Article · 8 min read

AI agents carried out what may be the first fully autonomous government hack. Here's what actually happened.

Published August 2026

For years, security researchers warned that AI would eventually be used not just to assist hackers but to replace them. In July 2026, something very close to that happened. Suspected China-linked attackers used a system of autonomous AI agents to break into Taiwanese government infrastructure, steal thousands of personnel records, and pivot to energy companies and a nuclear safety agency, all largely without a human in the loop. The incident was uncovered and reported publicly in August, and it deserves careful attention.

What happened

Suspected China-linked attackers carried out what researchers describe as the first fully autonomous cyberattack on a foreign government, using open-source artificial intelligence tools to breach Taiwanese government websites and critical infrastructure. The operation was uncovered by Dream, an Israeli AI and cyberdefence firm.

The attackers assembled an autonomous hacking platform from publicly available AI agent frameworks known as Hermes and OpenClaw. Over four days in early July, the system deployed as many as eight agents at once. These agents mapped 21 government systems, researched vulnerabilities, adapted tactics whenever blocked, and moved through the network with minimal human steering. The tool compromised at least 85 government accounts and extracted more than 2,500 personnel records before expanding its reach to Taiwan's nuclear safety agency and at least seven energy companies.

The illicit access allowed the agents to exfiltrate more than 2,564 personnel records, a full JSON export of all department system users, seven SSO client secrets, six internal database credentials across MSSQL, Oracle, and Sybase, and internal network IP ranges. That is not a smash-and-grab. It is a systematic dismantling of access controls.

Dream researchers discovered evidence of the campaign in a 160MB online archive containing 1,395 files left exposed during broader threat-tracking work. The archive revealed how the agents continuously ranked and reprioritised attack paths. When one route failed, another agent was tasked with scouring the internet for fresh intelligence and devising an alternative approach, allowing the operation to keep advancing without constant operator input.

There's more where this came from. New articles most weeks.Browse all articles →

Why this is different from ordinary hacking

Cybercriminals have used AI for a while now, mainly to write phishing emails, generate malware variants, or scan for known weaknesses. This incident went further than any of that.

Using AI to write code and search for vulnerabilities has become common. But this incident went significantly further. In this case, an autonomous system coordinating up to eight AI agents carried out intrusions and decided what to do next without human intervention, effectively running a hacking campaign rather than merely assisting a human hacker.

The distinction matters because human-assisted attacks have a natural speed limit: you need people awake, making decisions, switching tactics. An autonomous system has no such limit. The attack framework implemented what the AI tools called "learning cycles": autonomous sessions where the models searched vulnerability databases, GitHub repositories, and other security research for specific techniques, CVEs, and common weaknesses to exploit in the targeted infrastructure. The system was, in effect, teaching itself how to break in while it was already inside.

How we know about it, and what we don't

This is where some caution is warranted. The primary source for most of what is publicly known is Dream, the Israeli cybersecurity firm that discovered the campaign. Dream has a commercial interest in demonstrating that AI-powered attacks are real and serious, because that is the market it sells into. That does not make its findings wrong, but it is worth noting.

Dream did not attribute the attack to a specific group, but researchers found Simplified Chinese in internal communications, suggesting a high probability that the operator was connected to China. Data recovered from the target was written in Traditional Chinese, commonly used on government websites in Taiwan, Hong Kong and Macau. Linguistic evidence is meaningful, but it is also relatively easy to plant.

Experts suspect the hackers are from China, but neither Taiwan nor Dream would confirm the origin of the July attacks. Taiwan's own Ministry of Digital Affairs confirmed the attacks happened and that affected agencies had responded, but the ministry did not disclose where the attacks originated.

In other words: the attack was real, the tools used were real, the data stolen was real. The attribution to China is plausible but unverified. Treat it as the leading hypothesis, not established fact.

The tools were free and publicly available

One of the more uncomfortable details is that Hermes and OpenClaw, the two AI agent frameworks at the heart of the attack, are open-source. Anyone can download them. The attackers did not build some exotic, classified system. They assembled an autonomous hacking platform from components that are freely available online, which suggests that the barrier to replicating this kind of attack is lower than many governments have been assuming.

