Taiwan’s Ministry of Digital Affairs has officially confirmed the AI-driven cyberattack on government systems uncovered in July and declared the investigation complete. New is the confirmation that employee data from the Ministry of Justice was also stolen. The agency classifies the attack as a hybrid approach, in which humans only used AI agents as support.
Digital Ministry names Ministry of Justice as another target of the attack
Taiwan’s National Institute of Cyber Security announced, according to a statement from the ministry, that it had issued initial warnings about an “abnormal attack” on government agencies starting July 20, after internal monitoring systems had registered unusual access patterns. The agency now states that the sources, methods, and extent of the attack have been fully investigated, and affected parties have completed their assessments. New is the confirmation that the attackers, in addition to the nuclear safety authority, also stole personnel data from employees of the Ministry of Justice and intercepted passwords of several previously unidentified officials, as reported by Reuters. These details complement the original report on the attack, which initially only named the nuclear safety authority and seven energy providers as affected. The ministry continues to refrain from attributing the attack to a specific country, merely referring to sources from abroad. The security service provider Dream, on the other hand, reportedly did not want to present the stolen datasets or officially confirm the target country when the news agency inquired; only the Financial Times identified the target agencies as Taiwanese based on its own research.
Government classifies attack as hybrid and strengthens protective measures
Unlike the initial assessment by Dream and the Financial Times, which spoke of a largely autonomous attack, Taiwan’s government now describes the campaign as a hybrid approach. Human attackers reportedly used the AI agent software OpenClaw in a targeted supportive role, rather than allowing the entire operation to run independently. The current government confirmation thus bridges the gap between external security analysis and official classification that had remained after the initial reporting in July. According to the Taipei Times, Taiwan has issued new protective guidelines in response and strengthened system monitoring in all ministries to detect similar attacks earlier in the future. Cyberattacks on Taiwan’s digital infrastructure increased by six percent in 2025, according to authorities, to an average of 2.63 million attacks per day. In this context, the government classifies the AI-driven attack as part of a growing series of hybrid threats, which also include military exercises and disinformation campaigns—a pattern that Taiwan has associated with China for years, without Beijing being officially held responsible.
It remains open whether Taiwan has since closed the vulnerability in the authentication service that allowed access to the nuclear safety authority and energy providers. It will also be crucial whether cyber insurers will consider the reclassification as a hybrid rather than fully autonomous attack for future coverage questions and whether the government will eventually abandon its reluctance to name a responsible state.


