World First: A Nation Paralysed by AI Hack Without Human Assistance
The cyber threat is intensifying in the era of increasingly sophisticated artificial intelligence (AI) technology. Hackers are reported to have deployed autonomous AI systems to attack Taiwan. Experts consider this action to be the world’s first fully autonomous attack targeting government institutions.
Dream, an Israel-based AI cybersecurity company, revealed startling facts. In just four days last July, the AI agents were able to map 21 government systems, breach 85 user accounts, and steal 2,500 personnel records.
Although Taiwan and Dream declined to publicly disclose the origin of the hackers, experts believe Beijing is behind the attack.
“The investigation found strong indications that the attack originated from abroad and used a hybrid method—combining conventional operations with the assistance of AI agents such as OpenClaw,” Taiwan’s Ministry of Digital Affairs stated in an official release.
A report from the Financial Times disclosed that the hackers built a system based on open-source AI agents to automate the entire infiltration process, from reconnaissance and credential theft to determining the strategy for the next attack path.
The use of AI to write code or find security vulnerabilities is already common. However, the incident in Taiwan is considered a significant leap forward.
The autonomous system, which coordinated up to eight AI agents, was able to carry out infiltration and make independent decisions without human intervention. The AI acted like an independent team of hackers.
“This underscores one thing. The cost of launching a capable cyberattack has now plummeted, but the cost of defending against it has not,” Dream wrote in an official blog post.
Dream’s Chief Business and Strategy Officer, Amir Becker, highlighted the danger of the AI system’s adaptability.
“When one path is blocked, the system immediately researches new techniques in real time and adapts. This is an attacker that can strategise, learn, and adjust on its own,” Becker said.
Not only government institutions and the justice ministry, the chain attack also extended to Taiwan’s Nuclear Safety Commission, government IT vendors, and at least seven companies in the energy sector.
Experts identified the use of Simplified Chinese in the internal hacking documents. This strengthens the suspicion that the mastermind behind the action is strongly connected to China.
When asked for confirmation, a spokesperson for China’s Ministry of Foreign Affairs repeatedly claimed to have no knowledge of the situation.
Cyber threats from Beijing are not new to Taiwan. Last year, the island of 23 million people was hit by an average of 2.6 million cyberattacks per day from China—up 6% compared to the previous period.
Chairman of the Taiwan Network Information Center, Kenny Huang, asserted that the July incident is clear evidence that AI has shifted from being merely a tool to becoming a key player in cyber warfare.
“Every country, not just Taiwan, is still unprepared to face this threat. There remains a very large gap in global AI defence strategies, both in terms of regulation, technical capability, and policy,” Huang concluded.