A Cyberattack That Refused to Sit Still
Taiwan has faced cyberattacks for years. This one, however, came with a troubling upgrade: artificial intelligence agents capable of researching targets, testing weaknesses, correcting mistakes and changing strategies with limited human supervision.
The campaign unfolded over four days in early July 2026. According to findings reported by PCMag, suspected China-linked hackers used publicly available AI technology to assemble what researchers described as a “near-autonomous” hacking system.
It did not behave like a basic malicious script. Nor did it simply generate phishing emails or help someone write malware. The system reportedly operated more like a small digital strike team.
As many as eight AI agents worked simultaneously. Together, they mapped government networks, looked for vulnerabilities, tested routes into targeted systems and switched tactics when an approach failed.
The operation examined 21 government systems, compromised at least 85 user accounts and extracted more than 2,500 personnel records, according to the reports. It later expanded its attention to Taiwan’s nuclear safety agency, government technology suppliers and at least seven energy companies.
That combination—government accounts, personnel data and critical infrastructure—turned an already serious intrusion into something far more alarming.
The attack also offered a glimpse of a cybersecurity problem that experts have discussed for years: AI may allow hackers to operate faster, on more targets and with fewer people.
Now, that concern appears to have left the conference slide deck and walked directly into the server room.
Taiwan Confirms an AI-Assisted Campaign
Taiwan’s Ministry of Digital Affairs confirmed on August 13 that government agencies had encountered AI-assisted cyberattacks during July.
According to The Straits Times, Taiwan’s cybersecurity monitoring units detected what officials called an “abnormal attack.” The National Institute of Cyber Security began issuing warning alerts on July 20 while authorities investigated the activity.
Officials said the operation showed clear characteristics of an overseas source. The attackers apparently combined manual work with AI agent-assisted techniques, including the use of OpenClaw.
Taiwan did not publicly identify China as the attacker. Its statement also avoided disclosing detailed information about the affected systems, damage or data losses. Instead, the ministry said authorities had investigated the sources, methods and scope of the incident, while affected agencies had completed their response measures.
That wording matters.
Taiwan confirmed the AI-assisted campaign, but it did not publicly endorse every detail contained in Dream’s investigation. The Israeli cybersecurity company reconstructed a four-day operation after finding what it described as the attackers’ complete operational workspace.
The public record therefore contains two closely related accounts: Taiwan’s official confirmation of an overseas, AI-assisted attack and Dream’s detailed reconstruction of a multi-agent intrusion. Reports connect the two, although authorities have not published a complete technical timeline proving that every observed activity belonged to one operation.
In cyber investigations, certainty rarely arrives wearing a name tag.
Eight Agents, One Relentless Mission
Traditional hacking campaigns already use automation. Attackers scan networks, test stolen passwords and search for vulnerable servers with software tools. What made this operation different was the reported ability of its AI agents to coordinate and adapt.
The system deployed as many as eight agents at once, according to The Arabian Post. Each could handle a portion of the broader assignment.
One agent might map a network. Another could research a software vulnerability. Others could investigate exposed interfaces, test credentials or look for alternative entry points. The system then used the results to decide where to focus next.
That division of labor made the campaign resemble a coordinated human hacking team—except the digital workers did not need coffee, sleep or an argument over whose turn it was to update the spreadsheet.
Dream’s researchers said the system could reprioritize attack paths as new evidence appeared. If one tactic failed, an agent could search vulnerability databases, public security research and software repositories for another option.
These research sessions reportedly formed part of what the system called “Learning Cycles.” The agents gathered information specific to the targeted infrastructure and fed those findings back into the operation.
In practical terms, the attack did not merely follow a rigid checklist. It reacted.
That ability separates ordinary automation from more agentic behavior. A conventional script usually stops when it encounters an unexpected obstacle. An AI-driven agent can interpret the failure, search for another method and keep moving.
For defenders, “keep moving” may be the two most expensive words in the building.
The Open-Source Tools Behind the Operation
The attackers reportedly built their system around two publicly available agent frameworks: Hermes and OpenClaw.
Agent frameworks connect an AI model to tools and workflows. Depending on their configuration and permissions, agents can search the web, examine documents, write or execute commands, organize information and pursue objectives across several steps.
That capability has plenty of legitimate uses. Developers can employ agents to test software, automate repetitive work and identify security problems before criminals exploit them.
The same flexibility also creates a dual-use dilemma. A tool that helps an authorized security professional locate exposed systems can assist an attacker performing the same search without permission.
Crucially, investigators have not identified the underlying AI model that powered the Taiwan operation. The available evidence points to the surrounding frameworks and orchestration system, but it does not reveal which model supplied the reasoning engine.
