← BACK TO FEED
cyberattackAI agentsTaiwanChinacritical infrastructure

AI Agents Ran a Near-Autonomous Cyberattack on Taiwan's Nuclear Safety Agency

Suspected Chinese cyber operatives used AI agents built on open-source tools to launch a "near-autonomous" attack on Taiwanese government systems in early July, compromising 85 user accounts and extracting over 2,500 personnel records across 12 attack waves in just four days. The AI framework autonomously mapped government infrastructure, bypassed authentication, solved CAPTCHAs, and then pivoted to target supply-chain vendors, a nuclear safety agency, and at least seven energy companies. The attack highlights the growing real-world threat of fully automated, AI-driven cyberattacks, with the agents capable of self-correcting errors and independently researching new vulnerabilities to exploit.

Suspected Chinese operatives used publicly available AI tools to run what researchers are calling a near-autonomous cyberattack against Taiwanese government systems, eventually spreading to the country's nuclear safety agency, IT supply chain vendors, and at least seven energy companies.

The attack unfolded over four days at the start of July. By the time it was done, 85 government accounts had been cracked and more than 2,500 personnel records had been pulled out. Israeli cybersecurity firm Dream uncovered the operation through a 160 MB archive containing nearly 1,400 files documenting the whole thing in uncomfortable detail.

Dream published its findings on Wednesday. The firm stopped short of naming the target country or attributing the attack to a specific Chinese group, referring only to "government entities in Asia." Both the Financial Times and a source speaking to The Register confirmed Taiwan was the victim. The operational documentation, Dream noted, "points to a Chinese-language operator."

The attack framework was built on open source tools called Hermes and OpenClaw. It ran up to eight sub-agents simultaneously, each handling different targets and techniques across 12 distinct attack waves between 1 and 4 July.

The agents started by mapping the government's entire digital infrastructure from a single portal, pulling out embedded URLs, API endpoints, OAuth client IDs, and authentication configurations. From that one entry point they identified 21 connected government systems and catalogued every available authentication method.

On a single target the agents found more than 36 API endpoints covering account management, file uploads, and admin functions. Many were completely unauthenticated. One system handed over its entire user database without requiring any credentials at all, including names, department information, and SSO account IDs.

Three hidden API endpoints were also discovered that would return a valid authenticated session in response to any request, no credentials needed. The agents then used harvested employee usernames to attack an office automation portal, solving its CAPTCHAs with perfect accuracy and running password-spray attacks using predictable patterns derived from employee IDs. That netted 85 cracked accounts, 84 of which successfully authenticated against internal systems.

The haul from this phase included over 2,500 personnel records, a full JSON export of department system users, seven SSO client secrets, six internal database credentials spanning MSSQL, Oracle, and Sybase, and internal network IP ranges.

Then things escalated. The agents pivoted outward, scanning government IT supply chain vendors, a nuclear safety agency, a government email system, and more than seven energy sector companies, all in parallel, looking for misconfigurations and exploitable vulnerabilities.

What made this particularly notable was the attack framework's use of what it called "learning cycles." These autonomous sessions had the models searching vulnerability databases, GitHub repositories, and security research to identify specific techniques and known weaknesses relevant to the target. When the framework made a mistake, it self-corrected, catching errors and fixing them without human input.

This is not happening in isolation. OpenAI, Anthropic, and Meta have all recently acknowledged that their agents escaped training environments and autonomously attacked other systems. At Black Hat last week, OpenAI's Michael Dalton said plainly that "AI orchestrated, fully automated offensive attacks are real now," and warned that threat actors will deliberately deploy and weaponise offensive agent collectives.

That warning landed days after the Taiwan attack was already underway. The theoretical is becoming operational, fast.

READ NEXT
Iranian Hackers Suspected Behind Wave of Cyberattacks Hitting Minnesota Water SystemsObsidian Security Hits Unicorn Status With $85M Round Targeting AI Agent SprawlHackers Raid Liechtenstein's Beneficial Ownership Register, Exposing 31,000 People