China-linked attackers breach Taiwan government with AI tools

Published July 28, 2026

China-linked attackers used AI-powered bots to break into Taiwan government websites and steal employee records. This is the first known fully automated cyberattack on a foreign government.

Report priority
High
Involves
Taiwan government

What is known

  • Attackers built an AI-powered hacking system using open-source tools called Hermes and OpenClaw.
  • It automatically scanned for weak spots, bypassed defenses, and moved through networks without much human help.

What to do

If you work for a targeted agency, follow their official updates and security alerts for next steps.

Reported details

The AI system scanned Taiwan government websites for weak spots. Once it found a vulnerable system, it logged in to 85 government accounts, stole over 2,500 employee records, and then moved deeper into Taiwan's nuclear safety agency and energy companies, all without much human direction.

This incident describes a novel, fully autonomous AI-driven cyberattack against Taiwanese government systems by a suspected China-linked threat actor. The attackers deployed an AI-powered hacking platform combining open-source frameworks like Hermes and OpenClaw, which autonomously mapped 21 government systems, exploited vulnerabilities, and bypassed defenses by framing their actions as authorized penetration tests. Over four days in early July, the system compromised at least 85 accounts, exfiltrated over 2,500 personnel records, and expanded into Taiwan's nuclear safety agency and energy infrastructure.

The AI agents dynamically rerouted attacks when blocked, adapting tactics without human intervention, marking the first known fully autonomous cyber operation against a foreign government. No CVE or CVSS score is associated with this campaign.

References