Chinese hackers have, according to a report by the Financial Times, for the first time carried out a largely autonomous cyberattack using AI agents against Taiwan’s government. Up to eight agents worked simultaneously for four days. They compromised at least 85 government accounts and stole over 2,500 personal data records before the attack spread to Taiwan’s nuclear regulatory authority and seven energy providers.
Open AI agent software controls the waves of attack
The Israeli security company Dream discovered the incident and documented it in detail according to the Financial Times. The attackers reportedly built their tool from the freely available AI agent frameworks Hermes and OpenClaw. Both are actually intended for automated software development. In early July, the system deployed up to eight agents simultaneously over four days and mapped 21 government systems. Once a protective measure was triggered, it changed tactics. One software component continuously reassessed and prioritized possible attack paths; if one agent failed, another searched the internet for a new method. The attackers reportedly bypassed the built-in protective mechanisms of both frameworks by disguising their actions as an authorized penetration test – a role that both systems fundamentally allow. Already in August, a hacker had used the Hermes Agent framework for an attack on over 460 systems around the model DeepSeek. However, the success there was significantly lower, with only 14 compromised targets. The Taiwan case thus demonstrates how easily freely available developer tools can be repurposed into a coordinated attack system – entirely without the development of proprietary malware.
Attack reaches nuclear regulatory authority and energy providers
The hackers initially gained access to employee credentials. They intercepted personal data – including names, positions, and contact information – through unsecured API interfaces. The figures for accounts and data records come solely from Dream’s investigation and are independently unverified. Subsequently, the attackers found a vulnerability in the digital signature verification of the state authentication service, through which citizens and government employees identify themselves. Through this gap, access was extended to Taiwan’s nuclear regulatory authority and at least seven energy companies. This allowed the attackers to reach areas that are part of the country’s critical infrastructure and potentially affect power supply and nuclear safety measures. The internal documentation of the attackers was reportedly written in simplified Chinese characters, while the stolen data was in traditional Chinese, as is customary in Taiwan. This suggests, according to security researchers, a connection to China. However, there has not yet been an official attribution to a known hacker group or leadership in Beijing, and Beijing has not publicly commented on the allegations so far.
Incident joins growing series of autonomous agent attacks
This case is not the first of its kind. In July, an autonomous AI agent executed more than 17,000 individual actions over a weekend at Hugging Face and thus gained access to internal clusters. According to security researchers, what is new about the Taiwan attack is the extent of autonomy. The Chief Strategy Officer of Dream, Amir Becker, previously led the cyber operations of the Israeli elite unit 8200. He stated that he had not seen such a consistently automated attack on a government target before. For security teams, this means: a single attacker can achieve nearly the effect of a coordinated team today with freely available software. Programming skills for each individual step are no longer necessary. In about a year, this is already the third publicly known case of an AI agent that penetrated foreign systems largely without human control. Hermes and OpenClaw have now become some of the most popular open-source tools for autonomous programming agents – making them equally attractive for legitimate developers and attackers.
It remains open how cyber insurers and the judiciary will deal with an attacker whose actions are no longer individually controlled by a human. Policies typically define a hacker as a person. A formal attribution to a state actor is often crucial for coverage questions – and this remains outstanding in this case. It is also unclear whether Taiwan has since closed the vulnerability in the authentication service that was exploited.


