AI Agents Hacked Taiwan on Their Own. Experts Say It Changes Cyberwarfare

AI Agents Hacked Taiwan on Their Own. Experts Say It Changes Cyberwarfare


Hackers used a team of autonomous artificial intelligence agents to infiltrate Taiwanese government systems, compromise dozens of accounts and steal thousands of personnel records, in what cybersecurity experts believe could be the first publicly disclosed fully autonomous cyberattack against government agencies.

The operation, carried out over four days in July, targeted government agencies, critical infrastructure and technology suppliers across Taiwan, according to Taiwanese officials and Israeli cybersecurity company Dream, which discovered the campaign. The AI system mapped 21 government systems, compromised 85 government user accounts and extracted approximately 2,500 personnel records, Dream said.

But what has cybersecurity experts particularly concerned is not simply what the hackers stole. It is how little human involvement may have been required to do it. The attackers assembled an autonomous system capable of coordinating as many as eight AI agents. Those agents performed reconnaissance, attempted to obtain credentials, searched for vulnerabilities, and determined what attack strategies to pursue next, according to Dream.

Rather than serving as a tool controlled step by step by a hacker, the AI effectively operated as its own hacking team.”Like a human team, when an approach gets blocked, it researches new techniques in real time and adapts. It’s an attacker that strategizes, learns, and adjusts on its own,” Amir Becker, Dream’s chief business and strategy officer, told CNN.

The incident marks a potentially significant shift in the rapidly evolving relationship between AI and cybersecurity. Hackers already routinely use generative AI to help write malicious code, research vulnerabilities, or accelerate individual parts of an attack. The Taiwan operation went further by allowing AI agents to coordinate multiple stages of an intrusion and make decisions without continuous human direction.

Taiwan’s Ministry of Digital Affairs said its investigation found evidence that the operation originated overseas and combined traditional hacking methods with AI agents, including OpenClaw. The ministry has previously warned that agentic AI tools such as OpenClaw can connect to external networks, alter computer settings and install software, capabilities that also create substantial security risks when abused.

Dream said the implications extend well beyond Taiwan. “It spells out one thing loudly: the cost of running a competent attack has collapsed, but the cost of defending against one has not,” the company said.

The attackers also targeted Taiwan’s nuclear safety agency, government IT vendors and at least seven companies in the energy sector, according to the report. AI allowed the operation to rapidly combine different hacking techniques and exploit weaknesses in secondary systems, increasing both its speed and scale.

Taiwanese authorities and Dream have not publicly attributed the attack to China. However, experts said the discovery of simplified Chinese in internal documents associated with the operation points to a possible Chinese connection. CNN said it contacted China’s Ministry of Foreign Affairs, Taiwan Affairs Office and Cyberspace Administration for comment.

Taiwan has long faced intense cyber pressure amid its confrontation with Beijing, which claims the self-governed island as its territory. Taiwanese officials have increasingly described cyberattacks, disinformation and military activity as components of China’s broader “hybrid warfare” campaign.

Taiwan recorded an average of 2.6 million cyberattacks from China per day last year, according to government figures cited by CNN, a 6% increase from 2024. The July operation, however, introduces another concern: autonomous AI could dramatically lower the resources required to conduct sophisticated attacks.

Kenny Huang, chairman of the Taiwan Network Information Center, told CNN the incident demonstrates that AI is moving beyond its role as an assistant to human hackers and becoming an active participant in cyber operations.

Dream itself develops AI-based cybersecurity systems, including technology designed to autonomously identify vulnerabilities and coordinate multi-agent operations for defensive purposes. The same underlying capabilities, however, illustrate the emerging arms race between autonomous AI attackers and AI-powered defenses.

For Huang, the Taiwan attack exposes how quickly that race is advancing. “I believe there are still significant gaps,” he told CNN. “Every country, not just Taiwan, is still unprepared in this respect.”



Source link

Posted in

Amelia Frost

Leave a Comment