TAIPEI (Taiwan News) — The Ministry of Digital Affairs confirmed Thursday that foreign hackers used AI tools to attack government systems in July.
The operation may be the first known end-to-end autonomous cyberattack against a government target, according to the Financial Times, which broke the story Wednesday. It said “suspected Chinese hackers” may have been responsible.
In response, the ministry said its cybersecurity units detected the hack, investigated its impact, and responded according to established procedures. It said “overseas sources” were responsible but did not point the finger at China.
The Financial Times quoted researchers at Israeli AI company Dream as saying the use of simplified Chinese in internal communications suggested the operator was linked to China. However, the data taken from the targets of the attack was written in traditional Chinese, which is used in Taiwan, Hong Kong, and Macao.
The hackers reportedly used the open-source agent systems Hermes and OpenClaw. They chose the target and established the mission, while AI handled much of the reconnaissance, testing, and coordination.
The tool was said to have deployed as many as eight agents at once during a four-day operation in early July. It mapped 21 government systems and worked through attack paths with limited human direction.
The operation compromised at least 85 government user accounts, Dream said. It also extracted more than 2,500 personnel records, then targeted the nation’s nuclear safety agency and at least seven energy companies.
Dream reportedly found evidence of the attack in a 160-megabyte online archive. The archive contained 1,395 files showing how the hacking tool operated.
The Financial Times quoted the Ministry of Digital Affairs as saying, “AI agents have brought new dual challenges to network security defense: the attacks are automated, and AI agents themselves become new vulnerabilities.”
In January, the National Security Bureau said Taiwan’s critical infrastructure faced an average of 2.63 million Chinese cyberattack attempts every day in 2025. The figure was 6% higher than the previous year, with energy, emergency response, health, and communications systems among the targets.





