Autonomous AI Agents Breach Taiwan Government in First Known Attack
Hackers deployed coordinating AI systems that mapped networks, cracked accounts, and stole records across four days without human intervention.
First fully autonomous cyberattack targets government
Hackers deployed autonomous AI systems to breach Taiwan government networks in July, marking what cybersecurity experts believe is the first known case of a fully automated attack on government agencies. Over four days, the AI-driven operation mapped 21 government systems, compromised 85 user accounts, and extracted 2,500 personnel records.
The attack was discovered by Dream, an Israeli AI security firm, which found that hackers used open-source AI agents to coordinate the entire intrusion. Unlike previous attacks where AI merely assisted human operators, this system ran independently—conducting reconnaissance, executing credential attacks, and strategizing next steps without human intervention.
"Like a human team, when an approach gets blocked, it researches new techniques in real time and adapts," said Amir Becker, Dream's chief business and strategy officer. "It's an attacker that strategizes, learns, and adjusts on its own."
Why it matters
This incident represents a fundamental shift in cyber threat economics. Autonomous AI systems dramatically reduce the cost and expertise required to execute sophisticated attacks while defense costs remain unchanged. Organizations now face adversaries that can operate continuously, adapt in real-time, and scale attacks far beyond what human-led operations could achieve. The collapse in attack costs without corresponding advances in defensive capabilities creates an asymmetric threat that every organization must prepare for.
Scale and sophistication of the breach
Taiwan's Ministry of Digital Affairs confirmed the attack in a Thursday statement, noting that investigators found "clear indications that the attacks originated overseas and involved a hybrid approach in which hackers combined conventional operations with AI agents such as OpenClaw." The system coordinated up to eight AI agents simultaneously to carry out the campaign.
The breach extended beyond core government systems to Taiwan's nuclear safety agency, government IT vendors, and at least seven energy sector companies. The AI agents quickly combined different hacking techniques and exploited vulnerabilities in secondary systems, enabling attacks that were faster, cheaper, and larger in scale than traditional methods.
China suspected but unconfirmed
While neither Taiwan nor Dream officially confirmed the attack's origin, experts noted that internal documents linked to the hack contained simplified Chinese characters used in mainland China. Taiwan faces an average of 2.6 million cyberattacks daily from China, according to government reports, representing a 6% increase from 2024.
China claims Taiwan as its territory and has intensified pressure campaigns including disinformation operations, cyberattacks, and military exercises around the island. CNN reached out to China's Ministry of Foreign Affairs, Taiwan Affairs Office, and Cyberspace Administration but had not received comment.
Defensive gaps exposed
Kenny Huang, chairman of the Taiwan Network Information Center, said the incident demonstrates that AI has evolved from assisting human hackers to becoming the primary actor in cyberattacks. He questioned whether the world has adequate defensive strategies, legal frameworks, and technical capabilities to counter autonomous AI threats.
"I believe there are still significant gaps," Huang said. "Every country, not just Taiwan, is still unprepared in this respect."
The case was first reported by the Financial Times on Wednesday, with additional details provided by Dream's security research team.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call