According to the Financial Times, in early July, China-linked hackers attacked Taiwan by tasking AI agents with finding vulnerabilities in 21 government systems, coordinating their actions and changing tactics whenever an attempt failed. Researchers at the Israeli AI company Dream discovered traces of the operation and determined that the tool could deploy up to eight agents at the same time.
Over four days, the system compromised, among other targets, Taiwan’s nuclear safety agency and at least seven energy companies.
The agents independently divided up tasks and constantly reassessed potential attack paths based on the information they received. If one method of gaining access failed, the system deployed another agent, which searched the internet for additional information and developed a new approach.
Read also: North Korean Hackers Use AI in Cyberattacks
The tool used two open-source AI agent systems — Hermes and OpenClaw. The model powering them has not been identified, but researchers know that its safeguards were bypassed by presenting malicious actions as an authorized vulnerability assessment.
Dream did not attribute the attack to any specific hacker group. Researchers found Simplified Chinese in the internal communications, which, in their assessment, points to a high likelihood that the operator was connected to China.
Taiwan’s Ministry of Digital Affairs reported that the attack originated from overseas but did not publicly link it to China. The ministry described the incident as a new type of threat in which AI agents both automate attacks and become an additional source of cybersecurity risks.
After discovering the incident, Taiwanese authorities stepped up monitoring of government systems and developed additional security measures.
