AI agents have been pitched as digital coworkers: software that can research, plan, use tools and finish complicated tasks without someone constantly watching over them.
Taiwan just got a much darker demonstration of the same idea.
Hackers used an AI-powered system to attack Taiwanese government infrastructure during a four-day campaign in July 2026. The system could map networks, hunt for weaknesses, attack accounts and change its strategy when something didn’t work.
According to Israeli cybersecurity company Dream, which discovered the operation, the AI agents mapped 21 government systems, compromised 85 government user accounts and extracted more than 2,500 personnel records.
That alone would make this a serious breach.
What makes it different is who — or rather, what — was doing much of the work.
The AI Wasn’t Just Helping the Hackers
AI has been part of the cybersecurity arms race for years. Attackers can use models to write phishing emails, inspect code, research targets or automate repetitive tasks.
This operation appears to have gone considerably further.
Taiwan’s Ministry of Digital Affairs said its investigation found signs that the attacks originated overseas and used a hybrid approach combining conventional hacking with AI agents, including OpenClaw.
Dream’s researchers said the attackers built their system from open-source AI-agent technology. Multiple agents could work simultaneously, handling reconnaissance, credential attacks and decisions about where to attack next.
The important part is the decision-making.
When one route was blocked, the system could research alternatives and adjust its approach. Instead of an AI waiting for a hacker to issue every command, it behaved more like members of a hacking team pursuing an objective.
That distinction matters.
The Attack Spread Beyond Government Accounts
The campaign reportedly didn’t stop after breaking into government systems.
According to reports based on Dream’s findings, the attackers expanded their activity to Taiwan’s nuclear safety agency, government IT vendors and at least seven companies in the energy sector.
Taiwan said affected agencies had completed their response after cybersecurity monitoring detected the activity in July. The National Institute for Cyber Security began issuing alerts on July 20.
The attack shows one of the uncomfortable advantages AI gives cybercriminals and state-backed operators: scale.
An autonomous system doesn’t need to sleep. It can examine systems in parallel, test different approaches and process what it discovers faster than a traditional team working manually.
The economics of hacking start to look different when software can do a large chunk of the labor.
Was China Behind the Attack?
There is an important caveat here.
Taiwan has not publicly attributed this specific attack to China, and Dream has not formally named a Chinese hacking group as responsible.
Researchers did, however, discover internal communications associated with the operation written in Simplified Chinese, which is predominantly used in mainland China. That evidence has led researchers and experts to suspect a China connection.
It isn’t proof by itself.
The wider context is hard to ignore, though.
Taiwan’s National Security Bureau said Chinese cyberattacks against critical infrastructure reached an average of roughly 2.63 million attacks per day in 2025, about 6% higher than the previous year.
Cyber operations have become part of the much broader pressure surrounding Taiwan, alongside military activity and information warfare.
AI adds another layer to that contest.
We’ve Already Seen Where This Can Go
The Taiwan incident didn’t arrive from nowhere.
Anthropic previously disclosed a cyber-espionage campaign it assessed with high confidence was conducted by a Chinese state-sponsored group it designated GTG-1002. The attackers manipulated Claude Code as part of an automated attack framework targeting roughly 30 organizations.
Anthropic estimated AI performed around 80% to 90% of tactical operations, with humans stepping in mainly at critical decision points. The AI was used for reconnaissance, vulnerability discovery, exploitation, credential harvesting, lateral movement and data analysis.
That case already showed that AI could move from being a hacker’s assistant toward becoming part of the attack infrastructure itself.
Taiwan pushes the idea into uncomfortable territory again.
You don’t necessarily need a huge room full of skilled operators if a smaller group can deploy agents that search, test, adapt and attack simultaneously.
Autonomous Doesn’t Mean Humans Have Disappeared
Calling these attacks “autonomous” can make them sound almost science-fictional — an AI waking up one morning and deciding to hack a government.
That’s not what happened.
Humans still chose the target. Humans established the objective. Humans deployed the technology.
Security researchers have cautioned against overstating how independent these systems really are. There is still a human somewhere in the chain deciding what the operation is supposed to accomplish.
But requiring humans at the beginning and at a handful of important checkpoints is very different from requiring humans to manually execute thousands of individual actions.
That’s where the shift is happening.
Cyber Defense Now Has a Speed Problem
Traditional cybersecurity assumes attackers need time.
They scan. They investigate. They try something. It fails. They research another method. Then they try again.
AI agents can compress parts of that cycle.
They can also operate against several targets at once.
That creates a nasty asymmetry. Organizations may still depend on human security teams to investigate alerts, approve patches and coordinate responses while an attacking system can continuously probe for another opening.
Taiwan’s Ministry of Digital Affairs said AI agents can rapidly combine different attack techniques and exploit secondary systems, making operations faster, cheaper and easier to scale. The government says it has introduced guidelines addressing emerging AI-related cybersecurity threats and is strengthening monitoring and defenses.
Other governments and companies will be watching closely.
They probably should be.
AI Agents Just Found Another Job
The AI-agent boom has mostly been discussed around productivity.
Book the trip. Analyze the spreadsheet. Write the code. Search the web. Handle the repetitive work.
The same architecture doesn’t care whether the objective is helpful.
Give an agent access to cybersecurity tools, enough autonomy and a malicious goal, and the productivity gain belongs to the attacker instead.
The Taiwan operation is significant not because AI suddenly invented hacking. It didn’t.
It’s significant because tasks that once demanded constant human attention can increasingly be delegated to software capable of making decisions while the operation is already underway.
That means the next cybersecurity race may not simply be hackers versus defenders.
It could be attacking agents versus defensive agents, both operating at machine speed while humans supervise from further up the chain.
That future sounded theoretical not long ago.
It doesn’t anymore.
Sources
- CNN — “Hackers used autonomous AI agents to attack Taiwan. Is this the future of cyberwarfare?”
- Taipei Times — “Taiwan targeted in AI-driven hacking campaign”
- Financial Times — “China-linked hackers hit Taiwan in unprecedented ‘autonomous’ AI cyber attack”
- Anthropic — “Disrupting the first reported AI-orchestrated cyber espionage campaign”

