Drooid Logo
Back to story perspectives

Full Breakdown

AI-Assisted Cyberattack Targets Taiwan’s Government Agencies

8/14/2026, 9:04:53 PM

The Attack Unfolds

In early July 2026, Taiwan’s Ministry of Digital Affairs (MDA) detected an “abnormal attack” against multiple government networks. Over four days the intrusion used up to eight open-source AI agents—Hermes and OpenClaw—to map 21 systems, crack 85 user accounts and exfiltrate more than 2,500 personnel records. The campaign later reached the nuclear safety agency, supply-chain vendors and at least seven energy companies. Affected bodies completed remediation, and the government issued new protective guidelines and strengthened monitoring.

Background & Context

Taiwan has warned that China’s “hybrid warfare” blends drills, disinformation and cyber operations. The National Security Bureau reported Chinese-origin attacks on critical infrastructure rose 6 % in 2025, averaging 2.63 million attempts per day. The July incident is the first publicly documented case where autonomous AI agents coordinated an end-to-end breach of a sovereign government’s digital infrastructure.

Timeline

  • July 1–4 – Twelve attack waves launch, with AI sub-agents assigned to distinct targets.
  • July 20 – MDA’s monitoring units flag the activity; the National Institute of Cyber Security issues alerts.
  • July 29 – Israeli firm Dream releases a technical blog describing a 160 MB archive of 1,395 files.
  • August 12 – The Financial Times and Dream disclose the breach, identifying Taiwan as the victim and noting open-source AI agents.
  • August 13 – Taiwan’s MDA confirms the investigation, states the attacks originated overseas, and announces updated defenses.

Data & Statistics

Official Statements & Responses

The ministry said all affected units have completed handling and that new guidelines now require early-stage detection and layered defenses.

Dream, the Israeli cybersecurity firm that uncovered the operation, declined to name the targeted government but confirmed the tool was built from publicly available AI frameworks and that internal communications were written in Simplified Chinese, suggesting a high probability of a China-linked operator.

China’s Taiwan Affairs Office did not respond to requests for comment.

Criticism & Opposition

Security-industry analysts caution against overstating the tool’s autonomy. Kevin Surace, CEO of TokenCore, described the incident as “near-autonomous rather than completely independent,” emphasizing that human operators still selected targets and set overall objectives.

Conflicting Reports & Gaps

Sources differ on the degree of automation. Some outlets label the breach “fully autonomous,” while Dream’s analysis calls it “near-autonomous,” noting a capable operator directed the mission. Record counts vary slightly (2,500 vs. 2,564). Attribution remains unconfirmed; the only concrete indicator is the use of Simplified Chinese in attackers’ notes, which analysts interpret as a probable link to mainland China but stop short of naming a specific group.

The episode highlights a shifting threat landscape where readily available AI tools can compress weeks of reconnaissance into minutes, enabling large-scale, low-cost intrusions against high-value government targets. Taiwan’s response—enhanced monitoring, protective guidelines, and public acknowledgment of AI-derived threats—illustrates the emerging need for governments worldwide to prepare for autonomous AI-driven cyber operations.