Hackers used coordinated artificial intelligence agents in cyberattacks targeting Taiwanese government networks, according to Taiwan officials and cybersecurity researchers.
Taiwan’s Ministry of Digital Affairs said it detected an unusual wave of cyberattacks targeting government agencies last July, with investigators finding evidence that the operation combined traditional hacking techniques with artificial intelligence agents.
According to the ministry, cybersecurity monitoring systems first identified suspicious activity on July 20, prompting alerts from the National Institute of Cyber Security and a broader government investigation. Officials said affected agencies have since completed their response measures.
The ministry described the campaign as originating overseas and involving AI agents, including OpenClaw, that could rapidly combine multiple attack techniques and use backup or testing environments as launching points. Officials said the technology enabled attacks to be carried out at high speed, low cost and large scale.
Researchers link attack to autonomous AI system
The disclosure comes alongside separate reporting by the Financial Times about research from Israeli cybersecurity company Dream. Dream described the operation as what may be the first fully autonomous, end-to-end AI cyberattack against a government target.
Dream said the attackers assembled a hacking platform using open-source AI agent frameworks, including Hermes and OpenClaw. According to the company, the system deployed as many as eight AI agents simultaneously over four days in early July to map 21 government systems, identify vulnerabilities and adjust tactics when defenses blocked initial attempts.
Researchers said the operation compromised at least 85 government accounts and obtained more than 2,500 personnel records before expanding to Taiwan’s nuclear safety agency and at least seven energy companies.
Amir Becker, Dream’s chief strategy officer and a former cyber operations leader in Israel’s Unit 8200, called it an “end-to-end autonomous attack” and warned that governments should assume they are constantly under threat. “This must be the basic assumption of every government around the globe,” Becker said, per FT.
Signs point toward China
Neither Taiwan nor Dream formally attributed the operation to a specific hacking group. However, Dream researchers said internal communications tied to the attack were written in Simplified Chinese, while the stolen data was in Traditional Chinese, which is commonly used in Taiwan. The language evidence may suggest a China link, but it does not establish attribution.
Taiwan has long accused Beijing of conducting cyber and information operations against the island, although officials stopped short of naming China in this case. The island’s National Security Bureau reported earlier this year that Taiwanese government networks faced an average of 2.6 million cyber intrusion attempts attributed to China per day in 2025, a 6% increase from the previous year.
A new reality for cyber defense
Researchers said the AI-driven system stood out because it could independently evaluate attack options, reprioritize targets and seek new information when an approach failed. Rather than acting as a simple automation tool, the agents reportedly behaved more like a coordinated hacking team.
Taiwan’s government said it has already strengthened monitoring, expanded intelligence sharing across agencies and introduced new protection guidelines to address AI-related threats.
Read more: An AI cybercrime report warns that autonomous tools are making attacks faster and more accessible, increasing pressure on defenders to strengthen monitoring and vulnerability management.





