Taiwan has reported detecting an overseas cyber attack targeting government agencies that used artificial intelligence to assist hackers, highlighting the emergence of a new form of cyber threat that officials say combined conventional hacking techniques with autonomous AI tools.
Taiwan’s Ministry of Digital Affairs (MDA) said its cybersecurity monitoring units detected an “abnormal attack” against government agencies beginning on July 20. The National Institute of Cyber Security subsequently issued a series of alerts as authorities investigated the incident. The ministry said the investigation had identified characteristics indicating that the attack originated overseas.
It described the operation as a hybrid campaign in which hackers combined manual activity with attacks assisted by AI agents. “The relevant attack sources, methods, and scope of impact have all been fully investigated, and the affected units have successively completed their handling,” the MDA said.
The ministry said that the government had responded by establishing protective guidelines and strengthening monitoring of government systems to detect and block similar attacks at an earlier stage.
The incident was also examined by Dream, an Israeli artificial intelligence company that detected the intrusion. According to the company, the attackers used open-source AI agents to develop an autonomous hacking tool capable of operating in a way that resembled a coordinated cyber team.
Dream described the incident as a “first-of-a-kind breach,” reflecting the growing use of AI in cyber operations. According to reports citing Dream, the attackers compromised at least 85 government user accounts and extracted more than 2,500 personnel records before expanding their activity to Taiwan’s nuclear safety agency and at least seven energy companies.
The claims provide an indication of the potential scale of the operation, although Taiwan’s authorities have not publicly attributed the attack to a specific group.
China Link Suspected
The incident has attracted particular attention because Taiwan has repeatedly warned about cyber activity that it believes forms part of broader pressure from China. Taiwanese officials did not directly accuse Beijing of being responsible for the latest attack.
However, a news agency reported on Wednesday that China-linked hackers were suspected. Dream also stopped short of identifying a specific perpetrator. The company said, however, that the use of Simplified Chinese in internal communications associated with the operation suggested there was a high probability that the operator was connected to China.
Taiwan has for years accused China of employing what it describes as “hybrid warfare,” involving a combination of military pressure, disinformation and cyber activity. Beijing claims sovereignty over Taiwan, which has governed itself democratically for decades, and has increased military and political pressure on the island.
Taiwan has reported frequent Chinese military activity around its territory alongside concerns about attempts to influence public opinion and disrupt critical infrastructure. The latest cyber incident therefore comes against an already tense security backdrop.
Taiwan’s National Security Bureau said in January that cyber attacks on the island’s key infrastructure, including hospitals and banks, had risen by 6 percent in 2025 compared with the previous year. It estimated that Taiwan faced an average of 2.63 million cyber attacks each day. The bureau also said some attacks were coordinated with Chinese military exercises, describing the combination as part of broader “hybrid threats” that could be used to disrupt or paralyse the island.
The reported attack has also raised concerns beyond the immediate question of who was responsible. According to the investigation, the attackers used a combination of manual operations and AI agent-assisted activity. The MDA specifically referenced Open Claw as one of the AI-assisted tools used in the campaign.
Rather than relying entirely on human operators, autonomous or semi-autonomous AI agents can perform multiple stages of a cyber operation, potentially allowing attackers to work across numerous targets at greater speed. The reported compromise of government accounts followed by attempts to reach sensitive agencies and energy companies has heightened concerns about the potential consequences of such technology when directed at public institutions and critical infrastructure.
The threat has become more prominent as leading artificial intelligence companies have released increasingly capable models. Recent advances have allowed some AI systems to conduct reconnaissance, identify vulnerabilities and assist with exploiting weaknesses more rapidly than earlier tools.
However, the use of AI does not necessarily eliminate the role of human hackers. Taiwan’s investigation characterised the operation as a hybrid approach, suggesting that people remained involved alongside automated systems.
Taiwan said that the affected government agencies had completed their response to the incident and that authorities had investigated the sources, methods and scope of the attack. The government is now seeking to strengthen its defences against similar operations by introducing new protective guidelines and increasing system monitoring.
The measures reflect concerns that AI-assisted attacks could become more common as the technology becomes more capable and accessible. For Taiwan, the challenge is particularly significant because its cybersecurity environment is already under sustained pressure.










