Adversary Intelligence — 2026-08-13
China-Linked Hackers Deploy Eight Autonomous AI Agents to Breach Taiwan Government Networks
BLUFOpen-source AI agent frameworks used in this campaign will likely proliferate to additional state actors within 90 days, making autonomous intrusion toolkits a persistent feature of cross-strait cyber operations.
Israeli cybersecurity firm Dream reported that suspected China-linked hackers ran an autonomous AI hacking toolkit against Taiwanese government networks over four days in early July, deploying up to eight AI agents simultaneously to map 21 systems, compromise at least 85 government accounts, and extract more than 2,500 personnel records 12. The operation, built on the open-source Hermes and OpenClaw frameworks and later expanded to a nuclear safety agency, a government email system, and at least seven energy companies, bypassed the underlying model's safety guardrails by framing the campaign as an authorized penetration test, according to Dream 12. Taiwan's Ministry of Digital Affairs confirmed on Wednesday that its monitoring units detected an "abnormal attack" on government agencies beginning July 20, describing a hybrid approach combining manual operations with AI agent-assisted attacks including OpenClaw, without naming China as the source 34. Security researcher Cris Thomas of Semgrep, cited by Reuters, said a human operator still selected targets and set objectives, cautioning against describing the campaign as fully autonomous 3.
AnalysisTaiwan's Ministry of Digital Affairs will
likely name China as the source of the July AI-agent campaign within 90 days, moving from its current "overseas source" language toward explicit attribution as findings from Dream's reconstructed toolkit converge with the ministry's own investigation. This judgment carries high confidence, reflecting the ministry's confirmation of the incident days after Dream's disclosure and the consistency of technical details across both accounts. Formal attribution would push Taipei to treat autonomous AI-agent intrusions as a standing category of Chinese hybrid warfare rather than an isolated event, prompting agencies to institutionalize AI-specific detection. The open-source Hermes and OpenClaw frameworks lower the barrier for replication, widening the exposure Taipei must plan against beyond this single campaign.
4 sources
- China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan - Security Affairs
- Researchers observe first 'near-autonomous' AI attack on government target in Taiwan - CyberScoop
- Taiwan says it was targeted last month in AI-driven hacking campaign - Reuters
- AI-driven hacking campaign targets Taiwan government agencies - Taipei Times
View in full brief →