Taiwan Reports First AI-Assisted Cyberattack on Government
Autonomous hacking tools compromised 85 accounts and extracted personnel records from agencies including nuclear safety regulators.

Taiwan detects autonomous hacking campaign
Taiwan's Ministry of Digital Affairs has confirmed it detected what security researchers are calling a first-of-a-kind AI-assisted cyberattack on government systems last month. The intrusion, which began on July 20, used autonomous hacking tools built from open-source AI agents to breach at least 85 government user accounts and extract more than 2,500 personnel records, according to details first reported by the Financial Times.
The attack expanded beyond initial government targets to compromise Taiwan's nuclear safety agency and at least seven energy companies. Dream, an Israeli AI security firm that helped detect the breach, told the FT that the attackers deployed tools that behaved like a coordinated cyber team operating with minimal human oversight.
Why it matters
This incident marks a significant escalation in offensive cyber capabilities. While AI-assisted reconnaissance and vulnerability scanning have existed for years, the deployment of autonomous agents that can independently execute multi-stage attacks represents a new threat model. For critical infrastructure operators and government agencies, the speed and coordination demonstrated in this campaign—moving from initial compromise to data extraction to lateral movement across multiple organizations—suggests traditional defense timelines may no longer apply. Organizations must now assume adversaries can operate at machine speed across the entire attack chain.
Evidence points to China-linked operators
While Taiwanese officials stopped short of directly attributing the attack, the FT reported that China-linked hackers are suspected. Dream noted that the use of Simplified Chinese in internal communications associated with the hack indicated a high probability of Chinese state connection, though the firm did not make a definitive attribution.
The incident fits a broader pattern of escalating cyber operations against Taiwan. The island's National Security Bureau reported in January that Chinese cyberattacks on critical infrastructure rose 6% in 2025 to an average of 2.63 million attacks per day. Some of these operations have been synchronized with military exercises as part of what Taiwan describes as "hybrid warfare" campaigns.
Technical details and response
The Ministry of Digital Affairs said investigators identified the attack as originating from overseas sources and employing a hybrid approach that combined manual operations with AI agent-assisted attacks. The ministry specifically mentioned Open Claw, though it did not provide additional technical details about this tool.
Taiwan's National Institute of Cyber Security issued warning alerts during the investigation. The government has since established new protective guidelines and strengthened system monitoring capabilities designed to detect and block similar attacks earlier in their progression.
The autonomous hacking debate
Security researcher Cris Thomas of Semgrep cautioned against overstating the autonomy of these tools. "There's still a human in there somewhere," Thomas told the Guardian. "Somebody had to choose who to attack, had to establish an objective and give it a directive. It's not totally 100% autonomous. There was a capable operator in charge that did that."
The threat landscape has accelerated dramatically in recent months following the release of advanced AI models from major labs, including Anthropic's Mythos, which can rapidly conduct reconnaissance, identify system vulnerabilities, and exploit them.
These details were first reported by the Guardian and the Financial Times, with additional reporting from Reuters.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call