{"id":137712,"date":"2026-08-12T19:14:11","date_gmt":"2026-08-12T19:14:11","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/137712\/"},"modified":"2026-08-12T19:14:11","modified_gmt":"2026-08-12T19:14:11","slug":"china-linked-hackers-use-ai-agents-in-autonomous-attack-on-taiwan","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/137712\/","title":{"rendered":"China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan"},"content":{"rendered":"<p>\n\t\t\t\t\t\t\tChina-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan\n\t\t\t\t\t\t<\/p>\n<p>\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/user-icon.svg\" alt=\"\"\/> <a href=\"https:\/\/securityaffairs.com\/author\/paganinip\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi Paganini<\/a><br \/>\n\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> August 12, 2026<\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/Chinese-hackers-espionage.jpg\" alt=\"\"\/><\/p>\n<p>China-linked hackers reportedly used eight AI agents to breach a government network, steal data and compromise accounts with minimal human oversight.<\/p>\n<p class=\"wp-block-paragraph\">Israeli cybersecurity firm Dream documented what looks like the first fully autonomous, end-to-end AI hacking operation against a government target. Over four days at the start of July, according to the Financial Times, suspected Chinese hackers ran a tool built entirely from publicly available AI agents that mapped 21 government systems, hunted for vulnerabilities, and switched tactics on its own whenever it hit a wall.<\/p>\n<p class=\"wp-block-paragraph\">\u201cSuspected Chinese hackers used publicly available AI tools to compromise government websites in Taiwan in a first-of-a-kind breach, highlighting how artificial intelligence is transforming cyber warfare.\u201d <a href=\"https:\/\/www.ft.com\/content\/7d2ab3e0-9085-48f6-b38a-d90260d58795\" rel=\"nofollow noopener\" target=\"_blank\">reported<\/a> the Financial Times.<\/p>\n<p class=\"wp-block-paragraph\">The tool wasn\u2019t a single script running one attack. It deployed up to eight autonomous agents simultaneously, each working a different angle, more like a coordinated hacking team than a piece of malware. By the time researchers found it, the operation had compromised at least 85 government accounts, pulled over 2,500 personnel records, and expanded to hit a nuclear safety agency and at least seven energy companies.<\/p>\n<p class=\"wp-block-paragraph\">Dream\u2019s chief strategy officer, Amir Becker, spent years running cyber operations for Israel\u2019s Unit 8200 before this, and he\u2019s not easily rattled by new attack tooling. He said flatly he\u2019d never seen anything like this level of autonomy directed at a government before.  \u201cThis must be the basic assumption of every government around the globe,\u201d Becker said. <\/p>\n<p class=\"wp-block-paragraph\">He argued that permanent, assumed compromise is now the only realistic starting posture.<\/p>\n<p class=\"wp-block-paragraph\">Dream won\u2019t officially name the target government, citing company policy, though a person familiar with the matter told the FT it was Taiwan. The clues inside the data point the same direction: internal communications tied to the hacking tool were written in Simplified Chinese, while the data actually stolen from the target came back in Traditional Chinese, the script used almost exclusively by government systems in Taiwan, Hong Kong, and Macau. Taiwan\u2019s Ministry of Digital Affairs declined to confirm anything specific, saying only that incidents involving government agencies follow established response procedures.<\/p>\n<p class=\"wp-block-paragraph\">What makes this different from an AI model going rogue during a lab test, something <a href=\"https:\/\/securityaffairs.com\/196382\/security\/anthropic-finds-claude-breached-real-companies-during-security-evaluations.html\" data-type=\"post\" data-id=\"196382\" rel=\"nofollow noopener\" target=\"_blank\">Anthropic<\/a>, <a href=\"https:\/\/securityaffairs.com\/195658\/ai\/ai-agents-turned-into-attackers-hugging-face-reveals-autonomous-intrusion-campaign.html\" data-type=\"post\" data-id=\"195658\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI<\/a>, and <a href=\"https:\/\/securityaffairs.com\/196731\/security\/meta-ai-model-hacked-a-company-during-testing-marking-third-ai-lab-incident.html\" data-type=\"post\" data-id=\"196731\" rel=\"nofollow noopener\" target=\"_blank\">Meta<\/a> have all separately reported in recent weeks, is that this wasn\u2019t an accident inside a sandbox. Researchers found the toolkit sitting in a 160MB archive, 1,395 files built around two open-source AI agent frameworks, Hermes and OpenClaw, both freely downloadable and designed to let AI models act autonomously on real tasks. Whoever built this deliberately assembled it as a weapon.