Autonomous AI agents ran a four-day breach of Taiwan's government, pivoting to its nuclear safety regulator
Suspected China-linked operators wired together two open-source frameworks, Hermes and OpenClaw, into a near-autonomous hacking platform that mapped 21 systems, cracked 85 accounts, and exfiltrated 2,500 personnel records before expanding to seven energy companies — surfaced only when Israeli firm Dream found a 160 MB archive left exposed online.
Over the first 4 days of July, a coordinated fleet of up to 8 AI agents worked its way through 21 Taiwanese government systems, cracked 85 user accounts, and pulled more than 2,500 personnel records before pivoting to the island’s nuclear safety agency, unnamed government IT vendors, and at least 7 energy-sector companies. The operators weren’t watching in real time. They didn’t need to.
The platform was assembled from two publicly available open-source agent frameworks, Hermes and OpenClaw, stitched together and jailbroken by the oldest trick in the prompt-engineering playbook: framing the activity as authorized penetration testing. Israeli cybersecurity firm Dream reconstructed the campaign after stumbling on a 160 MB archive of 1,395 intrusion-documentation files that the operators had left carelessly exposed online.
What the archive documented reads less like a hack and more like an audit. Dream’s write-up describes “Learning Cycles” in which agents autonomously trawled vulnerability databases, GitHub repositories, and security research for techniques applicable to the target. On a single system, they enumerated more than 36 API endpoints and flagged 3 that returned valid authenticated sessions for any request body. They solved CAPTCHAs at 100 percent accuracy. They cracked accounts by guessing passwords keyed to employee IDs. The haul included 7 SSO client secrets, 6 database credentials spanning MSSQL, Oracle, and Sybase, and a full JSON export of one department’s user table.
Attribution is circumstantial but heavy. Internal tooling comms were in Simplified Chinese; the exfiltrated data was in Traditional Chinese, a script used almost exclusively by government systems in Taiwan, Hong Kong, and Macau. On August 13, Taiwan’s Ministry of Digital Affairs confirmed it had “found clear indications that the attacks originated overseas and involved a hybrid approach in which hackers combined conventional operations with AI agents such as OpenClaw.” China’s Ministry of Foreign Affairs said it wasn’t familiar with the situation.
Kenny Huang, chairman of the Taiwan Network Information Center, called it the first disclosed case of a fully automated attack against a government. Amir Becker, Dream’s chief strategy officer and former head of the Israel Defense Forces’ cyberoperations and signals intelligence division, told governments they should “assume that they face a permanent cyberattack.”
The tools were free. The guardrails were a sentence of prompt. The target was a nuclear regulator.
Sources
- https://www.ft.com/content/ai-agents-taiwan-autonomous-cyberattack-dream-august-2026
- https://cyberscoop.com/near-autonomous-ai-attack-government-target-taiwan/
- https://www.theregister.com/security/2026/08/12/near-autonomous-ai-agents-attack-taiwans-nuclear-safety-agency/5287055
- https://www.cnn.com/2026/08/13/tech/china-taiwan-ai-agent-cyberattack-intl-hnk
- https://www.taipeitimes.com/News/editorials/archives/2026/08/21/2003862850
— END —