In the past few hours the Ministry of Digital Affairs of Taiwan, through the National Institute of Cyber Security, confirmed that in July several government agencies came under attack, with alerts issued around 20th of the month. The campaign combined manual intrusion and artificial intelligence agentssoftware that aims at an objective and then reasons and acts largely on its own. In four days the attackers took away dozens of passwords and personnel files Ministry of Justiceand probed the Nuclear Safety Agency for vulnerabilities.
The confirmation comes after the report of Dreaman Israeli cybersecurity company, which had described an AI-led campaign against an unnamed Asian government, later identified as Taiwan by the Financial Times. According to that reconstruction the operation involved up to eight autonomous agents in parallelwhich they mapped 21 government systems before compromising at least 85 accounts. They would have been extracted from the same systems over 2,500 staff files.
Source: Dream
The activity then expanded to the Taiwanese Nuclear Safety Agency, at least seven energy companiesto government suppliers and other government systems. The detailed figures come from Dream’s work alone and are not reflected in the official communication, which remains general. The two reconstructions do not coincide regarding the placement in the month: the report places the four days at the beginning of July, while the government alerts began around the 20th.
Two open source systems, downloadable by anyone
The evidence emerged from an online archive of 160 megabytes surfaced while monitoring hostile actors, with 1,395 files. From those files it appears that the tool was built on two open source agent systems, Hermes And OpenClawboth freely downloadable and designed to let language models perform multi-step tasks without supervision. The Taiwanese ministry cited OpenClaw as an example of the observed agentic approach.
Which model powered the agents has not been determined. However, the data indicates that the model’s protections were bypassed by presenting the intrusion as a authorized penetration test rather than as an actual attack. Neither of the two members was born for the offense: the operators have assembled a capable tool from parts that any developer can download and put to work.
The most striking feature, for researchers, is the ability to devise attacks on your own instead of following a pre-planned path. The platform continuously evaluated the available information, ordered possible attack paths and he reprioritized them as circumstances changed. When a technique failed, he tasked another agent with searching online for the information needed to develop an alternative.
How much autonomy, and who is behind it
Dream presents the case as the first observed end-to-end autonomous cyber attack against a government. The Taiwanese reconstruction is more cautious and describes a mixed campaign, where manual labor relied on the assistance of agents. “There’s still a human out there somewhere,” one security researcher noted of the campaign, “it’s not totally 100% autonomous.” The difference weighs heavily: the agents compressed the time of an operation that the operators still conducted, and in the past such a large scale required an expert team to work for weeks.
On the origin, Dream indicates hackers suspected of links to the China. The Taipei authorities stopped short: they indicated a foreign origin without naming anyone responsible, and no group was identified. The communication comes amid persistent tensions between Taiwan and China, although the elements made public do not make the connection.
The ministry claims that the affected units have “gradually completed the management” and that “the sources of the attack, the methods and the extent of the impact have been fully ascertained”. Taipei says it has intensified monitoring and issued protection guidance to all agencies.

