China-linked attackers use AI to steal Taiwan government data
China-linked attackers used AI tools to break into Taiwan government systems, steal employee records, and hijack accounts, all without much human help. This is the first known fully automated AI-powered cyberattack on a government.
- Report priority
- Medium
- Targets
- Taiwan government+5 more
How it works
Attackers combined eight AI-powered tools to scan government websites, find weak spots, and steal data, all without human oversight.
What to do
If you're a private business or individual, check if your data was exposed in the leaked 2,500 records by contacting Taiwan's official cybersecurity or government alert channels.
Technical details
Affected software: Taiwan government, Windows, Google, Python, Anthropic, SpecterOps BloodHound
The attackers set up AI agents to scan Taiwan government websites for weaknesses. One agent mapped out 21 systems, another searched for flaws, and others switched tactics when blocked. Over four days, they stole 2,500 employee records and hijacked 85 accounts, including those in a nuclear safety agency and energy firms.
Researchers at Dream Security documented a novel, fully autonomous AI-driven cyberattack campaign linked to Chinese state actors, targeting a Taiwanese government network in early July. The operation deployed up to eight independent AI agents, built from publicly available tools, that simultaneously mapped 21 government systems, scanned for vulnerabilities, and dynamically adjusted tactics without human intervention. Over four days, the attackers compromised at least 85 government accounts, exfiltrated over 2,500 personnel records, and expanded to breach a nuclear safety agency and seven energy firms. The attack marked the first known end-to-end AI-powered breach against a government target, demonstrating how AI could automate reconnaissance, exploitation, and lateral movement in coordinated, adaptive campaigns.
References
- github.com · bloodhound product
- ft.com · 7d2ab3e0-9085-48f6-b38a-d90260d58795 SecurityAffairs
- asianews.it · taiwan-hit-by-about-26-million-daily-cyberattacks-from-mainland-china-in-2025 SecurityAffairs
- infosec.exchange · @securityaffairs SecurityAffairs
- securityaffairs.co · wordpress SecurityAffairs
- thehackernews.com · lazarus-exploits-windows-zero-day-to.html TheHackerNews
- thehackernews.com · china-linked-hackers-deploy-new.html TheHackerNews
- securityweek.com · fresh-windows-zero-day-exploited-in-north-korean-cyberattacks SecurityWeek
- darkreading.com · flaws-google-apk-python-agent-to-agent-attack DarkReading
- unit42.paloaltonetworks.com · aeternum-blockchain-c2-analysis Unit 42
- unit42.paloaltonetworks.com · frontier-ai-vulnerability-burst Unit 42
- sonatype.com · the-hugging-face-incident-changes-the-vulnerability-equation Sonatype
- huggingface.co · security-incident-july-2026 Sonatype
- snyk.io · evo-continuous-offensive-security Snyk
- snyk.io · remediation-agent-malicious-code-defense Snyk
- stepsecurity.io · anthropic-incident-ai-agent-malicious-package-pypi StepSecurity
- recordedfuture.com · ransomware-is-the-scoreboard Recorded Future
- picussecurity.com · cisa-alert-aa25-203a-interlock-ransomware-analysis Recorded Future
- cybersecurityventures.com · ransomware-damage-to-cost-the-world-74b-in-2026 Recorded Future
- attackiq.com · ctem Recorded Future
- neuracybintel.com · coca-cola-confirms-data-breach-following-fairlife-ransomware-attack-as-anubis-threatens-data-leak NeuraCybIntel
- investors.coca-colacompany.com · the-coca-cola-company-announces-technology-disruption-involving-fairlife-operations NeuraCybIntel
- investors.coca-colacompany.com · ko-20260716.htm NeuraCybIntel
- securityweek.com · coca-cola-confirms-data-breach-after-fairlife-ransomware-attack NeuraCybIntel
- reuters.com · gang-claims-responsibility-hack-coca-colas-fairlife-unit-2026-07-21 NeuraCybIntel
- bleepingcomputer.com · coca-cola-confirms-data-theft-in-fairlife-ransomware-attack NeuraCybIntel
- neuracybintel.com · origin-energy-suffers-major-customer-data-breach-affecting-millions-of-australians NeuraCybIntel
- openwall.com · 15 Openwall oss-security
- sec.cloudapps.cisco.com · cisco-sa-notice-LDquvx5d Cisco PSIRT
- blogs.cisco.com · strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery Cisco PSIRT
- cisecurity.org · multiple-vulnerabilities-in-sonicwall-gms-could-allow-for-remote-code-execution_2026-083 MS-ISAC
- cisecurity.org · a-vulnerability-in-zoom-clients-could-allow-for-remote-code-execution_2026-081 MS-ISAC
- cisecurity.org · critical-patches-issued-for-microsoft-products-august-11-2026_2026-080 MS-ISAC
- cyble.com · ransomware-incident-response-plan Cyble
- gbhackers.com · dark-web-corporate-access GBHackers
- cybersecuritynews.com · whatsapp-scam-alert-feature Cyber Security News
- engineering.fb.com · how-were-building-scam-alert-whatsapp Cyber Security News
- super.underdefense.com · 2027-security-operating-model-webinar Cyber Security News
- cybersecuritynews.com · fake-chrome-vpn-extensions Cyber Security News
- bleepingcomputer.com · city-forum-data-theft-attacks-target-salesforce-servicenow-portals BleepingComputer