China-Linked Hackers Deploy Autonomous AI Agents in Unprecedented Attack on Taiwan
Suspected China-linked threat actors have executed what security researchers are calling the first fully autonomous cyberattack against a foreign government, utilizing open-source AI agents to breach Taiwanese government websites and critical infrastructure.

Suspected China-linked attackers have carried out what researchers describe as the first fully autonomous cyberattack on a foreign government, using open-source artificial intelligence tools to breach Taiwanese government websites and critical infrastructure. The operation, uncovered by Israeli AI and cyberdefense firm Dream, marks a sharp escalation in how artificial intelligence is reshaping cyber warfare and demonstrates that machine-driven intrusion can now operate with the coordination once reserved for human hacking teams.
According to findings reported by the Financial Times and detailed by Dream, the attackers assembled an autonomous hacking platform from publicly available AI agent frameworks known as Hermes and OpenClaw. Over four days in early July, the system deployed as many as eight agents at once. These agents mapped 21 government systems, researched vulnerabilities, adapted tactics whenever blocked, and moved through the network with minimal human steering.
The tool compromised at least 85 government accounts and extracted more than 2,500 personnel records before expanding its reach to Taiwan’s nuclear safety agency and at least seven energy companies. Dream researchers discovered evidence of the campaign in a 160MB online archive containing 1,395 files left exposed during broader threat-tracking work. The archive revealed how the agents continuously ranked and reprioritized attack paths.
When one route failed, another agent was tasked with scouring the internet for fresh intelligence and devising an alternative approach, allowing the operation to keep advancing without constant operator input. Safeguards built into the underlying AI model were bypassed by framing the entire intrusion as an authorized penetration test, a simple prompt-engineering trick that let the agents treat destructive activity as legitimate security research.
Researchers could not determine which specific large language model powered the agents. Internal communications tied to the operation used Simplified Chinese, while data pulled from the targets appeared in Traditional Chinese, the written form common on government sites in Taiwan, Hong Kong, and Macau. Dream has not formally attributed the campaign to any named group and, citing company policy, would only confirm that it alerted a government in the Asia-Pacific region. A person familiar with the matter identified Taiwan as the target.
Amir Becker, Dream’s chief strategy officer and a former head of cyber operations at Israel’s elite Unit 8200, called the incident an unprecedented “end-to-end autonomous attack” on a government target, noting that the system behaved like a coordinated cyber team rather than a single automated script. The breach underscores how readily available open-source AI agents can lower the barrier to sophisticated, large-scale operations.
What once required teams of skilled operators working in shifts can now be orchestrated by software that maps networks, steals credentials, discovers flaws, and pivots in real time. At the same time, defenders are racing to build comparable AI systems capable of detecting and disrupting such autonomous campaigns before they spread.
This incident highlights a significant shift in cyber warfare capabilities, demonstrating the potential for AI-driven agents to conduct complex, multi-stage attacks with reduced human oversight. The ability of these agents to autonomously adapt and overcome defenses poses a substantial challenge to traditional cybersecurity measures and necessitates the development of new AI-native defense strategies.
This new report from CyberScoop provides additional detail on the AI-driven attack, specifically highlighting the use of open-source AI frameworks like Hermes and OpenClaw. It further emphasizes the system's ability to autonomously research vulnerabilities and adapt its tactics mid-operation, a capability described as 'near-autonomous' and distinct from previous AI-driven campaigns that required more human intervention.