That distinction often disappears in breathless headlines. “AI attacked Taiwan” sounds suitably cinematic. Reality remains more complicated.
Human operators selected or built the tools. They chose the targets, established the objectives and configured the agents. AI then appears to have performed significant parts of the operation with unusual independence.
Researchers also found evidence that the system’s safety protections had been bypassed. The malicious activity was allegedly presented to the AI as authorized penetration testing—a legitimate practice in which security professionals probe systems with the owner’s permission.
The agents apparently received the “authorized” part of the story. The real targets did not.
How Investigators Reconstructed the Attack

Dream did not discover the campaign by watching every action live. Instead, the company reportedly found an online archive containing the operational remains of the attack.
The archive held approximately 160 megabytes of information and nearly 1,400 files. Those materials allowed researchers to reconstruct how the agents communicated, selected targets and adjusted their methods.
That is the cyber equivalent of a burglar dropping a color-coded project binder on the way out.
The recovered workspace reportedly documented multiple attack waves and a collection of AI sub-agents. Dream said as many as eight operated concurrently during one wave.
The files also revealed how the system ranked possible attack paths. It evaluated available evidence, prioritized promising opportunities and reassessed its choices when conditions changed. Researchers described self-correction loops and adaptive research cycles that helped the agents recover from unsuccessful attempts.
This evidence supported Dream’s description of the campaign as near-autonomous. However, “near” deserves the spotlight.
The system did not spontaneously wake up, glance at a map and develop geopolitical ambitions. Humans still had to create the framework, define the mission and point it toward selected infrastructure.
Security researcher Cris Thomas emphasized that distinction in comments included in The Straits Times report. A capable operator still had to choose the victim, establish an objective and issue directions.
The attack showed meaningful operational autonomy, not magical independence. Unfortunately, defenders do not receive bonus points because a human clicked “start.”
What the Attackers Reportedly Reached
Dream’s findings described a campaign that moved well beyond casual reconnaissance.
The agents reportedly compromised at least 85 government user accounts and extracted more than 2,500 personnel records. They also obtained numerous passwords belonging to officials, although public reports do not provide a complete inventory of the stolen credentials.
Personnel records can support further espionage. They may reveal job roles, departments, contact information and organizational relationships. Attackers could use those details to select higher-value targets, craft convincing messages or identify employees with access to sensitive systems.
The campaign also reportedly reached Taiwan’s Ministry of Justice and examined systems belonging to the island’s nuclear safety agency. Investigators said the agents expanded their scanning to government email infrastructure, technology supply-chain vendors and at least seven energy-sector companies.
Scanning does not automatically mean compromise. A hacker can examine a system without successfully entering it. Public reporting does not establish that every organization investigated by the agents suffered a breach.
That difference is essential. The confirmed compromise of accounts and theft of records should not be carelessly extended to every scanned target.
Still, the expansion pattern remains worrying.
Once the system found success against its primary targets, it broadened the campaign. It searched connected organizations for exposed administration panels, configuration mistakes and exploitable vulnerabilities.
This is where an adaptive agent can create serious pressure. It can test numerous pathways in parallel, preserve useful discoveries and quickly redirect resources toward the weakest door.
Security teams, meanwhile, still have meetings.
The China Attribution Question
Several reports describe the operators as suspected China-linked hackers. Yet the available evidence does not conclusively identify a named hacking group or prove that the Chinese government directed the operation.
Investigators reportedly found internal communications written in Simplified Chinese. The data taken from Taiwanese networks, by contrast, largely used Traditional Chinese. Researchers considered that difference one indicator that the operators likely had links to mainland China.
It is meaningful evidence. It is not a digital fingerprint.
Attackers can change language settings, imitate another group’s habits or plant misleading clues. Cyber attribution usually requires multiple forms of evidence, including infrastructure records, malware similarities, operational patterns and intelligence unavailable to the public.
Taiwan’s Ministry of Digital Affairs described the campaign as coming from overseas but did not name China. Beijing’s Taiwan Affairs Office had not immediately responded to requests for comment when the official confirmation was reported.
The broader context inevitably shapes suspicion. Taiwan says it faces persistent Chinese cyber activity as part of a wider pattern of military pressure, influence operations and digital espionage.
The island’s National Security Bureau reported that cyberattacks attributed to China against critical infrastructure rose 6% in 2025, reaching an average of 2.63 million attempts per day. Some activity reportedly coincided with Chinese military exercises near Taiwan.
That context makes China-linked attribution plausible. It does not make it settled fact.
