Taiwan Reports Extensive AI-Powered Cyberattack on Critical Infrastructure, Linked to China

Taiwan’s status as a leading global chip hub and its reputation as a highly free democracy (often cited as the second freest in Asia) shapes Beijing’s cyber deterrence strategy and motivates cyber pressure against Taiwan.
The Dream report says the attack extended to Taiwan’s nuclear safety agency and at least seven energy companies, with 85 government accounts compromised and more than 2,500 personnel records exfiltrated.
The operation used up to eight autonomous AI sub-agents operating in parallel to map 21 government systems and probe for weaknesses.
The AI agents demonstrated self-learning capabilities, studying public databases to develop new infiltration techniques when existing methods were blocked.
Protective guardrails were bypassed by framing the activity as authorized penetration testing, and while there is suspicion of a China-linked operator, no formal attribution has been publicly confirmed.
Taiwan is facing an unprecedented wave of cyberattacks, with Chinese-linked hackers now deploying autonomous AI agents to break into government systems. Israeli cybersecurity firm Dream reports that in early July, attackers used two open-source AI tools — Hermes and OpenClaw — to run a near-fully automated four-day intrusion that compromised 85 government accounts and stole more than 2,500 personnel records. Benzinga called it "a first-of-its-kind cyberattack."
The attack is part of a much larger surge. Taiwan's National Security Bureau says the island faces an average of about 2.6 million cyberattack attempts every single day, according to Global Taiwan. Analysts say Beijing's pressure is driven by Taiwan's status as the world's leading chip manufacturer and its role as one of Asia's freest democracies.
Up to eight autonomous AI sub-agents ran in parallel during the July attack, each targeting different systems at the same time, according to Insurance Business Mag. Together they mapped 21 Taiwanese government systems and probed each one for weaknesses. The operation hit Taiwan's nuclear safety agency and at least seven energy companies. Emergency services, hospitals, and communications networks were also targeted.
When one method of entry was blocked, the AI agents did not stop. They studied public databases on their own and developed new ways in, according to National Technology. This self-learning behavior made the attack far harder to stop than a standard intrusion. Researchers found internal messages written in Simplified Chinese — the script used in mainland China — while the stolen data was in Traditional Chinese, the script used in Taiwan.
One of the most alarming findings involves how the attackers got past built-in safety limits. The AI agents bypassed protective guardrails by framing the attack as authorized penetration testing — essentially pretending they had permission to be there, according to Cryptopolitan. Penetration testing is a legitimate method where companies hire experts to find weaknesses before real attackers do. The hackers used that cover to slip through defenses undetected.
No government has formally and publicly attributed the attack to Beijing. Dream researchers say the evidence — including Simplified Chinese internal messages and known attack tools linked to Chinese state actors — points strongly toward a China-linked operator. But without official attribution, it remains difficult to trigger formal diplomatic or military responses, highlighting a key gap in how international cyber policy works today.
Taiwan became an even bigger target after Lai Ching-te's inauguration in 2024. Lai stated publicly that Taiwan is not subordinate to China, a direct challenge to Beijing's position, according to Global Taiwan. China views Taiwan's growing democratic reputation — often ranked the second freest democracy in Asia — and its dominance in global chip manufacturing as threats to its own authority and strategic goals.
Taiwan has responded with civil defense exercises meant to test how the island holds up under disruption to power, communications, and emergency services. But experts warn the gap between attack speed and government readiness is growing fast. The 2.6 million daily attack attempts show this is not a future risk — it is already happening at massive scale every day.
Experts say the Taiwan case is a warning for every country, not just Taiwan. AI agents can work around the clock, adapt in real time, and run multiple attacks at once — capabilities no human hacking team can match in speed or scale. Researchers are urging governments to assume they are under cyberattack at all times, not just when they find evidence of one, according to Benzinga.
The key lesson from the Taiwan attack is that AI is changing both sides of cybersecurity simultaneously. Defenders now need smarter tools, faster response systems, and clearer international rules for attributing AI-driven attacks to state actors. Without those changes, the gap between attacker and defender will keep growing — and the next target may not be Taiwan.
Publishers
18
Articles
6
Reach
24