China-linked attackers use AI to steal Taiwan government data

Published July 29, 2026

China-linked attackers used AI tools to break into Taiwan government systems, steal employee records, and hijack accounts, all without much human help. This is the first known fully automated AI-powered cyberattack on a government.

Report priority
Medium
Targets
Taiwan government+5 more

How it works

Attackers combined eight AI-powered tools to scan government websites, find weak spots, and steal data, all without human oversight.

What to do

If you're a private business or individual, check if your data was exposed in the leaked 2,500 records by contacting Taiwan's official cybersecurity or government alert channels.

Technical details

Affected software: Taiwan government, Windows, Google, Python, Anthropic, SpecterOps BloodHound

The attackers set up AI agents to scan Taiwan government websites for weaknesses. One agent mapped out 21 systems, another searched for flaws, and others switched tactics when blocked. Over four days, they stole 2,500 employee records and hijacked 85 accounts, including those in a nuclear safety agency and energy firms.

Researchers at Dream Security documented a novel, fully autonomous AI-driven cyberattack campaign linked to Chinese state actors, targeting a Taiwanese government network in early July. The operation deployed up to eight independent AI agents, built from publicly available tools, that simultaneously mapped 21 government systems, scanned for vulnerabilities, and dynamically adjusted tactics without human intervention. Over four days, the attackers compromised at least 85 government accounts, exfiltrated over 2,500 personnel records, and expanded to breach a nuclear safety agency and seven energy firms. The attack marked the first known end-to-end AI-powered breach against a government target, demonstrating how AI could automate reconnaissance, exploitation, and lateral movement in coordinated, adaptive campaigns.

References