Taipei’s Ministry of Digital Affairs is just now reporting that it detected “AI-assisted” cyberattacks in July and that the targets, whatever exactly happened to them, were able to return to normal. “The relevant attack sources, methods, and scope of impact have all been fully investigated, and the affected units have successively completed their handling.” From this kind of characterization, we can’t tell if the AI agents managed to disrupt anything or steal any information.
A Reuters report puts the Taipei-acknowledged intrusion in the context of the Chinese Communist Party’s “hybrid warfare…from daily military drills near the island to disinformation campaigns and cyberattacks” incessantly waged to try to compel Taipei to accept mainland rule. But the Ministry of Digital Affairs does not actually name the People’s Republic of China in its own reporting on the cyberattack (August 13, 2026).
Taiwan’s statement came a day after the Israeli cybersecurity company Dream said in a blog post that it had uncovered an AI-driven hacking campaign that stole credentials and other data from an unnamed government in Asia.
Dream said a team of AI agents worked together to extract scores of passwords from unidentified officials, steal personnel records from Taiwan’s justice ministry, and scan its nuclear safety agency for vulnerabilities over the course of four days.
Dream, which said it was able to reconstruct the hacking campaign after recovering the agents’ “complete operational workspace,” declined to share the data or name the government when approached by Reuters, but the Financial Times, which was the first media outlet briefed on Dream’s findings, identified the target agencies as Taiwanese.
The Financial Times reports:
Suspected Chinese hackers used publicly available AI tools to compromise government websites in Taiwan in a first-of-a-kind breach, highlighting how artificial intelligence is transforming cyber warfare.
The attackers used open-source AI agents to build an autonomous hacking tool that behaved like a co-ordinated cyber team, according to researchers at Dream, an Israeli AI company that first identified the intrusion.
Over four days at the start of July, the tool simultaneously deployed up to eight autonomous agents that mapped 21 government systems, researched vulnerabilities and changed tactics when blocked.
The tool compromised at least 85 government user accounts, extracting more than 2,500 personnel records before expanding the attack to Taiwan’s nuclear safety agency and at least seven energy companies, the research showed….
Dream has not attributed the attack to a specific group, but researchers said the use of Simplified Chinese in internal communications linked to the hack meant there was a high probability the operator was connected to China.
In contrast, the data recovered from the target was written in Traditional Chinese, as is common only on government websites in Taiwan, Hong Kong and Macau.
“AI-assisted,” the ministry’s adjective, sounds a little less AI-governed than the attack that Dream is talking about, consisting of a team of AI agents acting autonomously.
This may be a distinction without a difference, though, and it does sound as if, despite the vagueness of the ministry’s statement, the AI cyberattack that Dream and the Financial Times have reported is the same July AI cyberattack that the ROC Ministry of Digital Affairs has just acknowledged.
Which would mean that the targets of the ministry-acknowledged cyberattack were able to “complete their handling” of it only after the AI agents had managed to steal passwords from ROC officials, steal personnel records from the ROC’s justice ministry, “and scan its nuclear safety agency for vulnerabilities.”