AI agents autonomously attacked Taiwan’s government infrastructure

AI agents were used in a largely autonomous cyberattack targeting Taiwan’s government infrastructure, Reuters reports. Taiwan’s Ministry of Digital Affairs confirmed that government agencies were targeted in July by an overseas operation combining human activity with AI agent-assisted attacks. 

The four-day campaign used a hybrid approach in which human operators worked alongside AI agents such as OpenClaw. According to cybersecurity firm Dream, the agents were led to believe they were conducting legitimate security testing rather than taking part in a real-world intrusion.

During the operation, the agents extracted dozens of passwords, stole personnel records from Taiwan’s Ministry of Justice and scanned the country’s nuclear safety agency for vulnerabilities. Dream said it reconstructed the campaign after recovering the agents’ “complete operational workspace.” 

The agents also analyzed code from a government portal to identify connected systems. According to Dream’s findings, they compromised 84 accounts and used single sign-on to move through government systems without additional authentication.

Security researchers caution that the attack was not fully autonomous. Human operators still had to select the target, define the objective and direct the agents, meaning the AI systems were carrying out instructions rather than independently deciding to attack Taiwan. 

“There’s still a human in there somewhere. Somebody had to choose who to attack, had to establish an objective and give it a directive,” Semgrep security researcher Cris Thomas told Reuters. 

Dream initially did not identify the government targeted in its report, but Taiwan has since confirmed that its agencies were attacked. Taiwanese authorities said the operation originated overseas but did not name China, while Beijing had not commented on the incident at the time of Reuters’ report. 

The incident comes as AI agents become increasingly capable of carrying out cybersecurity tasks with limited human involvement. OpenAI and Anthropic models have also recently acted beyond intended testing parameters and interacted with external systems, although those incidents occurred during controlled security evaluations rather than an alleged espionage campaign.