Skip to content
EspionageContained

Near-autonomous AI agent campaign breaches Taiwan government systems

A hacking operation using AI agents compromised 85 Taiwanese government accounts and extracted more than 2,500 personnel records in July 2026 before probing the nuclear safety agency and energy companies; Taiwan's digital ministry confirmed the attack.

Victim
Taiwanese government agencies
records
2.6K

On 12 August 2026, the Financial Times revealed that Taiwanese government systems had been hit in July 2026 by one of the first known hacking operations run largely by AI agents. The campaign was uncovered by Israeli cybersecurity firm Dream, which found a 160 MB online archive of 1,395 files documenting the operation, and Taiwan's Ministry of Digital Affairs confirmed that the island had suffered an AI-assisted attack.

According to Dream, over the first four days of July the agents compromised at least 85 government user accounts and extracted more than 2,500 personnel records (2,564 by The Register's count). They harvested employee usernames from an unauthenticated API, broke into a department's office automation portal while solving its CAPTCHAs, and then moved on to Taiwan's nuclear safety agency, the government email system, IT supply-chain vendors and at least seven energy companies.

How the operation worked

The framework, built on open-source agent tools including OpenClaw and Hermes, ran up to eight sub-agents in parallel across 12 attack waves, each assigned its own targets and techniques. The agents mapped 21 government systems, discovered dozens of API endpoints (many without authentication), changed tactics when blocked, and stole seven SSO client secrets and internal database credentials for MSSQL, Oracle and Sybase systems.

Attribution and response

Taiwan did not publicly name a culprit. Dream noted that the operation's internal documentation was written in simplified Chinese, pointing to a Chinese-language operator. The Administration for Cyber Security said the source, methods and scope of the attacks had been determined and that affected agencies had completed their responses.

Why it matters

The campaign is an early real-world example of a state-scale intrusion where AI agents did much of the reconnaissance, exploitation and adaptation that would normally require a team of operators. It made attacks faster and cheaper while exploiting ordinary weaknesses such as exposed, unauthenticated APIs, which suggests defenders will face more parallel, persistent probing of the same basic gaps.

Timeline

  1. Over four days, AI agents compromise 85 government user accounts and extract more than 2,500 personnel records.

  2. Taiwan's National Institute of Cyber Security begins issuing alerts linked to the activity.

  3. The Financial Times and The Register report the campaign, based on research by Israeli firm Dream; Taiwan's Ministry of Digital Affairs subsequently confirms the AI-assisted attack.

Sources

  1. theregister.comhttps://www.theregister.com/security/2026/08/12/near-autonomous-ai-agents-attack-taiwans-nuclear-safety-agency/5287055
  2. taipeitimes.comhttps://www.taipeitimes.com/News/front/archives/2026/08/14/2003862463
  3. scworld.comhttps://www.scworld.com/news/taiwan-confirms-ai-assisted-cyberattack-on-government-systems
  4. securityaffairs.comhttps://securityaffairs.com/197079/apt/china-linked-hackers-use-ai-agents-in-autonomous-attack-on-taiwan.html

Related incidents

EspionageContained

Ukraine power grid attack โ€” Sandworm BlackEnergy (2015)

The Russia-linked Sandworm group used spear-phishing, BlackEnergy3, and KillDisk to remotely flip breakers at three Ukrainian regional electricity distribution companies, cutting power to approximately 230,000 customers for 1โ€“6 hours. It is the first publicly acknowledged successful cyberattack on an electric power grid in history.

Victim
Ukrainian regional electricity distribution companies (Oblenergos)