Cybersecurity officials have revealed that hackers utilized an artificial intelligence system to execute intricate cyberattacks on Taiwan, marking what experts believe to be the inaugural fully autonomous assault on governmental entities.
During a four-day period in July, AI agents successfully mapped out 21 governmental networks, breached 85 user accounts, and retrieved 2,500 personnel files, as reported by Dream, an Israeli AI firm that identified the breach.
While there are suspicions that the attackers may be linked to China, both Taiwan and Dream have refrained from confirming the origin of the July incidents.
Investigations revealed clear signs that the attacks emanated from abroad, employing a mixed-method strategy wherein traditional hacking tactics were combined with AI technologies such as OpenClaw, according to a statement from Taiwan's Ministry of Digital Affairs issued on Thursday.
According to Dream, the hackers operated an AI system harnessing open-source agents to execute and streamline various aspects of the intrusion, including reconnaissance, credential theft, and the formulation of future attack strategies. The Financial Times first highlighted these developments on Wednesday.
This incident arises at a time of heightened concern regarding the emergence of advanced AI models capable of conducting unauthorized operations, prompting calls for enhanced regulatory measures on AI technologies.
Kenny Huang, chairman of the Taiwan Network Information Center, indicated that this might be the first publicized instance of a completely automated attack targeting a government.
Utilization of AI to generate code and identify vulnerabilities during cyberattacks has become increasingly standard. However, this case pushed boundaries further.
An autonomous system was reported to manage up to eight AI agents, independently executing intrusions and determining subsequent actions without human oversight, fundamentally transforming the nature of the attack from mere support for human hackers to leading the hacking operation itself.
Dream summarized the implications succinctly: “The cost to conduct a successful attack has drastically decreased, yet the expenses tied to defense mechanisms remain unchanged.”
Amir Becker, Dream’s chief business and strategy officer, expressed serious concerns about the operational capabilities of the AI system in this incident.
“Similar to a human team, when faced with obstacles, it dynamically researches alternative methods and adapts its approach. This is an attacker that learns and evolves autonomously,” he explained.
The attack reportedly impacted not just the Taiwanese government but also targeted the nation's nuclear safety agency, various IT vendors, and at least seven energy sector firms.
The AI agents rapidly combined diverse hacking strategies and exploited weaknesses in secondary systems, enabling the attacks to occur more swiftly, economically, and at a larger scale, stated Taiwan's digital affairs ministry.
The presence of simplified Chinese characters, typically associated with China, in internal documents related to the hacking incident suggests a strong likelihood that the perpetrators have ties to China, as noted by experts.
Efforts to obtain comments from China's Ministry of Foreign Affairs, Taiwan Affairs Office, and Cyberspace Administration have been made by CNN.
Taiwan has a history of cyberattacks, predominantly from China, which considers the island a part of its territory and has threatened to annex it if necessary. A government report detailed an average of 2.6 million daily cyberattacks from China on Taiwan in the previous year, reflecting a 6% increase from 2024.
As Beijing intensifies its operations against Taipei, Taiwanese authorities assert that their democracy is at the leading edge of China’s “hybrid warfare,” encountering information manipulation, cyber assaults, and frequent military exercises in proximity to Taiwan.
Huang from the Taiwan Network Information Center stated that the July attacks underscore the emergence of AI as a primary force within cybersecurity, extending its role beyond merely aiding human hackers in partial automation tasks.
He emphasized the urgent need to assess whether global defenses against AI-driven attacks are sufficient, pointing to significant gaps in legal frameworks, technical abilities, and policies.
“There are considerable deficiencies. Countries around the world, not just Taiwan, are still unprepared in this regard,” he concluded.



