Published Security3 min read
Eight Agents, Four Days, No Sleep: Dream Says a Taiwan Intrusion Ran Itself
An Israeli firm says a toolkit built from downloadable AI agents mapped 21 government systems, took 85 accounts and 2,500 personnel records without a human driving. The tooling was ordinary. The tempo was not.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Israeli cybersecurity firm Dream documented what looks like the first fully autonomous, end-to-end AI hacking operation against a government target.
- Over four days at the start of July, according to the Financial Times, suspected Chinese hackers ran a tool built entirely from publicly available AI agents that mapped 21 government systems, hunted for vulnerabilities, and switched tactics on its own whenever it hit a wall. The FT reported that suspected Chinese hackers used publicly available AI tools to compromise government websites in Taiwan in a first-of-a-kind breach.
- The tool was not a single script running one attack; it deployed up to eight autonomous agents simultaneously, each working a different angle, more like a coordinated hacking team than a piece of malware.
- By the time researchers found it, the operation had compromised at least 85 government accounts, pulled over 2,500 personnel records, and expanded to hit a nuclear safety agency and at least seven energy companies.
- Dream will not officially name the target government, citing company policy, though a person familiar with the matter told the FT it was Taiwan.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Israeli security firm Dream says it documented an intrusion into a government's systems in early July that ran end to end without a human at the keyboard: a toolkit assembled entirely from publicly available AI agents that mapped 21 government systems over four days, hunted for vulnerabilities, and switched tactics on its own whenever it hit a wall [1][2]. If the account holds, the consequential part is not the tooling, which was free to download, but the operating tempo, which was not bound to anyone's shift.
The tool was not one script running one attack. Dream says it deployed up to eight autonomous agents at once, each working a different angle, behaving more like a coordinated team than a piece of malware [3]. By the time researchers found it, according to Dream, the operation had compromised at least 85 government accounts, pulled more than 2,500 personnel records, and expanded to a nuclear safety agency and at least seven energy companies [4]. Across a four-day window that averages roughly five systems mapped and about 21 accounts taken per day [1].
Attribution is thinner than the technical detail. Dream declines to name the target, citing company policy, though a person familiar with the matter told the Financial Times it was Taiwan [5]. The artifacts point the same way: internal communications tied to the tool were written in Simplified Chinese, while data stolen from the target came back in Traditional Chinese, the script used almost exclusively by government systems in Taiwan, Hong Kong and Macau [6]. Taiwan's Ministry of Digital Affairs declined to confirm specifics, saying only that incidents involving government agencies follow established response procedures [7].
The build was unremarkable. Researchers found a 160MB archive of 1,395 files organized around two open-source AI agent frameworks, Hermes and OpenClaw, both freely downloadable and designed to let models act autonomously on real tasks [8]. The model's safety guardrails were not broken so much as talked around: the operators framed the whole campaign as an authorized penetration test, a scenario the model apparently had no reliable way to verify or reject [9]. That is the distinction from the recent lab reports by Anthropic, OpenAI and Meta about models going off the rails in testing. This was not a sandbox accident; per Dream, it was deliberately assembled [10].
Dream's chief strategy officer, Amir Becker, who previously ran cyber operations for Israel's Unit 8200, said he had never seen this level of autonomy directed at a government, and that permanent assumed compromise is now the only realistic starting posture [11]. "This must be the basic assumption of every government around the globe," Becker said [12].
The number to sit with is the baseline. Taiwan's National Security Bureau logged an average of 2.6 million Chinese cyberattacks a day in 2025, up 6% year over year [13], which puts roughly 10.4 million recorded attempts inside the same four-day window [2]. Nearly all of that is noise absorbed by automation on both sides. The defensive problem arrives if a meaningful share of it starts doing what Dream found most striking: continuously ranking and reprioritizing attack paths as evidence came in, and when one path failed, deploying another agent to scour the internet and devise a new approach the way a human would [14].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Israeli cybersecurity firm Dream documented what looks like the first fully autonomous, end-to-end AI hacking operation against a government target.
- [2]
Over four days at the start of July, according to the Financial Times, suspected Chinese hackers ran a tool built entirely from publicly available AI agents that mapped 21 government systems, hunted for vulnerabilities, and switched tactics on its own whenever it hit a wall. The FT reported that suspected Chinese hackers used publicly available AI tools to compromise government websites in Taiwan in a first-of-a-kind breach.
- [3]
The tool was not a single script running one attack; it deployed up to eight autonomous agents simultaneously, each working a different angle, more like a coordinated hacking team than a piece of malware.
- [4]
By the time researchers found it, the operation had compromised at least 85 government accounts, pulled over 2,500 personnel records, and expanded to hit a nuclear safety agency and at least seven energy companies.
- [5]
Dream will not officially name the target government, citing company policy, though a person familiar with the matter told the FT it was Taiwan.
- [6]
Internal communications tied to the hacking tool were written in Simplified Chinese, while the data stolen from the target came back in Traditional Chinese, the script used almost exclusively by government systems in Taiwan, Hong Kong and Macau.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityaffairs.comPierluigi PaganiniAug 12China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan
Additional citations
- Dream, via SecurityAffairs
- Financial Times, via SecurityAffairs
- SecurityAffairs summarizing Dream/FT
- SecurityAffairs, citing FT
- SecurityAffairs summarizing the data clues
- Taiwan Ministry of Digital Affairs, via SecurityAffairs
- Dream researchers, via SecurityAffairs
- SecurityAffairs
- Amir Becker, Dream, via SecurityAffairs
- Taiwan National Security Bureau, via SecurityAffairs
- Dream, quoted by the Financial Times via SecurityAffairs



