started · updated
Taiwan government targeted by first autonomous AI-driven cyberattack
Israeli cybersecurity firm Dream has documented what is described as the first end-to-end autonomous cyberattack against a government target. The operation, which targeted Taiwan, utilized open-source AI agents, specifically Hermes and OpenClaw, to function like a coordinated hacking team.
During a four-day period in early July, the attack deployed up to eight autonomous agents simultaneously. These agents mapped 21 government systems, identified vulnerabilities, and independently altered tactics when blocked by defenders. The breach resulted in the compromise of at least 85 government user accounts and the theft of over 2,500 personnel records.
The campaign eventually expanded beyond general government systems to target Taiwan’s nuclear safety agency and at least seven energy companies. While Dream did not officially attribute the attack to a specific group, researchers noted that internal communications used Simplified Chinese, suggesting a potential connection to China. The incident highlights a shift toward AI-driven warfare where tools can independently choose targets and rank techniques with minimal human oversight.
Entities
Amir Becker · China · Dream · Hermès · Taiwan · Taiwan government
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 4 SOURCES] The AI agents mapped 21 government systems and searched for vulnerabilities. 4sysops.com · www.indyturk.com · securityaffairs.com · exame.com
- [● 4 SOURCES] Israeli firm Dream documented what researchers describe as the first end-to-end autonomous AI cyberattack against a government target. 4sysops.com · www.indyturk.com · securityaffairs.com · exame.com
- [● 3 SOURCES] The breach compromised at least 85 government user accounts. www.indyturk.com · securityaffairs.com · exame.com
- [● 4 SOURCES] The attack lasted four days in early July. 4sysops.com · www.indyturk.com · securityaffairs.com · exame.com
- [● 4 SOURCES] The operation utilized up to eight autonomous AI agents in parallel. 4sysops.com · www.indyturk.com · securityaffairs.com · exame.com
- [● 3 SOURCES] More than 2,500 personnel records were stolen during the attack. www.indyturk.com · securityaffairs.com · exame.com
- [● 4 SOURCES] The use of Simplified Chinese in internal communications suggests a connection to China. 4sysops.com · www.indyturk.com · securityaffairs.com · exame.com
- [● 4 SOURCES] The attack expanded to target Taiwan’s nuclear safety agency and at least seven energy companies. 4sysops.com · www.indyturk.com · securityaffairs.com · exame.com