Security

Taiwan confirms AI cyber attack: Justice Ministry also affected

2 min read

TL;DR Too Long; Didn’t read

Taiwan's Ministry of Digital Affairs has declared the investigation into the AI-driven cyber attack from July 2026 to be completed on August 13. It has been newly confirmed that personal data from the Justice Ministry was also stolen. The agency classifies the attack as a hybrid approach, not as a fully autonomous AI action. It still does not officially attribute the attack to a state.

A red official stamp presses down on a map of Taiwan out of which a mechanical spider leg protrudes, next to it a small scale symbolizing justice Image generated with GPT Image 2

Key takeaways

  • Taiwan's Digital Ministry declares the investigation into the July cyber attack completed on August 13.
  • Newly confirmed: Personal data and passwords from the Justice Ministry were also stolen.
  • The government officially classifies the attack as hybrid, not as fully autonomous AI action.
  • The National Institute of Cyber Security had already warned about the campaign starting July 20.
  • Cyber attacks on Taiwan increased by six percent in 2025 to 2.63 million daily.
  • An official attribution of the attack to a state is still pending.

Taiwan’s Ministry of Digital Affairs has officially confirmed the AI-driven cyberattack on government systems uncovered in July and declared the investigation complete. New is the confirmation that employee data from the Ministry of Justice was also stolen. The agency classifies the attack as a hybrid approach, in which humans only used AI agents as support.

Digital Ministry names Ministry of Justice as another target of the attack

Taiwan’s National Institute of Cyber Security announced, according to a statement from the ministry, that it had issued initial warnings about an “abnormal attack” on government agencies starting July 20, after internal monitoring systems had registered unusual access patterns. The agency now states that the sources, methods, and extent of the attack have been fully investigated, and affected parties have completed their assessments. New is the confirmation that the attackers, in addition to the nuclear safety authority, also stole personnel data from employees of the Ministry of Justice and intercepted passwords of several previously unidentified officials, as reported by Reuters. These details complement the original report on the attack, which initially only named the nuclear safety authority and seven energy providers as affected. The ministry continues to refrain from attributing the attack to a specific country, merely referring to sources from abroad. The security service provider Dream, on the other hand, reportedly did not want to present the stolen datasets or officially confirm the target country when the news agency inquired; only the Financial Times identified the target agencies as Taiwanese based on its own research.

Government classifies attack as hybrid and strengthens protective measures

Unlike the initial assessment by Dream and the Financial Times, which spoke of a largely autonomous attack, Taiwan’s government now describes the campaign as a hybrid approach. Human attackers reportedly used the AI agent software OpenClaw in a targeted supportive role, rather than allowing the entire operation to run independently. The current government confirmation thus bridges the gap between external security analysis and official classification that had remained after the initial reporting in July. According to the Taipei Times, Taiwan has issued new protective guidelines in response and strengthened system monitoring in all ministries to detect similar attacks earlier in the future. Cyberattacks on Taiwan’s digital infrastructure increased by six percent in 2025, according to authorities, to an average of 2.63 million attacks per day. In this context, the government classifies the AI-driven attack as part of a growing series of hybrid threats, which also include military exercises and disinformation campaigns—a pattern that Taiwan has associated with China for years, without Beijing being officially held responsible.

It remains open whether Taiwan has since closed the vulnerability in the authentication service that allowed access to the nuclear safety authority and energy providers. It will also be crucial whether cyber insurers will consider the reclassification as a hybrid rather than fully autonomous attack for future coverage questions and whether the government will eventually abandon its reluctance to name a responsible state.

Frequently asked questions

What has changed in the assessment of the attack since the first report?

Taiwan's government now officially classifies the attack as a hybrid approach, where humans supported the AI agent software, rather than as a largely autonomous operation, as initially described by Dream and the Financial Times.

What new targets has Taiwan additionally confirmed?

Personal data of employees from the Justice Ministry as well as passwords of several previously unidentified officials, in addition to the already known nuclear safety authority and the seven energy suppliers.

Has Taiwan officially attributed the attack to China?

No, the government only speaks of sources from abroad and does not officially name a country, although security researchers had previously found indications of China.

What protective measures has Taiwan implemented since the attack?

According to Taipei Times, the government has issued new protective guidelines and strengthened system monitoring in all ministries to detect similar attacks earlier in the future.

Has the exploited security vulnerability in the authentication service been closed yet?

Publicly available information on this is still lacking, and the government statement does not comment on the technical status of the vulnerability.

Sources (3)
  1. Taiwan says it was targeted last month in AI-driven hacking campaign (Reuters)
  2. AI-driven hacking campaign targets Taiwan government agencies (Taipei Times)
  3. China-linked hackers hit Taiwan in unprecedented 'autonomous' AI cyber attack (Financial Times)

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog