Suspected China-linked hackers assembled an autonomous hacking tool from open-source AI agents, then used it to break into Taiwanese government websites, in what researchers call the first fully autonomous, end-to-end AI cyberattack on a government target.
The Financial Times reported the attack on Tuesday, citing Israeli cybersecurity firm Dream. Over four days in early July, the tool ran as many as eight AI agents at once, drawing on two open-source frameworks, Hermes and OpenClaw.
🇨🇳🇹🇼 Chinese hackers carried out the first fully autonomous AI cyberattack against a foreign government, targeting Taiwan
— Visegrád 24 (@visegrad24) August 12, 2026
Using open-source AI agents, the attackers independently conducted reconnaissance, searched for vulnerabilities, and adapted tactics over four days in early… pic.twitter.com/9guRsjFNP2
It surveyed 21 government networks for weaknesses and pivoted to new approaches on its own each time defenders shut down a route, without a human directing individual steps. Attackers also disguised the intrusion as an authorized security test to bypass the underlying AI models’ safety measures.
The hackers compromised at least 85 government accounts, pulled more than 2,500 personnel records, and later pushed into Taiwan’s nuclear safety agency and at least seven energy firms. Dream would not officially name the victim, citing company policy, but a person familiar with the matter told the Financial Times it was Taiwan.
The researchers pointed to the hackers’ internal communications, written in Simplified Chinese, while the stolen data itself came back in Traditional Chinese, the script also used by government sites in Hong Kong and Macau.
Amir Becker, Dream’s chief strategy officer and a former Unit 8200 cyber operations chief for Israel, said the degree of autonomy on display had no precedent against a government target, and argued organizations should now treat compromise as “the basic assumption of every government around the globe.”
Taiwan’s National Security Bureau reported an average of 2.6 million cyberattacks a day from mainland China in 2025, up 6% from the year before. Chinese authorities did not respond to requests for comment.
OpenAI, Meta and Anthropic have each separately reported instances of their models attempting unprompted cyberattacks during internal testing, and Anthropic disclosed in November that it disrupted a campaign it attributed with high confidence to a Chinese state-sponsored group manipulating its Claude Code tool.