Taiwan says it spent part of last month fending off a hacking campaign that leaned on artificial intelligence to do the heavy lifting. The island's Ministry of Digital Affairs, through its National Institute of Cyber Security, disclosed that government agencies were targeted in July, with alerts going out from around 20 July.
What makes the episode notable is not the break-in itself but the method. According to the ministry, the campaign blended old-fashioned manual hacking with the assistance of AI agents — software that can be pointed at a target and left to reason and act largely on its own. One such agent, “Open Claw,” was cited as an example of the agent-assisted approach.
The speed of the attack
The result was speed. Over roughly four days, the attackers extracted “scores of passwords,” stole personnel records from the justice ministry, and probed a nuclear-safety agency for vulnerabilities. That kind of breadth once demanded a skilled human team working for weeks, which is partly why the question of who is liable when a rogue AI agent hacks a company has stopped being hypothetical.
The targets were government bodies, and the reported activity ranged from credential theft to broader data extraction. The ministry said the affected units had “successively completed their handling” and insisted that “the relevant attack sources, methods, and scope of impact have all been fully investigated.” Officials described the source as overseas but stopped short of naming a culprit, and no threat-actor group has been identified.
The disclosure nonetheless lands amid the persistent tensions between Taiwan and China, and it is not hard to read a subtext into the timing, even if the evidence made public does not spell one out. The wider context arrived from outside Taiwan. The disclosure follows a report by the cybersecurity firm Dream describing an AI-driven campaign against an unnamed Asian government, later identified as Taiwan by the Financial Times. That is roughly the sequence in which these stories now tend to surface: a private firm spots the pattern, and the government confirms it afterwards.
The human element remains
For all the talk of autonomous machines, the humans have not left the building. “There's still a human in there somewhere,” one security researcher cautioned of the campaign. “It's not totally 100% autonomous.” The distinction matters because the AI here is an accelerant rather than a replacement, and accelerants are the sort of thing defenders lose sleep over.
What that acceleration lowers is the barrier to entry. An AI agent recently faked identities to plant malware, and the tools involved are cheap, widely available, and improving fast, which quietly hands the resources of a state to almost anyone willing to run them. The vulnerabilities cut both ways, mind. Researchers have shown that these agents can be turned against their own operators, in one case tricking an OpenClaw agent into leaking AWS keys and customer data with nothing more than a phishing email. An attacker's clever assistant is also a fresh attack surface.
Taiwan as a proving ground
Taiwan is, in many respects, the obvious place to watch this play out first. It sits at the sharp end of geopolitical pressure, runs a dense and heavily digitised public sector, and has long served as a proving ground for cyber-techniques that later surface elsewhere. The compression of time is the part worth dwelling on. What used to be measured in the weeks a human crew needed to move laterally through a network can now, on this evidence, be squeezed into a long weekend, which rewrites the arithmetic for everyone tasked with defending one.
Taiwan says it has since tightened monitoring and issued protective guidance across its agencies. Whether that proves enough is another matter, because if a handful of AI agents can rifle through government systems in four days, the next campaign is unlikely to wait politely for the defenders to catch up.
The growing reliance on AI in cyberattacks reflects a broader trend across the threat landscape. Security firms have documented a steady increase in the use of large language models and autonomous agents by both state-sponsored groups and financially motivated criminals. These tools can automate reconnaissance, craft convincing phishing messages, adapt to defensive measures, and even execute multi-step attack chains with minimal human oversight.
In the Taiwan case, the use of OpenClaw — an open-source AI agent framework originally designed for general automation tasks — shows how readily available components can be repurposed for malicious ends. OpenClaw is not a hacking tool per se; it is a flexible assistant that can browse the web, interact with applications, and manipulate files. But in the hands of an attacker, it can be instructed to identify vulnerable endpoints, test credentials, and exfiltrate data, all while iterating on its own approach.
Security analysts note that the four-day timeline is particularly significant. Traditional intrusion campaigns against well-defended government networks often take weeks or months of planning and execution. Human operators need to study the target, craft custom exploits, maintain persistence, and avoid detection. AI agents compress that cycle by automating the repetitive parts and allowing a small number of humans to supervise multiple concurrent operations.
The Taiwan disclosure also raises questions about attribution and deterrence. Identifying the perpetrator of an AI-assisted attack is harder when the techniques are widely available and the operational footprint is diffused. A state actor could plausibly deny involvement, while a lone hacker with rented infrastructure could mimic the behavior of a sophisticated group. This ambiguity makes it difficult for governments to respond proportionately or to impose consequences.
