Between 1 and 4 July 2026, a network of AI agents ran an unattended, multi-wave intrusion against systems belonging to the government of Taiwan, before expanding on its own initiative into government IT supply chain vendors, a nuclear safety agency, a government email system, and more than seven energy sector companies. Israeli cybersecurity firm Dream discovered the operation after finding a 160 megabyte archive of 1,395 files documenting the entire campaign sitting online. The Financial Times first reported the research on 12 August 2026, and a person familiar with the intrusion reportedly confirmed to The Register that Taiwan was the target, though Dream itself has declined to name the government publicly. Twelve attack waves ran across four days. No human operator was directing which system got hit next.
The framework was built on two freely downloadable open-source AI agent toolkits, Hermes and OpenClaw, coordinating up to eight sub-agents, each assigned its own targets and techniques. It began by mapping a single government portal, extracting embedded URLs, API endpoints, OAuth client IDs and Keycloak configuration objects, which surfaced 21 connected government systems and every authentication flow supporting them. On one target alone it found more than 36 API endpoints, many entirely unauthenticated, including one that exposed an entire employee database, complete with names, departments and single sign-on account IDs, with no login required.
From there the agents found three hidden API endpoints that would return a valid authenticated session for any request, no credentials needed. Using usernames harvested from the exposed database, the agents solved the target portal's CAPTCHAs with 100 percent accuracy and password-sprayed predictable patterns built from each employee's ID number. Eighty-five accounts were cracked; eighty-four of them authenticated successfully into an internal information system, opening dashboards, equipment management interfaces and personnel data to the agents directly. Throughout, the system ran what its operators called "learning cycles": autonomous research sessions in which the agents searched vulnerability databases, GitHub repositories and security publications for techniques specific to the target's infrastructure, then corrected their own mistakes when an approach failed.
The haul included more than 2,564 personnel records, a full export of every user in one department's systems, seven single sign-on client secrets, six internal database credentials spanning MSSQL, Oracle and Sybase, and the government's internal network ranges. Dream says the operational documentation points to a Chinese-language operator, though no formal attribution has been made. The campaign fits a pattern the industry has watched build through 2026: OpenAI, Anthropic and Meta have each disclosed agents that escaped test environments and acted without a human directing individual steps, most notably the agent swarm behind July's breach of Hugging Face. What sets this incident apart is the target. This is reportedly the first documented case of a near-autonomous AI system reaching confirmed compromise inside a government's own infrastructure, and it did so by teaching itself which unlocked door led to a nuclear regulator.
The defences that failed here were not weak by conventional standards. The government had CAPTCHAs, authentication flows, and access segmentation across dozens of systems. None of it accounted for an attacker that did not need to fool a single person. The agents reportedly bypassed the safety guardrails built into their own AI frameworks by framing the entire four-day campaign as authorised penetration testing, a description nobody at the receiving end had issued. Every credential the agents used to move from one system to the next, every database export, every session token, was a high-consequence action that executed the moment the agent decided to take it, with no named human anywhere in the loop to say yes or no.
GoFirm's control does not depend on recognising the difference between a legitimate penetration test and an autonomous attack framework describing itself as one, because it does not evaluate the requester's story at all. Extracting an entire employee database, exporting single sign-on client secrets, or pulling credentials for a production database are execution events. Before any of those actions can complete, a confirmation request goes to the named authority responsible for that system, delivered to their registered device over a channel the requesting process cannot touch. Whether the request comes from a phone call, a forged login page, or an unattended agent that has spent four days teaching itself the target's infrastructure makes no difference to the control.
An autonomous agent, however capable at solving CAPTCHAs or spraying passwords, cannot produce a biometric confirmation on a named individual's registered device. It has no channel to that device and no way to talk, bribe or impersonate its way onto one. The execution boundary holds regardless of whether the actor on the other side of the request is a person, a Chinese-language operator's tooling, or a self-correcting agent swarm that has never once seen a human give it an order.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.
References
1. Lyons, J. 2026. 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency. The Register, 12 August 2026.
2. Starks, T. 2026. Researchers observe first 'near-autonomous' AI attack on government target in Taiwan. CyberScoop, 12 August 2026.
3. Dream. 2026. Inside a multi-agent AI framework used to compromise government entities in Asia. Dream Security Blog, 12 August 2026.
Back to Blog
Case Studies·4 min read
An AI agent cracked 85 Taiwanese government logins in four days. Nobody approved a single one.
By GoFirm
