China-linked attackers breach Taiwan government with AI tools
China-linked attackers used AI-powered bots to break into Taiwan government websites and steal employee records. This is the first known fully automated cyberattack on a foreign government.
- Report priority
- High
- Involves
- Taiwan government
What is known
- Attackers built an AI-powered hacking system using open-source tools called Hermes and OpenClaw.
- It automatically scanned for weak spots, bypassed defenses, and moved through networks without much human help.
What to do
If you work for a targeted agency, follow their official updates and security alerts for next steps.
Reported details
The AI system scanned Taiwan government websites for weak spots. Once it found a vulnerable system, it logged in to 85 government accounts, stole over 2,500 employee records, and then moved deeper into Taiwan's nuclear safety agency and energy companies, all without much human direction.
This incident describes a novel, fully autonomous AI-driven cyberattack against Taiwanese government systems by a suspected China-linked threat actor. The attackers deployed an AI-powered hacking platform combining open-source frameworks like Hermes and OpenClaw, which autonomously mapped 21 government systems, exploited vulnerabilities, and bypassed defenses by framing their actions as authorized penetration tests. Over four days in early July, the system compromised at least 85 accounts, exfiltrated over 2,500 personnel records, and expanded into Taiwan's nuclear safety agency and energy infrastructure.
The AI agents dynamically rerouted attacks when blocked, adapting tactics without human intervention, marking the first known fully autonomous cyber operation against a foreign government. No CVE or CVSS score is associated with this campaign.
References
- ft.com · 7d2ab3e0-9085-48f6-b38a-d90260d58795 Cyber Security News
- dreamgroup.com · inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia Cyber Security News
- super.underdefense.com · 2027-security-operating-model-webinar Cyber Security News
- thehackernews.com · ai-assisted-http-terminator-finds-novel.html TheHackerNews
- infosecurity-magazine.com · hugging-face-diffusers-trust Infosecurity Magazine
- infosecurity-magazine.com · ai-linux-kernel-zero-day-net-sched Infosecurity Magazine
- neuracybintel.com · sonicwall-sma1000-zero-days-fuel-inc-ransomware-attacks-against-enterprise-vpn-infrastructure NeuraCybIntel
- securityweek.com · sonicwall-issues-urgent-sma-patch-warning-for-two-zero-day-exploits NeuraCybIntel
- securityweek.com · sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch NeuraCybIntel
- sonicwall.com · kA1VN000001nv6D0AQ NeuraCybIntel
- securityweek.com · over-2500-organizations-impacted-by-litellm-supply-chain-attack SecurityWeek
- scworld.com · litellm-supply-chain-attack-impacted-over-2500-organizations SC World
- infosecurity-magazine.com · logistics-ceva-data-breach Infosecurity Magazine
- infosecurity-magazine.com · bdthemes-wordpress-poisoned-api Infosecurity Magazine
- thehackernews.com · sandworm-linked-uac-0145-uses-fake-job.html TheHackerNews
- thehackernews.com · gunra-ransomware-exploits-fortinet-and.html TheHackerNews
- darkreading.com · ransomware-hits-colombian-justice-ministry-presidential-transition DarkReading
- darkreading.com · gunra-ransomware-gang-fortinet-flaws-bypasses-mfa DarkReading
- cisa.gov · cisa-fbi-and-partners-warn-organizations-gunra-ransomware-actors-targeting-multiple-critical CISA News