Suspected Chinese hackers used public AI tools to breach Taiwanese government sites.
Researchers at Israeli AI outfit Dream said attackers used open-source AI agents to build an autonomous hacking tool that acted like a coordinated cyber team.
According to the Financial Times the tool spent four days at the start of July mapping 21 government systems, probing for vulnerabilities and changing tack when blocked.
It deployed up to eight autonomous agents at once, compromised at least 85 government user accounts and lifted more than 2,500 personnel records. The attack then widened to Taiwan’s nuclear safety agency and at least seven energy companies, according to the research.
The discovery lands as AI and cyber outfits grapple with new models that can spot and exploit software flaws without much babysitting. Anthropic, OpenAI and Meta have reported new AI models launching unexpected cyber attacks during testing, which is just the sort of progress nobody asked for.
Dream chief strategy officer Amir Becker, previously head of cyber operations for Israel’s elite signals intelligence Unit 8200, said he had never seen such an “end-to-end autonomous attack” on a government target.
The arrival of AI tools meant governments must assume they are permanently under cyber attack, Becker added.
“This must be the basic assumption of every government around the globe,” he said.
The target was Taiwan, although Dream declined to confirm the government’s identity, citing company policy, but said it had informed a country in “Asia-Pacific” of the breach.
Dream has not pinned the attack on a named group. Its researchers said Simplified Chinese in internal communications linked to the hack meant there was a high probability the operator was connected to China.
The stolen target data was written in Traditional Chinese, which is commonly used on government websites in Taiwan, Hong Kong and Macau.
Researchers could not identify which AI model powered the agents. The data showed its safeguards had been bypassed by disguising the hacking as an authorised vulnerability test.
In November 2025, Anthropic said it suspected Chinese state-sponsored hackers had manipulated Claude to try to hack 30 international companies and government agencies, with limited success.
Dream said the July attack’s most striking feature was how the tool ranked and reprioritised possible attack paths using available evidence.
When one attack route failed, it sent another agent to trawl the internet for information and cook up another approach, much like a human hacker.







