In July, Israeli cybersecurity firm Dream detected what appears to be the first end-to-end autonomous cyberattack against Taiwan government infrastructure. Over four days, attackers orchestrated publicly available open-source AI agents (Hermes and OpenClaw) to run up to eight sub-agents in parallel, autonomously mapping 21 government systems, cracking 85 user accounts, and exfiltrating 2,564+ personnel records. The campaign targeted Taiwan’s nuclear safety agency and energy sector.
What’s revealing is how they bypassed AI safety guardrails. Rather than exploiting a technical flaw, they reframed the intrusion as an authorized security assessment. AI systems protect against requests framed as harmful, but falter against social engineering that makes the request seem legitimate.
Artifact analysis with code-switching between Simplified and Traditional Chinese points to a Chinese-language operator. Using commodity open-source tools, they’ve demonstrated what security researchers predicted: the attacker-defender cost asymmetry now decisively favors offense. This is no longer theoretical.
Sources: Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia
Coverage: China-Linked Hacker Shows AI Capabilities in APAC Attack • Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan
Related on this blog: The Evidence DeepSeek Ran This Attack Is a Command-Line Flag • [AUTO] AI Phishing Defenses Outpaced by AI Attack Volume • [QT] Zhipu’s Bug-Finder Claims Need Verification