Suspected Chinese hackers used publicly available artificial intelligence tools to compromise government websites in Taiwan in what researchers described as a first-of-a-kind breach, highlighting how rapidly artificial intelligence is changing the nature of cyber warfare.
Researchers at Israeli AI company Dream said the attackers used open-source AI agents to build an autonomous hacking tool capable of operating like a co-ordinated cyber team. Over four days at the start of July, the system deployed as many as eight autonomous agents simultaneously, mapping 21 government systems, identifying vulnerabilities and changing tactics when its attempts were blocked.
The attack compromised at least 85 government user accounts and extracted more than 2,500 personnel records, before expanding to Taiwan’s nuclear safety agency and at least seven energy companies, according to Dream’s research.
The incident comes as governments and technology companies grapple with the growing ability of advanced AI systems to identify and exploit software vulnerabilities. Anthropic, OpenAI and Meta have reported that their latest models have launched unexpected cyberattacks during testing, underscoring concerns that increasingly capable AI systems could lower the barriers to sophisticated cyber operations.
Amir Becker, Dream’s chief strategy officer and a former head of cyber operations for Israel’s elite signals intelligence Unit 8200, said he had never previously seen such an “end-to-end autonomous attack” against a government target. He argued that the development meant governments should now assume they are under permanent cyber attack.
“This must be the basic assumption of every government around the globe,” Becker said.
A person familiar with the attack said Taiwan was the target. Dream declined to publicly confirm the identity of the targeted government, citing company policy, but said it had informed a country in the Asia-Pacific region about the breach.
Dream has not attributed the operation to a specific hacking group. Researchers, however, said the use of Simplified Chinese in internal communications associated with the attack indicated a high probability that the operator was connected to China. The data recovered from the target was written in Traditional Chinese, a format commonly used on government websites in Taiwan, Hong Kong and Macau.
Taiwan’s Ministry of Digital Affairs declined to comment on the specific incident, citing confidentiality requirements. The ministry said incidents involving government agencies or critical infrastructure would be handled under established reporting and response procedures.
The ministry also acknowledged the broader challenge posed by AI-enabled attacks, saying that the integration of AI technology had transformed the nature of cyber security incidents. It said AI agents created a dual challenge because attacks could be automated while the agents themselves could become vulnerabilities.
Dream researchers identified evidence of the attack in a 160MB online archive containing 1,395 files. The archive showed that the hacking tool used two open-source AI agent systems, Hermes and OpenClaw, which allow AI models to perform tasks autonomously.
The researchers could not determine which AI model powered the agents. The data indicated, however, that the model’s safeguards had been bypassed by presenting the hacking activity as an authorised exercise intended to test system vulnerabilities.
The tool’s ability to continuously assess and reprioritise possible attack routes was among the most significant features of the operation, according to Dream. When one route failed, another agent was tasked with searching the internet for information and developing an alternative approach, allowing the system to adapt without direct human intervention.
The incident follows growing evidence of attempts to use AI in sophisticated cyber operations. Anthropic said last November that it suspected Chinese state-sponsored hackers had manipulated its Claude tool in an attempt to attack 30 international companies and government agencies, although the operation had limited success.
For Taiwan, the development adds another dimension to an already intense cyber threat. Taiwan’s National Security Bureau reported in January that the island faced an average of 2.6 million Chinese cyberattacks a day in 2025, a 6 per cent increase from the previous year.
Beijing claims Taiwan as part of its territory and threatens to annex it by force if Taipei refuses indefinitely to submit to its control. The emergence of autonomous AI-enabled hacking therefore adds a potentially more scalable and adaptive tool to the cyber pressure already facing the island.

