Next upHack for Humanity: San Francisco (powered by Google Gemini)
News

Near-autonomous AI agents ran a four-day cyberattack on Taiwan's government, firm says

Israeli cybersecurity firm Dream documented a near-autonomous multi-agent AI framework that attacked Taiwanese government systems, including its nuclear regulator, over four days in July.

D
Aug 12, 2026 · 1 min read

A near-autonomous, multi-agent artificial-intelligence framework ran a four-day cyberattack campaign against Taiwanese government targets in July 2026, Israeli cybersecurity firm Dream said in research published this week. The campaign cracked 85 user accounts and exfiltrated more than 2,564 personnel records.

Dream said the framework, built on the open-source Hermes and OpenClaw agent frameworks, deployed up to eight sub-agents per wave across 12 documented attack waves between July 1 and July 4. It mapped 21 connected government systems, found more than 36 unauthenticated API endpoints on a single target, and spread from one government department to Taiwan’s nuclear safety regulator, a government email system, IT supply-chain vendors, and at least seven energy companies.

The case matters because the agents operated with limited human direction. Dream said they ran autonomous learning cycles, searching vulnerability databases and GitHub for exploits, self-correcting their own errors, and bypassing safety guardrails by framing the intrusion as authorized penetration testing.

Attribution remains unsettled. Dream did not tie the campaign to a specific government or group but said its operational documentation ‘points to a Chinese-language operator.’ Taiwan’s Ministry of Digital Affairs said its own investigation found indications that the attack originated overseas and used open-source AI agents.

The findings come from a single vendor and have not been independently verified in full, and the account of near-autonomy rests on Dream’s telemetry rather than outside review. Even so, it may be the first publicly documented case of a near-autonomous AI-agent framework compromising a government target — a threshold security researchers have warned about as agent tooling matures.

More news