AI Agents Used in Hybrid Hacking Campaign Against Taiwan Government
Attackers blended manual operations with AI frameworks to steal credentials and probe nuclear safety infrastructure.
Taiwan's government agencies were targeted by a sophisticated AI-assisted cyberattack in July, marking a significant escalation in the digital threats facing the island. The Ministry of Digital Affairs detected the abnormal activity and has since stated that the affected bodies successfully handled the incident.
The campaign employed a hybrid operational model, blending traditional manual hacking with AI agents to increase efficiency. According to the Israeli cybersecurity firm Dream, these AI agents were used to steal passwords from government officials and exfiltrate personnel records from Taiwan's justice ministry. Additionally, the attackers used the tools to scan the nuclear safety agency for vulnerabilities over a four-day period. Technical analysis confirmed the attackers utilized open-source AI agent frameworks, specifically mentioning 'OpenClaw' and 'Hermes' to facilitate the breach.
The Context of Hybrid Warfare
This breach occurs against a backdrop of intensifying 'hybrid warfare' directed at Taiwan. The island has faced a steady increase in military drills and disinformation campaigns, often synchronized with digital incursions. Data from Taiwan's National Security Bureau underscores the scale of this pressure, reporting that Chinese cyberattacks on key infrastructure rose 6% in 2025. This surge has resulted in an average of 2.63 million attacks per day, highlighting a persistent and systemic effort to probe the island's defenses.
Implications for Cyber Defense
The incident serves as a critical case study in the evolving threat of AI-driven reconnaissance. By leveraging AI agents, attackers can conduct vulnerability scans and credential theft at a speed and scale that far exceeds human capability alone. While the tools provide unprecedented efficiency, security experts emphasize that they are not yet fully autonomous. Cris Thomas, a security advocate at Semgrep, noted that a human operator is still required to establish objectives and provide directives, stating, "There’s still a human in there somewhere... It’s not totally 100 per cent autonomous."
Future Outlook
As AI frameworks become more accessible, the barrier to entry for executing complex, coordinated cyber operations continues to drop. The use of open-source tools like OpenClaw suggests that state-sponsored or affiliated actors are rapidly integrating commercial AI capabilities into their arsenals. Security analysts will now be watching for whether these autonomous agents evolve to handle the 'objective-setting' phase of an attack, which would remove the current human bottleneck and further accelerate the pace of cyber warfare.