Taiwan reports that AI agents played a role in hacking its government within a span of four days.

Taiwan reports that AI agents played a role in hacking its government within a span of four days.

      Taiwan reported that it spent part of last month countering a hacking campaign that utilized artificial intelligence for its operations. The Ministry of Digital Affairs, through its National Institute of Cyber Security, revealed that government agencies were targeted in July, with alerts issued starting around July 20.

      What makes this incident significant is not just the breach itself, but the method employed. The ministry stated that the campaign combined traditional manual hacking techniques with AI assistance, using software capable of reasoning and acting largely independently once directed at a target. One such AI, referred to as "Open Claw," was mentioned as an example of this agent-assisted strategy.

      As a result, the attackers managed to quickly extract “scores of passwords,” steal personnel records from the justice ministry, and investigate a nuclear safety agency for weaknesses over approximately four days. Such extensive actions would typically require a skilled human team working for weeks, which raises real concerns about liability when a rogue AI agent compromises a company.

      The targets consisted of government entities, and the reported activities included credential theft and broader data extraction. The ministry indicated that the affected units had "successively completed their handling" and asserted that “the relevant attack sources, methods, and scope of impact have all been fully investigated.”

      Officials characterized the source as being overseas but did not name any specific culprit, and no threat-actor group has been identified. This disclosure arrives amid ongoing tensions between Taiwan and China, and while the timing may suggest a subtext, the evidence published does not provide a clear narrative.

      The broader context comes from outside Taiwan. The announcement followed a report by cybersecurity firm Dream detailing an AI-driven campaign against an unnamed Asian government, later identified as Taiwan by the Financial Times. The typical pattern of these disclosures involves a private company identifying a trend, followed by government confirmation.

      Despite the focus on autonomous machines, humans still play a role in these incidents. One security researcher cautioned, “There’s still a human in there somewhere; it’s not totally 100% autonomous.” This distinction is important because the AI is an accelerant rather than a replacement, and accelerants can be troubling for defenders.

      The lowering of the barrier to entry is significant. An AI agent recently created fake identities to deploy malware, and the tools involved are inexpensive, readily accessible, and rapidly advancing, effectively equipping anyone willing to use them with state-like resources.

      However, the vulnerabilities exist in both directions. Researchers have demonstrated that these agents can be turned against their operators, as shown when an OpenClaw agent was tricked into leaking AWS keys and customer data through a phishing email. Thus, an attacker’s intelligent assistant also becomes a new attack surface.

      In many ways, Taiwan is the ideal place to observe these developments. It faces significant geopolitical pressure, has a dense and digitized public sector, and has historically been a testing ground for cyber techniques that later emerge in other regions.

      The rapidity of attack is particularly noteworthy. What once required weeks for a human team to navigate a network can now be accomplished in just a long weekend, fundamentally changing the calculus for those responsible for defending these systems.

      Taiwan stated that it has since strengthened monitoring and provided protective guidance to its agencies. Whether these measures will be sufficient remains to be seen, as if a few AI agents can scour government systems within four days, the next assault is unlikely to wait for defenders to regroup.

Other articles

All the announcements from Made by Google 2026: Pixel 11 series, Pixel Watch 5, and Pixel Tag. All the announcements from Made by Google 2026: Pixel 11 series, Pixel Watch 5, and Pixel Tag. Google was quite forthcoming today: they unveiled four new phones, a revamped watch, their first-ever tracker, and numerous Gemini features. Pixel 11 vs Pixel 10 series: Are Google’s latest phones worth upgrading to? Pixel 11 vs Pixel 10 series: Are Google’s latest phones worth upgrading to? Google enhanced the cameras, performance, charging, displays, and durability throughout the Pixel 11 series, but the significant upgrade threshold is set further back than the previous year's Pixel 10. Anthropic is reportedly negotiating to acquire Decart for $6 billion, marking its largest transaction to date. Anthropic is reportedly negotiating to acquire Decart for $6 billion, marking its largest transaction to date. Anthropic is said to be negotiating the acquisition of Israeli startup Decart for approximately $6 billion, marking its largest transaction to date. This move reflects a focus on efficiency over scale as the company prepares for an IPO. The AI Sales Engineer Is Entering the Meeting. The AI Sales Engineer Is Entering the Meeting. As voice agents and photorealistic avatars are incorporated into enterprise software, the sales call is emerging as a key example of whether AI can go beyond merely summarizing a conversation once it has concluded. The pressure is something anyone who has participated in a software demonstration understands well: a buyer inquires about a security assessment, integration nuances, [...] Brazil instructs Discord to halt livestreaming following the death of a 13-year-old. Brazil instructs Discord to halt livestreaming following the death of a 13-year-old. The data protection agency in Brazil has instructed Discord to halt its Go Live feature within three days following the death of a teenager, assessing the extent to which a government can impose regulations on a platform regarding child safety. Asus created a compact e-bike conversion kit that can easily fit into a backpack. Asus created a compact e-bike conversion kit that can easily fit into a backpack. Asus introduced a small e-bike conversion kit named Oxiis E250G1, a lightweight gadget that attaches to your seatpost and provides electric assistance to nearly any standard bicycle.

Taiwan reports that AI agents played a role in hacking its government within a span of four days.

Taiwan reported that it was the victim of an AI-driven hacking operation in July, which utilized tools such as Open Claw to extract passwords and personnel information within a span of approximately four days.