The careful conclusion is straightforward: investigators found signs pointing toward China-linked operators, but neither Dream nor Taiwan publicly established direct state responsibility.
Sometimes the least exciting sentence is also the most accurate one.
Why Taiwan Is Such a Valuable Target
Taiwan occupies an unusually important place in global technology and geopolitics.
Its government manages sensitive diplomatic, defense and security information. Its companies hold central positions in semiconductor manufacturing, electronics and international supply chains. Its energy networks and public infrastructure support an economy whose disruptions could ripple far beyond the island.
That makes Taiwanese institutions attractive espionage targets.
Government personnel data can help foreign intelligence operations understand who works where and which officials may hold privileged access. Compromised accounts can provide footholds for deeper intrusion. Information collected from suppliers may offer an indirect route into better-protected agencies.
Critical infrastructure adds another dimension. Even when attackers do not immediately disrupt energy or nuclear-related systems, mapping those networks can produce valuable intelligence for future operations.
Taiwan has long characterized hacking, disinformation and military activity as connected elements of hybrid pressure. Cyber operations provide an adversary with options that sit below the threshold of conventional conflict.
They can steal information. They can probe readiness. They can create uncertainty. Most importantly, they may allow an attacker to prepare access that becomes useful during a future crisis.
AI agents could increase the scale of such operations. A smaller team may be able to investigate more organizations at once, maintain activity for longer periods and respond faster when defenders block one route.
This does not make AI an unbeatable cyber weapon. Agents can fail, misunderstand results and waste time pursuing dead ends.
But when software can test thousands of possibilities, being wrong cheaply can still become a powerful strategy.
Near-Autonomous Does Not Mean Unstoppable
The attack demonstrates a real increase in capability, but it should not inspire a robot-apocalypse soundtrack just yet.
AI agents still depend on infrastructure, credentials, tools and human-defined objectives. They can make errors. They may misinterpret a system, choose an ineffective exploit or generate commands that fail.
Attackers also expose themselves when they operate. Their agents create network traffic, access logs, files, command histories and patterns that defenders can detect. In this case, the preserved workspace gave investigators an unusually detailed view of the campaign.
Taiwan said the affected agencies successfully handled the incident. Authorities established new defensive guidelines and strengthened monitoring across government bodies so they could identify and block similar attacks earlier.
Those steps point toward the likely future of cybersecurity: automation fighting automation.
Defensive agents can sift through massive volumes of logs, correlate suspicious events and isolate compromised accounts. They can also help security analysts prioritize alerts instead of drowning them in a digital swimming pool filled entirely with red flags.
However, defensive automation needs careful controls. Giving an AI system permission to shut down accounts or modify networks creates its own risks. A mistaken response could interrupt important services just as effectively as an attacker.
The answer is not simply “deploy more AI.” Organizations need layered defenses, restricted privileges, strong authentication, network segmentation, current software and human supervision.
AI may accelerate the contest. It does not repeal cybersecurity fundamentals.
A Preview of Cyberwar’s Next Phase

The Taiwan campaign matters because it appears to cross an operational threshold.
Hackers have used AI for reconnaissance, coding and social engineering before. This system reportedly went further. It coordinated multiple agents, learned from failed attempts, pursued several targets simultaneously and expanded the operation as new opportunities appeared.
That does not amount to full autonomy. The phrase “near-autonomous” remains more accurate. Humans designed the mission and stayed somewhere in the loop, even if the agents performed much of the tactical work.
Still, the economics of hacking may be shifting.
A sophisticated operation once required numerous specialists working long hours. Agentic systems could help smaller groups imitate some of that capacity. They may also allow well-resourced state-linked teams to increase their speed and coverage dramatically.
Open-source availability adds another twist. Defenders cannot solve this problem by pressuring a single AI company or blocking one commercial model. Agent frameworks can connect with different models, tools and databases. The pieces are widely distributed.
The central lesson is not that open-source AI caused the attack. The lesson is that capable models, flexible agent frameworks and real-world tools can form an offensive system when a determined operator assembles them.
Taiwan’s experience offers an early warning. AI agents are no longer limited to drafting suspicious emails or suggesting snippets of malicious code. They can participate in sustained, adaptive operations against real institutions.
The bots have joined the hacking team. Now defenders must make sure they do not get the promotion.
Sources
- PCMag — Chinese Hackers Created a “Near-Autonomous” Attack Using Open-Source AI
- The Straits Times — Taiwan Says It Was Targeted in AI-Driven Hacking Campaign
- The Arabian Post — AI Agents Breach Taiwan Government Networks
Publishing
The Kingy Brief
Source-checked AI launch and product intelligence. See the public archive for the latest edition and cadence.
