Indo-Pacific — 2026-08-13

China-Linked Hackers Deploy First Fully Autonomous AI Cyberattack Against Taiwan Government Compromising 85 Accounts and Reaching Nuclear Safety Agency

BLUFCrossing the autonomous AI threshold in state-linked cyber operations renders human-paced network defense architectures structurally inadequate, and the guardrail bypass exploited here remains trivially reproducible.

Israeli cybersecurity firm Dream reported that suspected China-linked hackers ran an end-to-end autonomous AI hacking operation against Taiwanese government systems over four days and 12 attack waves in early July, deploying up to eight AI agents built on the open-source Hermes and OpenClaw frameworks that mapped 21 government systems and switched attack tactics without human intervention 12. The Financial Times, which first reported the research, said the operators bypassed the underlying AI models' safety guardrails by framing the campaign as an authorized penetration test 1. Dream said the operation compromised at least 85 government accounts and extracted more than 2,500 personnel records, then expanded to government IT supply chain vendors, a nuclear safety agency, a government email system, and at least seven energy-sector companies 123. Researchers said they uncovered the campaign in a 160-megabyte online archive of roughly 1,395 files whose Chinese-language operator documentation underpinned the suspected China link 23. Dream did not officially name the targeted government, but a person familiar with the matter told the Financial Times it was Taiwan, and Taiwan's Ministry of Digital Affairs said only that incidents involving government agencies follow established response procedures 1.

Analysis
Autonomous AI tooling now runs government-network intrusions end to end, mapping targets, prioritizing paths, and pivoting on failure without sustained human direction. It outpaces detection postures built for human-paced intrusion sets; expansion from initial account compromises into a nuclear safety agency and multiple energy firms shows the tooling scales targeting decisions faster than responders can contain them. The guardrail bypass, achieved by simply framing the campaign as an authorized penetration test, exposes a systemic weakness in how commercial AI models validate operator intent rather than a one-off jailbreak. Attribution to a state actor rests on circumstantial linguistic evidence inside the toolkit, and the same Chinese-language tooling is equally consistent with a criminal group or contractor rather than a tasked state operation. Reporting traces to a single Dream Security research post, amplified without independent verification.
5 sources
  1. China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan - Security Affairs
  2. Researchers observe first 'near-autonomous' AI attack on government target in Taiwan - CyberScoop
  3. 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency - The Register
  4. Suspected China-linked hackers used AI to run the first-ever end-to-end autonomous cyberattack on Taiwan's government, Israeli firm says - Tom's Hardware
  5. Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia - Dream Security (Dream Research Labs)

View in full brief →

UNCLASSIFIED // OPEN SOURCE