s vital infrastructure. The targets included:

Taiwan’s nuclear safety agency;
IT suppliers serving government institutions;
at least seven energy-sector companies.

Taiwan’s Ministry of Digital Affairs noted that the AI agents rapidly combined different hacking methods and exploited vulnerabilities in secondary systems. This approach could make cyber operations faster, cheaper, and far more scalable than traditional attacks, which require the constant involvement of a large team.

Are autonomous AI attacks becoming the new reality?

Kenny Huang of the Taiwan Network Information Center called the July incident the first publicly disclosed example of a fully automated attack against government systems. In his view, artificial intelligence is already moving from the role of an auxiliary tool to that of an active participant in cyber operations.

Taiwan regularly faces cyberattacks, including those originating from China. A government report indicates that last year the country recorded an average of 2.6 million cyberattacks per day from China. This was 6% more than in 2024.

The case involving autonomous AI agents raises urgent questions about governments’ readiness for a new type of threat. Protection is needed not only for core government networks, but also for less visible systems operated by contractors, suppliers, and critical infrastructure facilities. If autonomous systems continue to independently identify weak points and adapt to defenses, cybersecurity could become one of the main arenas of future confrontation between states.