Suspected China-linked hackers used autonomous open-source AI agents to breach multiple Taiwanese government systems in early July, according to an exclusive report by the Financial Times. Israeli cybersecurity firm Dream, which disclosed the case, described it as the first government-focused cyberattack it has seen carried out in an end-to-end autonomous way.
Attack unfolded over four days
Dream said the operation was concentrated within four days in early July. The attackers deployed as many as eight autonomous AI agents at the same time, with different agents handling target discovery, vulnerability research, attempts across multiple intrusion paths, and changes in method when defenses blocked their progress.
According to the company’s research, the agents mapped the network architecture of 21 government systems. Dream said the campaign eventually compromised at least 85 government user accounts and stole more than 2,500 personnel records. The scope of the intrusion later extended to Taiwan’s nuclear safety authority and at least seven energy companies.
Dream says it had not seen this type of government-targeted attack before
Dream Chief Strategy Officer Amir Becker, previously head of cyber operations in Israel’s elite Unit 8200 signals intelligence organization, said AI had generally been used in the past to help human hackers with isolated tasks. In this case, he said, the chain from reconnaissance to vulnerability discovery to intrusion was handled largely by AI agents.
Becker said he had never previously seen this kind of end-to-end autonomous attack aimed at a government target. He added that governments now need to assume they are under constant cyberattack. In his view, operations that once required a full team and substantial manpower may now be compressed into software that runs on its own.
Taiwan declined comment, China did not respond
Taiwan’s Ministry of Digital Affairs declined to comment on the incident, citing confidentiality. The report also said China did not respond to requests for comment.
The report noted that the assessment that the attack was linked to China currently comes from cybersecurity research and the Financial Times report, and that official attribution has not been confirmed.
The ABMedia item said the report was compiled by TechNews based on the Financial Times coverage.

