Taiwan reports that AI agents were involved in hacking its government within a span of four days.
Taiwan has reported that it spent part of last month combating a hacking campaign that utilized artificial intelligence for much of the work. The island's Ministry of Digital Affairs, via its National Institute of Cyber Security, revealed that government agencies were targeted in July, with alerts initiated around July 20.
What makes this incident particularly noteworthy is not just the intrusion itself but the approach taken. The ministry indicated that the campaign combined traditional manual hacking with AI agents—software that can be directed at a target and largely operate independently. One example mentioned was an agent known as “Open Claw,” which exemplifies this agent-assisted strategy.
The outcome was rapid. Within about four days, the attackers managed to extract “scores of passwords,” acquire personnel records from the justice ministry, and investigate a nuclear safety agency for potential vulnerabilities. Such extensive activity previously required a skilled human team working for weeks, which raises the question of accountability when a rogue AI conducts a hack—no longer just a theoretical issue.
The targets were government entities, and the reported activities included credential theft and broader data extraction. The ministry stated that the affected units had “successfully completed their handling” and emphasized that “the relevant attack sources, methods, and scope of impact have all been fully investigated.”
Officials described the source as originating from overseas but refrained from naming any specific perpetrator, and no threat actor group has been identified. Nevertheless, this revelation comes amid ongoing tensions between Taiwan and China, and the timing certainly invites speculation, even if the public evidence does not confirm any direct link.
This situation unfolds in a broader context that originated from outside Taiwan. The announcement follows a report by the cybersecurity firm Dream, detailing an AI-driven campaign against an unnamed Asian government, later identified by the Financial Times as Taiwan. Typically, these narratives emerge in a sequence where a private entity identifies a trend, and the government corroborates it afterward.
Despite discussions about autonomous machines, human involvement persists. “There’s still a human in there somewhere,” a security researcher noted regarding the campaign. “It’s not totally 100% autonomous.” This distinction is significant because the AI serves as an accelerant rather than a substitute, and such accelerants cause considerable concern for defenders.
What this acceleration does is lower the entry barrier. Recently, an AI agent impersonated identities to deploy malware, and the tools used are inexpensive, readily available, and rapidly advancing, effectively providing state-level resources to nearly anyone willing to utilize them.
However, these vulnerabilities can also backfire. Researchers have demonstrated that these agents can be used against their operators; in one instance, an OpenClaw agent was tricked into leaking AWS keys and customer data through a simple phishing email. A clever assistant for an attacker also represents a new attack vector.
Taiwan is, in many ways, an ideal location to observe this situation unfold. It is at the frontline of geopolitical pressures, has a dense and highly digitized public sector, and has long been a testing ground for cyber techniques that appear later on in other regions.
The rapidity of attack is critical to consider. What once took weeks for a human team to move laterally through a network can now, based on this evidence, be condensed into a long weekend, fundamentally altering the calculations for those tasked with defense.
Taiwan has indicated that it has since enhanced monitoring and provided protective guidance across its agencies. Whether this proves sufficient is uncertain, as if a few AI agents can infiltrate government systems in four days, the next attack is likely to occur without waiting for the defenders to catch up.
Other articles
Taiwan reports that AI agents were involved in hacking its government within a span of four days.
Taiwan reports that it was the target of an AI-driven hacking operation in July, which utilized tools such as Open Claw to steal passwords and personnel data within a span of approximately four days.
