- Category
- World
Researchers Say China Likely Linked to Unprecedented Autonomous AI Attack on Taiwan

Suspected China-linked hackers used publicly available AI tools to breach Taiwanese government websites in a first-of-its-kind attack, with autonomous software agents independently coordinating reconnaissance, intrusion, and tactical changes.
The Financial Times detailed the intrusion on August 12, citing findings from Dream, an Israeli AI and cyberdefense firm that first identified the breach.
We bring you stories from the ground. Your support keeps our team in the field.
The attackers relied on open-source AI agents to assemble an autonomous hacking tool that operated like a coordinated cyber team. Over four days at the start of July, it deployed up to eight agents that mapped 21 government systems, researched vulnerabilities, and shifted tactics whenever blocked.
The tool compromised at least 85 government accounts and extracted more than 2,500 personnel records, then widened its reach to Taiwan's nuclear safety agency and at least seven energy companies.
The evidence surfaced in a 160MB online archive of 1,395 files uncovered during the company's broader tracking of cyber threat actors. The files showed that the tool ran on two open-source agent systems, Hermes and OpenClaw, and that the underlying model's safeguards were bypassed by framing the intrusion as an authorized test of system vulnerabilities. Researchers could not determine which AI model powered the agents.

The tool's most striking trait, according to Dream, was its capacity to continuously rank and reprioritize attack paths against the evidence it gathered. When one route failed, it dispatched another agent to scour the internet and devise a fresh approach, much as a human operator would.
Amir Becker, Dream's chief strategy officer and a former head of cyber operations at Israel's elite Unit 8200 signals intelligence agency, described the operation as an unprecedented "end-to-end autonomous attack" on a government target. He warned that governments must now treat constant intrusion as a given, stating: "This must be the basic assumption of every government around the globe."
Dream has not tied the operation to any specific group. Researchers assessed a high probability that the operator was linked to China, citing the use of Simplified Chinese in internal communications connected to the hack. Data pulled from the target appeared in Traditional Chinese, a form common on government sites in Taiwan, Hong Kong, and Macau.

A person with knowledge of the incident identified the target as Taiwan, though Dream declined to confirm it, citing company policy, and would disclose only that it had alerted a government in the "Asia-Pacific."
A spokesperson for Taiwan's Ministry of Digital Affairs declined to comment on the specific breach, citing confidentiality, and indicated that incidents involving government agencies or critical infrastructure would be handled under established reporting and response procedures.
The spokesperson emphasized the shifting threat landscape: "Hacker attack methods have become increasingly diverse, and in recent years, the integration of AI technology has further transformed the nature of cyber security incidents." The official added that autonomous agents posed a twofold risk, automating attacks while themselves becoming fresh vulnerabilities.

Chinese authorities did not respond to requests for comment. Beijing claims Taiwan as its own territory and has threatened to seize the island by force should Taipei reject unification indefinitely. Taiwan's National Security Bureau reported in January that the island absorbed an average of 2.6 million Chinese cyberattacks per day in 2025, a 6 percent increase from the previous year.
The manipulation of commercial AI systems for hostile cyber operations has previously drawn scrutiny. Last November, Anthropic reported that it suspected Chinese state-sponsored hackers had manipulated its Claude tool to breach around 30 international companies and government agencies, though with limited success.
The use of artificial intelligence to accelerate state-linked cyber operations has surfaced elsewhere in recent months. Earlier, in August, a Russian state espionage unit was found to be leveraging AI tools to accelerate sophisticated phishing and malware campaigns that hijacked hotel and conference Wi-Fi networks worldwide, redirecting corporate executives and government travelers to malicious infrastructure disguised as routine software updates to harvest login credentials and access corporate accounts.
Discuss this article:

-111f0e5095e02c02446ffed57bfb0ab1.jpeg)

-c439b7bd9030ecf9d5a4287dc361ba31.jpg)



-72b63a4e0c8c475ad81fe3eed3f63729.jpeg)