Taiwan’s Ministry of Digital Affairs says its cybersecurity units detected an abnormal, AI-assisted cyber-attack on government agencies that began on 20 July and came from an overseas source. The National Institute of Cyber Security issued warning alerts as it investigated.
The ministry said the operation combined manual activity with AI-agent-assisted attacks, including the tool Open Claw. It said the affected units had completed their handling of the incident and that the government had strengthened monitoring to block similar attacks earlier.
What Taiwan’s investigation found
The Ministry of Digital Affairs said the attack’s sources, methods and scope of impact had been fully investigated. It described the activity as a hybrid operation in which human operators worked alongside AI agents, rather than as a wholly autonomous campaign.
A report on the intrusion quoted Dream, an Israeli AI company that detected it, as saying the attackers used open-source AI agents to build a tool that acted like a coordinated cyber team. Dream did not identify a specific group behind the operation.
The reported scale of the intrusion
The source report said Dream estimated that the tool compromised at least 85 government user accounts and extracted more than 2,500 personnel records before extending the attack to Taiwan’s nuclear safety agency and at least seven energy companies. These figures were presented as findings attributed to Dream, not as a separate figure issued by Taiwan’s ministry.
Dream was also reported to have linked the use of Simplified Chinese in internal communications to a high probability that the operator was connected to China. Taiwanese officials did not accuse China in their statement, and Chinese authorities had not commented on the incident at the time of the report.
Why the incident matters for Taiwan
Taiwan has described cyber-attacks, disinformation and military activity near the island as elements of what it calls China’s hybrid warfare. Its National Security Bureau said in January that attacks on key infrastructure, including hospitals and banks, averaged 2.63 million a day in 2025, up 6% from the previous year.
The reported operation also illustrates the changing role of AI in hacking campaigns. Security researcher Cris Thomas cautioned that AI agents can speed reconnaissance, vulnerability discovery and exploitation, but said a human operator still chooses the target, sets the objective and gives the system its directive.
No comments yet. Start the discussion.