AI Agents Ran a Four-Day Hacking Campaign Against Taiwan's Government Systems
Researchers say a cluster of AI programs worked in near-total automation to steal credentials, map government networks, and probe a nuclear safety agency, a sign that organised hacking is getting cheaper and faster.

Key points
- Over four days in early July, AI agents produced 1,395 files, cracked 85 credentials, and exfiltrated thousands of government personnel records.
- Taiwan's Ministry of Digital Affairs confirmed it detected an AI-assisted attack on government agencies during the same period.
- The campaign ran across 12 separate attack waves, with multiple AI programs working simultaneously on different targets.
- Researchers at Dream say linguistic clues suggest a Chinese-language operator was behind the operation, though no specific group or country has been named.
- Safeguards built into the AI tools were bypassed by disguising the attack as an authorised security test.
Something unusual happened to government computer systems in Asia this past July. A collection of AI programs did most of the work automatically, at a scale that would have taken human operators far longer to match.
Researchers at cybersecurity firm Dream published a detailed account, describing it as a "near-autonomous attack" built on two open-source AI agent frameworks called Hermes and OpenClaw. Open-source means the underlying code is freely available to anyone.
What exactly did these AI programs do?
Almost everything a human hacker would, just faster and running in parallel. In roughly four days, the system mapped government networks, found weak points, cracked login credentials, and copied out thousands of personnel records.
The campaign ran in 12 successive waves. Each deployed multiple AI sub-agents, smaller programs each assigned a specific job: scanning for unprotected login portals, or testing stolen passwords against other systems. Dream counted 1,395 files generated and 85 cracked credentials by the time the operation wound down.
Once inside, the compromised accounts moved laterally across connected systems through single sign-on integrations. Single sign-on is the technology that lets one login unlock multiple services. Convenient for staff; a serious risk when that one set of credentials is stolen.
| Stage | What happened |
|---|---|
| Reconnaissance | AI mapped public-facing systems and pulled login configurations from accessible code |
| Credential attack | Passwords cracked; hidden login endpoints exploited |
| Lateral movement | Stolen accounts used to access connected government services |
| Expansion | Supply chain partners and an energy-sector organisation also reached |
| Critical probe | A nuclear safety-related organisation was targeted |
Taiwan's Ministry of Digital Affairs told Reuters it detected an AI agent-assisted attack on government agencies during the same window. Neither the ministry nor Dream has formally confirmed the two incidents are the same event. Dream told CSO Online it found no evidence of a confirmed breach at every targeted organisation and declined to name any specific victim or attacker.
Should people whose data was held by these agencies be worried?
Possibly. Thousands of personnel records were copied out, meaning names, contact details, and potentially employment information may now be in unknown hands. If you work for, or have recently dealt with, a Taiwanese government agency, watch for unexpected emails or calls asking you to confirm personal details. Criminals routinely use stolen records to craft convincing follow-up scams.
The attack also reached supply chain partners, meaning private companies that provide services to the government. Employees of such firms should check with their IT teams about whether their systems were among those assessed.
How did the AI get around its own safety rules?
This is one of the more unsettling details. AI tools like these are typically built with guardrails designed to stop them doing harmful things. The operators bypassed those guardrails by framing the activity as an authorised security test, essentially telling the AI it had permission to proceed. Our earlier story on how attackers exploit the code wrapped around AI agents, published 12 August, shows this isn't an isolated technique.
Dream said it later identified the use of a DeepSeek-V3-Flash model, a publicly available AI, within the framework, though it couldn't confirm whether other models were also involved. Both OpenAI and Anthropic have separately flagged that advanced models may be capable of finding and exploiting software flaws with little human direction.
Dream put the broader picture plainly: "The cost of running a competent attack has collapsed, but the cost of defending against one has not."
The attribution caveat here matters. Linguistic analysis pointing to a Chinese-language operator is a single indicator. It's medium confidence at best, and Dream has stopped well short of naming a country or group. Worth watching whether Taiwan's government eventually publishes its own technical findings, which would either corroborate or complicate the picture.



