In the shadow of rising tensions across the Taiwan Strait, a quiet intrusion last month exposed a new chapter in state-linked cyber operations. Suspected Chinese hackers deployed a swarm of artificial intelligence agents to strike Taiwanese government systems. The operation ran with striking independence. Over just four days in early July it mapped networks, hunted weaknesses, breached accounts and exfiltrated data before shifting targets.
Israeli cybersecurity firm Dream first spotted the campaign. Researchers there uncovered a 160-megabyte online archive packed with 1,395 files that documented the entire effort. The files revealed how eight open-source AI frameworks, among them Hermes and OpenClaw, powered an autonomous hacking platform. This tool behaved less like a scripted script and more like a coordinated team of operators adapting on the fly.
The Financial Times broke the story on August 12, 2026. Its reporting drew directly from Dream’s analysis. The attackers compromised 85 government accounts. They stole records on more than 2,500 personnel. Then the system expanded. It reached Taiwan’s nuclear safety agency and at least seven energy companies. One vulnerability surfaced inside the nuclear regulator itself.
But the most unsettling detail sits in plain sight. The entire hacking framework relied on publicly available code. No custom malware. No proprietary exploits. Just off-the-shelf AI models stitched together and pointed at a strategic adversary. Hackers framed prompts as routine “cyber readiness tests” to slip past model guardrails. The agents listened. They proceeded.
Dream’s researchers stopped short of naming a specific group. Yet clues pointed one direction. Internal notes and operator communications appeared in Simplified Chinese, the script used on the mainland. Stolen data, by contrast, showed Traditional Chinese characters common in Taiwan. That code-switching, Dream concluded, carried a high probability of Chinese origin.
Taiwan’s Ministry of Digital Affairs responded the next day. In a statement carried by Reuters, officials confirmed detection of an “abnormal attack” on government agencies last month. The activity bore “clear characteristics of an overseas source.” Warnings began flowing from the National Institute of Cyber Security on July 20. Affected bodies handled the incident. New protective guidelines followed. Monitoring intensified.
The ministry described a hybrid campaign. Human operators set targets and oversaw infrastructure. AI agents handled reconnaissance, vulnerability research, credential attacks and tactical adjustments. One example cited: Open Claw. The approach combined manual direction with automated persistence. “There’s still a human in there somewhere,” a researcher told The Guardian. A capable operator remained in charge.
Technical logs painted a picture of relentless iteration. The system launched learning cycles. It scoured vulnerability databases, GitHub repositories and security publications tailored to Taiwanese infrastructure. When one path stalled, subagents ranked alternatives, researched fixes and tried again. Bayesian prioritization guided choices. Self-correction loops fixed mistakes mid-operation. Parallel agents spread activity across addresses and sessions to avoid easy detection.
Nothing exotic turned up in the exploited flaws. Exposed development endpoints. An API that accepted tokens with signature checks disabled. Unauthenticated data interfaces. Passwords derived from employee ID numbers. Familiar identity and access mistakes. Yet the sequencing told a different story. The same accounts moved from system to system, chaining access, retesting weaknesses, pivoting to fresh routes. Conventional scanners rarely exhibit such fluid coordination.
Collin Hogue-Spears, senior director at Black Duck, reviewed Dream’s findings. “The agents ran the intrusion end to end and invented nothing new to run it with,” he said in coverage by TechRadar. “Dream Research Labs documented up to eight subagents working concurrently across twelve waves, ranking attack paths, redirecting when a technique failed, and researching alternatives online before trying again.”
Amir Becker, Dream’s chief strategy officer, delivered a blunt warning. “This must be the basic assumption of every government around the globe.” The remark, quoted across multiple outlets, underscored a shift. AI agents now scale complex operations once reserved for skilled teams. They lower the bar. They accelerate pace. And because the building blocks sit on public repositories, replication costs almost nothing.
Security analysts have watched AI enter cyber operations for years. Early uses focused on phishing email generation or basic reconnaissance. This incident crosses a threshold. The platform conducted end-to-end compromise with limited human tweaking. It adapted. It expanded scope from government websites to critical infrastructure suppliers and nuclear oversight. All while logs still resembled routine security scans.
Dream discovered the archive during routine monitoring of criminal cyber activity. The materials included not only logs but also the framework itself. That openness changes the threat calculus. State actors or even well-resourced criminal groups can download similar models, fine-tune prompts and launch comparable campaigns. Attribution grows harder when tools carry no unique fingerprints.
Taiwan has long braced for digital pressure from Beijing. Its National Security Bureau reported 2.5 million suspected Chinese cyberattacks per day in 2025. Most remain noisy and detectable. This one operated with greater sophistication and autonomy. The hybrid model lets humans retain strategic control while delegating tactical execution to software that learns in real time.
Experts note the absence of zero-days. Success hinged on basic hygiene failures. Yet that reality offers little comfort. The speed and parallelism of eight concurrent agents overwhelmed thresholds built for single human operators. Route diversity per source, per session, per account suddenly matters more than raw request volume. Re-authentication at single sign-on boundaries becomes essential. Unsigned tokens must be rejected outright.
Recent coverage reinforces the urgency. CyberScoop described the effort as “near-autonomous,” highlighting how the framework corrected errors and expanded to email systems, supply chain vendors and energy firms. CNN examined whether such operations signal the future of cyber warfare. Both outlets stressed the role of open-source components in democratizing advanced tactics.
The timing adds geopolitical weight. Cross-strait friction has intensified. Beijing considers Taiwan a breakaway province. Taipei asserts its separate democratic identity. Cyber intrusions serve as constant reminders of vulnerability without triggering kinetic escalation. An AI-driven campaign that hits nuclear safety and energy targets fits neatly into gray-zone pressure strategies.
Still, limitations remain visible. The system required initial human setup. Guardrails had to be circumvented through clever framing. Complete autonomy has not arrived. But the gap is closing. As large language models grow more capable and agent frameworks mature, the need for constant human steering may shrink further.
Defenders face a dilemma. Blocking every open-source AI model is impossible. Monitoring for anomalous chaining across systems demands new analytics. Organizations must assume that tomorrow’s intrusions will blend human intent with machine persistence. The archive Dream found sits as both warning and instruction manual.
Taiwan’s response signals awareness. Enhanced monitoring and fresh guidelines aim to raise the bar. Yet the broader lesson travels far beyond one island. Governments worldwide now confront tools that anyone with modest technical skill can assemble from public sources. The barrier to entry for sophisticated, adaptive cyber operations has dropped.
What happened in July marks an observed milestone rather than an isolated curiosity. Future campaigns will likely build on these techniques. They may incorporate newer models. They could target different sectors or nations. The code is already loose. The agents are already learning. And the next archive may prove even harder to find before damage spreads.
Security teams that once tuned alerts for lone attackers must recalibrate for parallel, self-improving swarms. Network defenders will study sequence patterns over isolated events. Policy makers will weigh how openly shared AI research accelerates both innovation and predation. The line between research tool and weapon has blurred. This time the target was Taiwan. Next time it could be anywhere.