mimile
Back to feed

Dream: AI agents compromise 85 Taiwan government accounts in four-day attack

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Dream: AI agents compromise 85 Taiwan government accounts in four-day attack

AI agents compromise at least 85 Taiwanese government accounts and steal more than 2,500 personnel records during a four-day campaign in July, according to cybersecurity firm Dream. The operation uses up to eight autonomous sub-agents in 12 attack waves and expands to Taiwan's nuclear safety agency and more than half a dozen energy companies. Taiwan's Ministry of Digital Affairs confirms the attack targeted its infrastructure.

Key Facts

  • The attack framework was built on open-source Hermes and OpenClaw AI agents and deployed up to eight sub-agents.
  • Taiwan's Ministry of Digital Affairs confirmed the autonomous attack targeted its infrastructure after Dream did not name the target.
  • The campaign expanded beyond government systems to Taiwan's nuclear safety agency and more than half a dozen energy companies.
  • In May, researchers documented an AI agent carrying out an end-to-end attack in less than an hour, harvesting cloud credentials and destroying an internal database.
  • Researchers later reported what they described as the first fully agentic ransomware attack, with an AI agent that could adapt, fix errors, and recover on its own.

Attack Structure

Researchers at cybersecurity firm Dream uncovered a four-day campaign in July that targeted multiple Taiwanese government agencies. The attack framework was built on open-source Hermes and OpenClaw AI agents and deployed up to eight sub-agents. Each sub-agent was assigned its own targets and attack techniques, carrying out 12 attack waves between July 1 and July 4. The agents worked through network reconnaissance, vulnerability discovery, exploitation, and data collection while adapting tactics with minimal human input.

Targets and Impact

The campaign compromised at least 85 government accounts and extracted more than 2,500 personnel records. The operation expanded beyond government systems, pivoting to Taiwan's nuclear safety agency and more than half a dozen energy companies. Although Dream did not explicitly name the target, Taiwan's Ministry of Digital Affairs subsequently confirmed the autonomous attack targeted its infrastructure. Dream wrote that the campaign shows the cost of running a competent attack has collapsed while the cost of defending against one has not.

AI Offensive Operations

The Taiwan operation is the latest in a growing number of AI-enabled offensive operations documented by researchers. In May, researchers documented an AI agent carrying out an end-to-end attack in less than an hour, moving from exploiting a vulnerability to harvesting cloud credentials and destroying an internal database. A couple of months later, researchers reported what they described as the first fully agentic ransomware attack. The AI agent used in that attack could adapt, fix errors, and recover on its own when something went wrong. Traditional automated attacks often halt when a command fails, unlike the adaptive agent observed in the ransomware case.

1 source

Dream: AI agents compromise 85 Taiwan government accounts in four-day attack