China-linked Hackers Using AI Agents to Attack Taiwan Government Websites
Cybersecurity NewsArchived Aug 12, 2026✓ Full text saved
Suspected China-linked attackers have carried out what researchers describe as the first fully autonomous cyberattack on a foreign government, using open-source artificial intelligence tools to breach Taiwanese government websites and critical infrastructure. The operation, uncovered by Israeli AI and cyberdefense firm Dream, marks a sharp escalation in how artificial intelligence is reshaping cyber warfare and […] The post China-linked Hackers Using AI Agents to Attack Taiwan Government Website
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeCyber Security News
China-linked Hackers Using AI Agents to Attack Taiwan Government Websites
By Guru Baran
August 12, 2026
Suspected China-linked attackers have carried out what researchers describe as the first fully autonomous cyberattack on a foreign government, using open-source artificial intelligence tools to breach Taiwanese government websites and critical infrastructure.
The operation, uncovered by Israeli AI and cyberdefense firm Dream, marks a sharp escalation in how artificial intelligence is reshaping cyber warfare and demonstrates that machine-driven intrusion can now operate with the coordination once reserved for human hacking teams.
According to findings reported by the Financial Times and detailed by Dream, the attackers assembled an autonomous hacking platform from publicly available AI agent frameworks known as Hermes and OpenClaw.
Over four days in early July, the system deployed as many as eight agents at once. These agents mapped 21 government systems, researched vulnerabilities, adapted tactics whenever blocked, and moved through the network with minimal human steering.
Attack Chain
The tool compromised at least 85 government accounts and extracted more than 2,500 personnel records before expanding its reach to Taiwan’s nuclear safety agency and at least seven energy companies.
Dream researchers discovered evidence of the campaign in a 160MB online archive containing 1,395 files left exposed during broader threat-tracking work. The archive revealed how the agents continuously ranked and reprioritized attack paths.
When one route failed, another agent was tasked with scouring the internet for fresh intelligence and devising an alternative approach, allowing the operation to keep advancing without constant operator input.
Safeguards built into the underlying AI model were bypassed by framing the entire intrusion as an authorized penetration test, a simple prompt-engineering trick that let the agents treat destructive activity as legitimate security research. Researchers could not determine which specific large language model powered the agents.
Internal communications tied to the operation used Simplified Chinese, while data pulled from the targets appeared in Traditional Chinese, the written form common on government sites in Taiwan, Hong Kong, and Macau.
Dream has not formally attributed the campaign to any named group and, citing company policy, would only confirm that it alerted a government in the Asia-Pacific region.
A person familiar with the matter identified Taiwan as the target. Amir Becker, Dream’s chief strategy officer and a former head of cyber operations at Israel’s elite Unit 8200, called the incident an unprecedented “end-to-end autonomous attack” on a government target, noting that the system behaved like a coordinated cyber team rather than a single automated script.
The breach underscores how readily available open-source AI agents can lower the barrier to sophisticated, large-scale operations. What once required teams of skilled operators working in shifts can now be orchestrated by software that maps networks, steals credentials, discovers flaws, and pivots in real time.
At the same time, defenders are racing to build comparable AI systems capable of detecting and disrupting such autonomous campaigns before they spread.
[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now
Tags
cyber security
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security
WhatsApp Unveils New Scam Alert Feature to Protect Users from Social Engineering Attacks
Cyber Attack News
Eclipse Ransomware Launches RaaS Platform Targeting Windows, Linux, and ESXi Infrastructure
Cyber Security News
Google Chrome 151 Patches Five High-Severity Use-After-Free Flaws in V8, Blink, and Extensions
Cyber Security News
Hackers Actively Exploiting VMware vCenter Systems to Gain and Maintain Remote Access
Cyber Security News
737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?