Autonomous AI Hacking Campaign Targets Taiwan Government Systems

Autonomous AI Hacking Campaign Targets Taiwan Government Systems

Israeli cybersecurity firm Dream has documented what it describes as the first fully autonomous, end to end AI driven hacking operation targeting a government. According to a report by the Financial Times, the attack took place over four days at the beginning of July and was allegedly carried out by suspected Chinese hackers using a toolkit built entirely from publicly available AI agents. Rather than relying on a single script or manually controlled malware, the attackers deployed multiple autonomous AI agents that independently mapped government infrastructure, searched for vulnerabilities, adapted to changing conditions, and modified their tactics whenever they encountered obstacles. Researchers said the campaign demonstrated a new level of automation that closely resembled the work of a coordinated team of human hackers.

Dream found that the attack involved as many as eight autonomous AI agents operating simultaneously, each assigned to different tasks throughout the intrusion. During the campaign, the system mapped 21 government networks, compromised at least 85 government accounts, extracted more than 2,500 personnel records, and expanded its activity to include a nuclear safety agency along with at least seven energy companies. Amir Becker, Chief Strategy Officer at Dream and a former cyber operations member of Israel Unit 8200, said he had never witnessed this level of autonomous decision making being used against a government target. Becker stated that governments should now assume they are operating in an environment of permanent compromise because AI driven attacks are becoming increasingly capable of carrying out sophisticated operations without continuous human direction. While Dream has not officially identified the targeted government because of company policy, a person familiar with the investigation told the Financial Times that the victim was Taiwan. Supporting evidence included internal communications related to the hacking toolkit written in Simplified Chinese, while the stolen government data was stored in Traditional Chinese, a writing system commonly used by government organizations in Taiwan, Hong Kong, and Macau. Taiwan Ministry of Digital Affairs did not confirm the reported breach and only stated that incidents involving government agencies are managed through established response procedures.

Researchers noted that the campaign differed significantly from recent laboratory incidents involving AI models from Anthropic, OpenAI, and Meta, where experimental systems unexpectedly carried out unauthorized actions during controlled security testing. In this case, the AI toolkit was intentionally assembled for offensive cyber operations. Dream discovered the toolkit inside a 160 MB archive containing 1,395 files built around two open source AI agent frameworks known as Hermes and OpenClaw. Both frameworks are freely available and designed to enable AI models to autonomously perform real world tasks. Investigators also found that the operators bypassed the AI model safety controls by presenting the entire operation as an authorized penetration test. Since the AI system had no reliable way to verify whether that claim was legitimate, it continued executing the requested tasks. Researchers described this as a weakness in how AI systems interpret instructions rather than a software vulnerability within the model itself.

Dream also highlighted the toolkit ability to continuously evaluate, rank, and reprioritize attack paths based on newly discovered information. When one method failed, the system automatically launched another AI agent to search the internet, gather additional intelligence, and develop alternative approaches without requiring direct human involvement. Researchers said this closely mirrored the workflow of experienced human penetration testers, except the AI agents were able to operate continuously without interruption. According to Taiwan National Security Bureau, government systems experienced an average of 2.6 million cyberattacks every day during 2025, representing a six percent increase compared with the previous year. Security experts warned that if even a portion of those attacks begin using highly autonomous AI capabilities similar to those observed by Dream, defending critical government infrastructure will become significantly more challenging due to the speed, scale, and adaptability of these operations.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment