Taiwan’s Ministry of Digital Affairs (MODA) confirmed that government systems and critical national infrastructure were targeted in a cyberattack. Investigated by Israeli AI security firm Dream, the campaign marks one of the first documented real-world intrusions where hackers leveraged open-source AI agents to run near-autonomous, multi-wave hacking operations.
1. How the AI-Driven Attack Unfolded
The attackers did not rely purely on manual exploitation. Instead, they deployed an automated framework built on open-source agentic platforms—including Hermes and OpenClaw—powered in part by the DeepSeek-V4-Flash model.

- Multi-Agent Coordination: The system deployed up to eight sub-agents operating in parallel across 12 distinct attack waves.
- Autonomous Decision Loops: Rather than following a rigid script, the AI agents ran planning loops—analyzing output, pivoting when defenses blocked an attack path, and trying alternative exploitation methods autonomously.
- Bypassing AI Safety Guardrails: Operators bypassed the underlying AI model’s safety restrictions by framing the malicious commands as authorized penetration testing.
In a statement, the Ministry of Digital Affairs said its cybersecurity monitoring units detected the “abnormal attack” targeting government agencies in July, and beginning July 20, its National Institute of Cyber Security issued a series of warning alerts while it investigated, reuters added.
The investigation results showed the attacks displayed clear characteristics of an “overseas source”, with hackers employing a hybrid approach that combined manual operations with AI agent-assisted attacks, such as Open Claw, it said. “The relevant attack sources, methods, and scope of impact have all been fully investigated, and the affected units have successively completed their handling,” the ministry added.
2. Attack Progression & Tactics
1. API Reconnaissance: Agents searched publicly exposed endpoints and code repositories to extract authentication configurations and valid employee directory data.
2. Identity Compromise: Using harvested usernames, the sub-agents ran automated, low-and-slow password spraying and solved CAPTCHA challenges via optical character recognition to compromise user accounts.
3. Exploitation & Persistence: Agents discovered flaws in government authentication services, bypassed API token checks, and automatically installed backdoors on vulnerable web applications.
3. Scope of Impact
Over roughly four days of activity, the automated campaign achieved significant reach across Taiwanese state bodies and energy providers:
- 21 Connected Systems Mapped: Fully cataloged across government networks.
- 85 Accounts Compromised: Credential sets cracked and harvested.
- 2,500+ Personnel Records Exfiltrated: Sensitive internal government directory files extracted.
- Pivot to Critical Infrastructure: The campaign expanded to probe Taiwan’s Nuclear Safety Council and at least seven energy companies before being contained by security operations teams.
4. Attribution & Industry Reaction
- China Connection: While Taiwanese officials refrained from formally naming a specific nation-state, cybersecurity researchers noted that internal developer documentation and agent-command logs were written in Simplified Chinese.
- “Near-Autonomous” Human-in-the-Loop: Security experts emphasized that while the AI executed the operational phases (reconnaissance, lateral movement, script generation) at unprecedented speed, human operators still defined the mission objectives and initial targets.
- Government Response: Taiwan’s National Institute for Cyber Security issued threat alerts on July 20, 2026. MODA confirmed that all affected agencies completed incident response procedures and launched new protective guidelines to counter AI-derived threats.