For defenders, the implications are sobering. Traditional perimeter defenses, such as firewalls and intrusion detection systems, are designed to catch known signatures and predictable behavior. AI-driven attacks can generate novel patterns faster than signature databases can be updated. Security teams must therefore shift toward behavioral analytics, automated response systems, and threat hunting that assumes a breach is already underway.
Another layer of concern is the potential for AI agents to be used in supply-chain attacks. If a hacker compromises a software vendor, they could embed malicious instructions in an update that an AI agent then executes. The agent might not understand the full context but would follow the instructions faithfully, making the attack harder to trace and attributing the actions to the AI rather than a human mastermind.
Taiwan's response has been to issue a series of protective bulletins and to require agencies to audit access logs, rotate credentials, and review firewall rules. The Ministry of Digital Affairs has also said it is working with private sector partners to develop AI-specific defense tools. However, the ministry acknowledged that no system is fully immune, and it has encouraged agencies to assume that some data may already have been compromised.
Internationally, the Taiwan case is likely to become a reference point for policy discussions on AI and cybersecurity. Governments around the world are grappling with how to regulate autonomous systems, where to place liability, and how to build resilience against AI-augmented threats. The European Union's AI Act, for example, includes provisions for high-risk AI applications, but applying those rules to cyberweapons or hacking tools is fraught with jurisdictional challenges.
Some experts argue that the answer lies in using AI to defend against AI. Automated threat detection, self-healing networks, and AI-powered incident response are emerging fields. But defenders are often constrained by budgets, legacy systems, and a shortage of skilled personnel. The gap between offensive and defensive AI capabilities may widen before it narrows.
At the same time, the human factor remains critical. In the Taiwan incident, the attackers still relied on manual oversight to ensure the AI agents did not veer off course or trigger alarms. That suggests a hybrid model of attack, where machines handle the grunt work and humans make high-stakes decisions. For defenders, that means training people to recognize subtle signs of AI-generated activity, such as unusual command sequences, rapid-fire navigation, or a strangely polished spear-phishing message.
The Taiwan government's public statement did not elaborate on the specific agencies affected or the full scope of the data loss. But the disclosure itself is notable for its transparency. Many governments prefer to hide such incidents for fear of embarrassment or public panic. Taiwan chose to announce the attack, release details about the weaponization of AI, and share its recommendations with allied cybersecurity organizations.
This openness may also reflect a strategic calculation. By publicly framing the attack as AI-enabled, Taiwan draws attention to a threat that affects all digital societies, not just those at geopolitical flashpoints. It invites other governments to cooperate in tracking and mitigating AI-driven intrusions, while subtly highlighting the kind of adversary that might benefit from such tools.
Meanwhile, the private sector is watching closely. Companies that provide cloud infrastructure, identity management, and endpoint security are already adjusting their products to detect the fingerprints of AI agents. Some have built honeypots designed to lure automated attackers and study their behavior. Others are experimenting with AI models that can patch vulnerabilities in real time, effectively fighting fire with fire.
The Taiwan episode is also a reminder that cybersecurity is not merely a technical issue but a strategic one. The ability to breach a government's systems in days rather than weeks has geopolitical consequences. It undermines trust in digital institutions, raises the cost of governance, and creates opportunities for disinformation or covert influence. When AI agents do the dirty work, the threshold for launching such an attack drops dramatically.
As more organizations adopt AI assistants for legitimate purposes, the attack surface expands. Every AI agent connected to a corporate network is a potential foothold for an intruder. The same features that make these tools useful — autonomy, access to data, ability to act on instructions — also make them dangerous if compromised. The Taiwan case underscores the urgency of securing the AI supply chain, hardening the interfaces between agents and internal systems, and ensuring strict authentication for every command.
In the end, the most striking takeaway from the Taiwan disclosure is the normalization of AI in cyber-conflict. What was once the stuff of science fiction — a software agent autonomously probing a nuclear-safety agency — is now a documented event in a government report. The four-day timeline may be just the beginning; future attacks could be even faster, more targeted, and more difficult to attribute. Defenders are now in a race not only against other humans but against machines that never sleep, never tire, and improve with every iteration. Taiwan has responded with heightened alertness and updated guidance, but the episode leaves a broader question hanging over every connected government and company: are we ready for what AI agents are about to release?
Source: TNW | Security News