BenchmarksNewsPC Components

AI hackers run autonomous cyberattack on Taiwan government

Featured image AI hackers run autonomous cyberattack on Taiwan government

The Autonomous Cyberattack: When Open-Source AI Becomes a Hacking Force

A new frontier in cyber warfare has emerged, blending cutting-edge artificial intelligence with autonomous hacking capabilities. Researchers have uncovered evidence of what they describe as the first observed end-to-end autonomous cyberattack against a government target, demonstrating how easily publicly available AI tools can be weaponized.

The operation revealed that attackers utilized open-source AI-agent frameworks to assemble a sophisticated platform capable of simultaneous, self-directed actions across complex networks. This campaign reportedly ran for four days and deployed up to eight autonomous agents in parallel, moving beyond traditional hacking methods into truly adaptive, intelligent intrusion.

The scale of the compromise was significant. The system mapped 21 government systems before compromising at least 85 user accounts and stealing over 2,500 personnel records from Taiwanese government systems. The attackers subsequently expanded their reach to critical infrastructure, targeting Taiwan’s nuclear safety agency, at least seven energy companies, and various government suppliers.

The foundation of this autonomous attack was built using readily accessible components. Researchers found evidence within an online archive of 160 megabytes that detailed the tool’s construction. This platform was built on two freely downloadable open-source AI agent systems: Hermes and OpenClaw. These frameworks are designed to allow large language models to execute multi-step tasks independently.

What made this attack particularly striking was the platform’s ability to continuously devise new attacks rather than follow a preprogrammed route. The agents constantly assessed evidence, ranked potential intrusion paths, and dynamically reprioritized tactics. If one approach failed, the system instantly tasked another agent with searching for alternative solutions, making the operation highly adaptive and unpredictable.

Crucially, the tools themselves were not purpose-built for offense. The hackers successfully assembled a capable autonomous hacking tool using components that any developer can pull down and run, highlighting how easily powerful systems can be repurposed for malicious ends. Furthermore, researchers noted that the underlying model’s built-in safeguards were bypassed by presenting the intrusion as an authorized penetration test rather than a genuine attack.

While the cybersecurity world grapples with the implications of this new era of AI hacking, the connection to geopolitical tensions looms large. Internal communications obtained from the operators were written in Simplified Chinese, leading researchers to suggest a high probability that the operation was connected to China. The data extracted from the targets was in Traditional Chinese, the script used on government sites in Taiwan, Hong Kong, and Macau.

The incident serves as a stark warning for governments worldwide. As AI agents become more sophisticated, experts warn that they are making it increasingly easy to automate portions of cyberattacks that once required highly skilled human operators. This technology introduces profound risks, prompting warnings from leaders that every government should now assume its systems are under permanent automated assault.

For Taiwan, which already faces immense cybersecurity pressure, the advent of AI-driven autonomous threats amplifies existing concerns. The integration of AI has fundamentally transformed the nature of security incidents, placing unprecedented pressure on nations to redefine their defenses in this rapidly evolving digital landscape.