AI Agents Ran a Government Hacking Campaign in Taiwan
Over four days in July, a system of up to eight AI agents ran a government hacking campaign in Taiwan with no human deciding the next move. The attacker effort that enterprise security economics assumes is scarce just stopped being scarce.

For two years the standard line on AI in offensive security was that it helps attackers write code and find bugs faster. A productivity gain, not a change in kind. Taiwan has just reported something different.
Over four days in July, an autonomous AI system attacked Taiwanese government networks. It mapped 21 government systems, cracked 85 user accounts and pulled out 2,500 personnel records. Dream, an Israeli AI firm, found the intrusion. The Financial Times reported it first, and Taiwan's Ministry of Digital Affairs confirmed it in a statement on Thursday.
Kenny Huang, who chairs the Taiwan Network Information Center, believes it is the first disclosed case of a fully automated attack against a government.
What "autonomous" means here
Not a person running an AI-assisted toolkit. Dream describes a system coordinating as many as eight AI agents that carried out the intrusions and chose what to do next with no human in the loop — reconnaissance, credential attacks, and working out the next hop through the network.
Taiwan's digital affairs ministry described a hybrid operation: conventional hacking combined with AI agents, including the open-source assistant OpenClaw. The agents chained techniques together and exploited weaknesses in secondary systems, which let the campaign move faster, cost less and cover more ground than a human team would.
Amir Becker, Dream's chief business and strategy officer, described behaviour that sounds uncomfortably like a competent red team. Block one route and the system researches new techniques and adapts on the spot.
The blast radius went well past those 21 systems. Taiwan's nuclear safety agency was hit, along with government IT vendors and at least seven energy companies.
On attribution
Neither Taiwan nor Dream has named the origin. Experts suspect China, and the reasoning is circumstantial but specific: internal documents tied to the operation use simplified Chinese, the writing system used in mainland China. CNN has approached Chinese authorities for comment.
Keep it in proportion, though. Taiwan absorbed an average of 2.6 million cyberattacks a day from China last year, 6% up on 2024. What's new isn't that Taiwan was attacked. It's how few people it took.
Why this one matters to enterprise security teams
Dream's own summary is the line worth carrying into your next risk review: the cost of running a competent attack has collapsed, while the cost of defending has not.
Enterprise security economics rests on attacker effort being scarce. Skilled operators are expensive, so the sophisticated campaigns go to high-value targets and everyone else survives on the odds. An agent that plans, adapts and works around blocks removes the scarcity. The same quality of campaign can now be pointed at a mid-size manufacturer, a state utility, or a supplier three tiers down your chain.
Detection windows shrink. Four days from reconnaissance to exfiltration across 21 systems is machine pace. Controls tuned to catch a human operator moving over weeks will fire well after the fact.
Your suppliers are in scope. The IT vendors and energy companies pulled into this campaign were reachable because agents can afford to work the periphery. Cheap attacks make secondary targets economical.
And the tooling is open source. OpenClaw is public — no export control, no procurement trail, no vendor anyone can pressure. Any threat model that assumes attackers need scarce, purchasable capability needs another look.
This isn't a reason to panic. It is a reason to re-check assumptions formed when a competent attacker was a scarce resource, and to treat agentic AI security as this year's operational problem rather than next year's research topic.
Source: Hackers used autonomous AI agents to attack Taiwan. Is this the future of cyberwarfare? — CNN