Agentic market $10.8B and climbing  ·  editor@gaasnews.com
Sections
HomeWhat is GaaS?PlatformsPricingGlossaryOpinionAboutContact
HomeEvaluation & SafetyTaiwan AI Attack
Evaluation & Safety

Researchers say China-linked hackers ran the first near-autonomous AI attack on a government

Israeli security firm Dream says a China-linked operator used open-source agent frameworks to breach 85 Taiwanese government accounts and steal more than 2,500 personnel records over four days in July, with minimal human steering once the system was running.

AJ
Andrew Jamerson
Founding Editor
Aug 16, 2026 · 3 min read
Dream says up to eight agents ran attack waves against Taiwanese systems in parallel. // GaaS News

The hypothetical everyone in agent security has been warning about now has a case number. Israeli cybersecurity firm Dream said this week that a suspected China-linked operator used an autonomous AI agent system to attack Taiwanese government infrastructure over four days in early July, in what researchers describe as the first observed end-to-end autonomous cyberattack on a government target, The Register reported Wednesday.

According to Dream, the system ran 12 attack waves between July 1 and July 4, deploying as many as eight sub-agents in parallel. The campaign compromised 85 government user accounts and extracted more than 2,500 personnel records, then widened its aim to Taiwan's nuclear safety agency, government suppliers, and at least seven energy companies. Dream's researchers recovered a 160 MB archive of 1,395 files documenting the operation, with internal notes written in simplified Chinese. The firm has not tied the activity to a specific group, and Taiwan has not publicly confirmed the intrusions.

The tooling is the part that should bother the agentic services industry. Dream says the platform was assembled from openly available components, including the open-source Hermes and OpenClaw agent frameworks, the same commodity software that powers legitimate automation businesses. GaaS News readers have met OpenClaw's initiative before, in a lower-stakes setting. The operators reportedly bypassed model guardrails by framing tasks as authorized penetration testing, and the framework ran learning cycles that searched vulnerability databases and GitHub for techniques, then corrected its own errors when an attack path failed.

"AI orchestrated, fully automated offensive attacks are real now," Michael Dalton, a member of OpenAI's technical staff, said in remarks quoted by The Register.

Dream's own researchers were more measured. "We increasingly see threat actors leveraging AI for autonomous offensive operations. But building a system that actually works at this level takes more work than 'just' running a model," the firm noted, in comments to CyberScoop. Significant human effort still went into building and maintaining the platform, which is why several outlets settled on the phrase near-autonomous.

The caveat is fair and the trendline is still ugly. The expensive part of this attack was engineering, done once, up front. The per-target cost after that was compute. Every agentic AI service pitch of the past year has celebrated exactly that economic shape, and this campaign demonstrates it works just as well when the customer is an intelligence operation. Defenders now face attackers with the operating costs of a SaaS company, and the defense side's agent story is not yet as far along as the sales decks say.

AJ

Andrew Jamerson

Founding Editor, GaaS News

Andrew Jamerson is the founding editor of GaaS News, covering the economics of the agent era. He started the publication to cover Agentic AI as a Service as a dedicated beat and edits every article on the site.

Be on the list when the beat breaks

One email when a platform ships, a round closes, or the ground shifts under the software stack.