In a significant breach, suspected Chinese cyber operatives utilized publicly available AI tools to infiltrate Taiwanese government systems, subsequently extending their attack to the nuclear safety agency and multiple energy companies. This operation has been characterized by security researchers as a “near-autonomous attack.”
Over the first four days of July, the attackers compromised 85 government user accounts and extracted over 2,500 personnel records, as reported by Dream, an Israeli cybersecurity firm. The firm disclosed its findings in a research paper published on August 12, 2026, detailing the intrusions and confirming Taiwan as the target.
Details of the Attack
Although Dream did not directly attribute the attack to the Chinese government or a specific hacking group, the operational documentation suggested involvement of a Chinese-language operator. The attack framework employed open-source AI agents, Hermes and OpenClaw, deploying up to eight sub-agents across 12 distinct attack waves from July 1 to July 4.
The initial phase involved mapping the government ecosystem, where agents extracted critical data such as embedded URLs and API endpoints from a government portal. This mapping revealed 21 connected government systems and various authentication flows. Notably, one system exposed its entire user database without any authentication, allowing the attackers to access thousands of employee records.
Exploitation of Vulnerabilities
Following the mapping, the agents identified multiple entry points, including three hidden API endpoints that accepted requests without user credentials. Using harvested usernames, the agents accessed a government department’s automation portal, bypassing CAPTCHAs with complete accuracy. They successfully cracked 85 accounts through various password-spray techniques, gaining access to internal systems that included dashboards and personnel statistics.
The breach allowed the extraction of extensive government information, including over 2,564 personnel records and internal database credentials across multiple platforms.
Expansion of the Attack
The operation escalated as the agents targeted the Taiwanese government’s supply chain, including IT vendors, the nuclear safety agency, and over seven energy sector companies. The AI framework utilized “learning cycles” to autonomously search for vulnerabilities and exploit weaknesses in the targeted infrastructure.
Dream’s research indicates that the AI tools were capable of self-correction, identifying and rectifying errors during the attack process. This incident highlights the growing sophistication of cyber threats involving AI, as acknowledged by experts from leading AI firms who noted that fully automated offensive attacks are becoming a reality.
Implications for Cybersecurity
This near-autonomous attack underscores the urgent need for enhanced cybersecurity measures, particularly in critical sectors such as nuclear safety and energy. As AI technologies evolve, the potential for their misuse in cyber warfare raises significant concerns for national security and regulatory frameworks.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.
Original source: theregister.com








