Taiwan's government confirmed last week that it detected an abnormal cyberattack against several agencies, starting in July. The country's Ministry of Digital Affairs said the attack showed clear signs of coming from overseas and combined manual hacking with AI agent tools.
The real detail came from Dream, an Israeli cybersecurity firm that found the operation. According to Dream's research, the attackers deployed up to eight AI agents at once, each working a different task, more like a small hacking team than a single piece of malware. Over four days, the tool broke into at least 85 government accounts, pulled out more than 2,500 personnel records, and then expanded into Taiwan's nuclear safety agency and at least seven energy companies.
Dream said the AI agents mapped out each target's systems and found login pages that granted access without any password check at all. On one system, the agents solved the site's CAPTCHA test, the little box that asks you to prove you are human, with perfect accuracy every time. These are not exotic weaknesses. They are the same basic gaps security teams have warned about for years, except now something can find and use all of them at once, continuously, without needing sleep or a paycheck.
Dream stopped short of naming a government behind the attack, but noted that internal notes left behind were written in Simplified Chinese, the writing system used in mainland China. Taiwan's government did not name a suspect either. That fits a pattern: Taiwan's National Security Bureau reported that Chinese-linked cyberattacks on its infrastructure rose by 6 percent in 2025 compared with the year before, averaging 2.63 million attempts a day.
What makes this case matter beyond Taiwan is that it is the second confirmed example of an AI system running most of a real cyberattack with very little human help. The first came in November 2025, when Anthropic, the company behind the Claude chatbot, disclosed that a group it believed was linked to the Chinese state had used Claude to carry out 80 to 90 percent of an espionage campaign against roughly 30 organizations worldwide, including banks and chemical companies. In both cases, the attackers used the same trick: they told the AI it was running an authorized security test, which is often enough to get around the safety rules built into these systems.
The tool used in the Taiwan case, an open-source AI agent called OpenClaw, is not a hacking product. It is a general-purpose assistant that anyone can download for free and run on their own computer to handle emails, files, and tasks around the clock. That same openness is what makes it usable as a weapon: no company controls who runs it or what they point it at.
One security researcher pushed back on the idea that this was fully automated, noting a person still had to choose the target and set the goal. That is fair, but it misses the point. The skilled human labor needed to run an attack this size has dropped sharply, and the AI did the slow work of finding and exploiting weaknesses faster than any human team could.
For any organization outside the tech industry, the takeaway is not about geopolitics. It is that basic security habits many companies have put off, like removing old unprotected logins and retiring password-free shortcuts built for convenience, are now the first thing an AI agent will find. Cyber insurance underwriters and procurement teams checking vendor security should expect this kind of scan-and-exploit attack to become a normal cost of doing business, not a rare event worth a one-time fix.