<\/p>\n<p class=\"wp-block-paragraph\">Getting the underlying AI model to cooperate took a specific trick rather than brute force. The operators had bypassed the model\u2019s safety guardrails simply by framing the entire hacking campaign as an authorized penetration test, a scenario the model apparently had no reliable way to verify or reject. That\u2019s a strange kind of vulnerability: not a flaw in the code, but a flaw in how convincingly you can lie to a system that\u2019s trying to be helpful.<\/p>\n<p class=\"wp-block-paragraph\">The part Dream\u2019s researchers found most striking wasn\u2019t the scale, it was the decision-making. The tool kept ranking and reprioritizing possible attack paths as new evidence came in, and when one route hit a dead end, it spun up another agent to search the internet for fresh information and try a different approach, the same iterative process a human red-teamer would run, just without anyone sleeping. <\/p>\n<p class=\"wp-block-paragraph\">\u201cThe most striking feature of the July attack was how the tool continuously ranked and reprioritised possible attack paths based on available evidence, Dream said.\u201d reported the FT. \u201cWhen one attack path failed, the tool deployed another agent to scour the internet for information and devise a new approach as a human hacker would.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Taiwan\u2019s National Security Bureau already <a href=\"https:\/\/www.asianews.it\/en\/articles\/taiwan-hit-by-about-26-million-daily-cyberattacks-from-mainland-china-in-2025\" rel=\"nofollow noopener\" target=\"_blank\">logged<\/a> an average of 2.6 million Chinese cyberattacks a day in 2025, up 6% year over year; if a meaningful fraction of that volume starts running with this kind of autonomy, the math on defending against it gets a lot uglier very quickly.<\/p>\n<p class=\"wp-block-paragraph\">Follow me on Twitter:\u00a0<a href=\"https:\/\/twitter.com\/securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">@securityaffairs<\/a>\u00a0and\u00a0<a href=\"https:\/\/www.facebook.com\/sec.affairs\" rel=\"nofollow noopener\" target=\"_blank\">Facebook<\/a>\u00a0and\u00a0<a href=\"https:\/\/infosec.exchange\/@securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">Mastodon<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"http:\/\/www.linkedin.com\/pub\/pierluigi-paganini\/b\/742\/559\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi\u00a0Paganini<\/a><\/p>\n<p class=\"wp-block-paragraph\">(<a href=\"http:\/\/securityaffairs.co\/wordpress\/\" rel=\"nofollow noopener\" target=\"_blank\">SecurityAffairs<\/a>\u00a0\u2013\u00a0hacking,\u00a0AI Agents)<\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan Pierluigi Paganini August 12, 2026 China-linked hackers reportedly&hellip;\n","protected":false},"author":2,"featured_media":137713,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[24,405,22148,25,7537,387,315,7512,8067,8068,8069,8070,390],"class_list":["post-137712","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai","tag-ai-agents","tag-apt","tag-artificial-intelligence","tag-artificial-intelligence-agents","tag-china","tag-hacking","tag-information-security-news","tag-it-information-security","tag-pierluigi-paganini","tag-security-affairs","tag-security-news","tag-taiwan"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/137712","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=137712"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/137712\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/137713"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=137712"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=137712"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=137712"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}