Malicious hackers deployed self-operating AI agents in a complex cyberattack on Taiwanese government systems, which experts consider to be the first documented case of an almost autonomous or end-to-end AI-aided attack on a governmental establishment. During the four-day incident, the Israeli software security firm Dream published details about the event, and the Ministry of Digital Affairs of Taiwan (MODA) eventually confirmed it.Hackers, as the research published by Dream, created their attacking instrument through free AI agent platforms like Hermes and OpenClaw. These technologies permit multiple “attack waves” via eight parallel sub-agents. The machines autonomously discovered vulnerabilities in 21 government systems, mapped those systems, pulled embedded URLs, APIs and configuration details, and changed strategies without any need for human intervention or guidance after they were being blocked.
A total of 85 user accounts in the government sector were exposed and over 2,500 personnel records retrieved because of that. Then, the attackers spread their attack to various sectors including nuclear safety agency, government IT suppliers and at least seven energy companies in the island. Attackers claimed that the operation was an authorized security test and aimed at bypassing safety guardrails in the AI models used. The Ministry of Digital Affairs stated that cyber security units detected the abnormal attack in July, and the National Institute of Cyber Security began issuing alerts at about the 20th. Authorities say a hybrid method with manual operations and some AI agent assistance like OpenClaw was used to carry the attack from a foreign location. Officially, the sources, the techniques, and the extent of the attacks have all been fully investigated, also responding agencies have finished their mitigation measures; Yet, the ministry has not mentioned the specific entity behind the crime.
Really internal communication of the hacking operation is in Simplified Chinese while the stolen data is in Traditional Chinese has led to speculation of China involvement. Although Dream and the government have not publicly assigned the attack to any particular country or organization, researchers still see China behind the hack. Meanwhile China overall, keeps silent to the reports.
Experts have drawn attention to the high degree of the attackers’ independence which is one of the most striking features of this cyber campaign. Dream’s top strategist called it a first for government entities and advised organizations that they should take it seriously that the adversaries will keep on using the tools that enable the automatic compromise. The availability of free open-source software illustrates the potential of AI agents to dramatically speed up reconnaissance, credential exploitation and decision-making, so it might become a lot easier doing really sophisticated cyber intrusions. Over time, the island has reported numerous cyber attacks often linking with China as part of a broad array of tactics including cyber. This is just another indication of the rapidly changing nature of cyber war since AI systems have been working more or less like a coordinated team rather than just helping tools, so it is now an acute issue worldwide on how well governments are preparing for and responding to the defense in the face of such advanced threats.


