Published Security3 min read
An AI framework picked its own next targets in Taiwan, and the list included a nuclear safety agency
Israeli firm Dream says a near-autonomous multi-agent system extracted more than 2,500 personnel records from a Taiwanese government target, then widened the operation on its own to supply-chain vendors, a government...
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Suspected Chinese hackers used open-source artificial intelligence models to run a cyberattack against the Taiwanese government, in the first publicly known case of an autonomous AI hack hitting a government target, according to research published Wednesday by Israeli cyber firm Dream.
- The hackers extracted more than 2,500 personnel records, among other data, in what Dream researchers called a "near-autonomous attack" in a blog post.
- The attackers set up the framework so that it could "adapt mid-operation without human intervention."
- Dream wrote that "the attacker didn't stop at primary targets" and "expanded the operation to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies - scanning them all in parallel for misconfigurations, exposed admin interfaces, and exploitable vulnerabilities."
- The framework "implements dedicated research phases it calls 'Learning Cycles' - autonomous sessions where the AI system searches vulnerability databases, GitHub repositories, and security research publications for techniques specifically applicable to its target government's infrastructure."
Compiled by The WatchSomething wrong?How this is made
Why it matters
Israeli security firm Dream published research on Wednesday describing what it calls a near-autonomous AI attack on the Taiwanese government, run by suspected Chinese operators using open-source AI models, which pulled out more than 2,500 personnel records along with other data [1] [2]. The detail that should occupy defenders is not the theft but the expansion: according to Dream, the framework did not stop at the primary target and moved on to government IT supply chain vendors, a nuclear safety agency, a government email system and more than seven energy sector companies, scanning them all in parallel for misconfigurations, exposed admin interfaces and exploitable vulnerabilities [4].
Dream says the attackers configured the system to adapt mid-operation without human intervention [3], and that it implements dedicated research phases the operators called Learning Cycles: autonomous sessions in which the system searches vulnerability databases, GitHub repositories and security research publications for techniques applicable to the target government's infrastructure [5]. Dream also says the framework learned from its own failures as the campaign progressed [6]. Counting only what is named, the expansion touched at least nine discrete organisations beyond the initial target, plus an unspecified number of supply-chain vendors [7].
That is the operationally interesting number. A human intrusion set works a target list serially because attention is the scarce resource. A framework that runs its own reconnaissance loop and fans out concurrently produces simultaneous, unrelated victims, and each of those victims discovers the problem on its own clock. Nothing in Dream's account suggests the tooling was novel; the reported scanning looked for misconfigurations and exposed interfaces [4], which is the same bread and butter defenders already fail to close. The change is arrival rate.
The autonomy claim deserves the qualifier Dream itself attaches. The firm notes that building a system that works at this level takes more than running a model, and points to careful task adjustment, optimisation of agent coordination and fine-tuning of decision logic, along with Bayesian prioritisation, self-correction loops and adaptive research cycles [8]. Humans built and tuned this; the machine executed and re-scoped. The operators used two open-source AI frameworks, Hermes and OpenClaw, and bypassed safety guardrails by presenting the work as authorised penetration testing [9] [10]. Dream found the whole thing in an exposed online archive of 160 megabytes and nearly 1,400 files, which it says revealed a multi-agent system that achieved confirmed real-world compromises against state infrastructure [11].
For context, Anthropic reported last autumn that it disrupted what it described as the first autonomous cyber espionage campaign, and researchers noted that the campaign still required significant human work [12]. The pattern holds here. The Financial Times first reported the Dream research and the details of the target [13].
Watch for independent corroboration: this is one vendor's reading of one archive it discovered [11], and confirmation from Taiwanese agencies or the named downstream sectors has not been reported. Watch the guardrail question, because "authorised penetration testing" as a framing device [10] is a policy problem for model providers rather than a technical one. And watch whether the tuning burden Dream describes [8] stays high, since that effort, not the model, is what currently limits how many of these run at once.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Suspected Chinese hackers used open-source artificial intelligence models to run a cyberattack against the Taiwanese government, in the first publicly known case of an autonomous AI hack hitting a government target, according to research published Wednesday by Israeli cyber firm Dream.
- [2]
The hackers extracted more than 2,500 personnel records, among other data, in what Dream researchers called a "near-autonomous attack" in a blog post.
- [3]
The attackers set up the framework so that it could "adapt mid-operation without human intervention."
- [4]
Dream wrote that "the attacker didn't stop at primary targets" and "expanded the operation to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies - scanning them all in parallel for misconfigurations, exposed admin interfaces, and exploitable vulnerabilities."
- [5]
The framework "implements dedicated research phases it calls 'Learning Cycles' - autonomous sessions where the AI system searches vulnerability databases, GitHub repositories, and security research publications for techniques specifically applicable to its target government's infrastructure."
- [6]
Dream said the system also learned from its mistakes as the operation went on, and identified this as something that stood out about the campaign.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cyberscoop.comTim StarksAug 12Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan
Additional citations
- Dream, via CyberScoop
- Dream blog post
- Dream
- Anthropic and Dream, via CyberScoop
- CyberScoop