The threat of AI-assisted hacking campaigns has been growing for years but ramped up dramatically over the past few months after top AI labs released models that can rapidly conduct reconnaissance, identify vulnerabilities, and take advantage of them. The Taiwan incident is, in that sense, the predictable consequence of capabilities that have been openly developing in public.

The scale of what Taiwan is already dealing with

It would be easy to read this as a story that is uniquely about Taiwan's geopolitical situation. But the technical shift it represents is not unique to any one target. Taiwan has in recent years complained about what it sees as China's "hybrid warfare," from daily military drills to disinformation campaigns and cyberattacks. Chinese cyberattacks on Taiwan's key infrastructure rose 6% in 2025 from the previous year to an average of 2.63 million attacks a day.

Now consider what happens when even a fraction of that volume becomes fully autonomous. Taiwan's National Security Bureau already logged an average of 2.6 million Chinese cyberattacks a day in 2025, up 6% year over year. If a meaningful fraction of that volume starts running with this kind of autonomy, the maths on defending against it gets a lot uglier very quickly.

The cost asymmetry problem

Perhaps the most important thing Dream's researchers identified is an economic one. "It spells out one thing loudly: the cost of running a competent attack has collapsed, but the cost of defending against one has not," a blog post by Dream said.

This is the structural problem that autonomous AI hacking creates. Mounting a sophisticated intrusion campaign used to require skilled people, time, and coordination. All three are expensive. An autonomous agent framework running on cloud compute changes that calculation significantly. Defenders, by contrast, still need human security engineers, and those engineers are in short supply and high demand everywhere. The attack side gets cheaper. The defence side does not, at least not yet.

What this doesn't mean

It is worth being clear about what is not being claimed here. This was not an AI acting on its own initiative to attack a government. There were human operators who chose the target, set the objective, and deployed the tools. The "autonomous" part refers to the execution: once set in motion, the agents made tactical decisions without being steered moment-to-moment. That is a significant step change, but it is not the science-fiction scenario of AI deciding to start a war.

It also should not be taken as proof that every government system is now trivially breakable by anyone with a laptop. The Taiwan attack succeeded partly because of specific misconfigurations and exposed interfaces that gave the agents footholds. Good basic security hygiene, patching, proper access controls, network segmentation, would have raised the difficulty considerably. AI agents amplify attacker capability; they do not magically bypass all defences.

What it does mean

What this incident does tell us is that the shift from "AI assists hackers" to "AI conducts the attack" has happened at least once, in the real world, against a real government. The tools used were not exotic. The operation ran for four days before being detected. And the data taken included exactly the kind of records, credentials, network maps, personnel files, that you would want if you were planning further intrusions.

The operation marks a sharp escalation in how artificial intelligence is reshaping cyber warfare and demonstrates that machine-driven intrusion can now operate with the coordination once reserved for human hacking teams.

Governments and organisations that have been treating autonomous AI hacking as a future problem are now behind the curve. Taiwan appears to have detected and contained this one. The next one may be harder to spot, and the attackers will have learnt from leaving a 160MB archive of evidence lying around.

From Telltale
Keep reading

If this one was useful, there's plenty more on the site. Pieces on how AI works, plus coverage of AI news, the downsides included. All free to read, no account needed.

See all articles →

References

  1. China-linked Hackers Using AI Agents to Attack Taiwan Government Websites, Cybersecurity News
  2. Hackers used autonomous AI agents to attack Taiwan. Is this the future of cyberwarfare?, CNN Business
  3. Chinese Hackers Used AI Agents to Hunt Taiwan Government Systems, Benzinga
  4. 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency, The Register
  5. China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan, Security Affairs
  6. Taiwan Says It Was Targeted Last Month in AI-Driven Hacking Campaign, US News & World Report
  7. Taiwan targeted in AI-driven hacking campaign, Taipei Times
Published August 2026 · telltale-ai.com
All articles · Privacy · Terms