Breaking
August 12, 2026

China-linked hackers use open-source AI to breach Taiwan government systems Hannah Collymore | usagoldmines.com

Suspected Chinese operators turned freely available AI agents into an autonomous hacking tool that broke into Taiwanese government networks over four days in early July, according to the Financial Times. 

The Israeli AI firm Dream said the attack broke into at least 85 accounts and stole more than 2500 personnel records. 

How were Taiwanese government systems compromised? 

An Israeli AI firm, Dream, says hackers who are suspected to have links to China infiltrated Taiwanese government systems by using open-source AI agents wired together to behave like a full offensive team. 

At its peak, the Financial Times report stated that the setup consisted of as many as eight agents working at once, and over a four-day window in July, it surveyed 21 government systems, hunted for weak points, and switched its approach whenever it was blocked by defenders.

Dream says the attackers got into at least 85 government accounts and pulled out more than 2,500 personnel records before the operation reached further, touching Taiwan’s nuclear safety agency and no fewer than seven energy companies. 

Researchers reconstructed the activity from a 160MB archive of 1,395 files that the operators left exposed online.

Dream observed that the tool had a habit of re-scoring its own options mid-attack. When one path into a target stalled, the system handed a fresh agent the job of scouring the internet for new information and building another route, so it kept moving without an operator steering each step.

The archive showed the tool leaned on two open-source agent frameworks, Hermes and OpenClaw, which let AI models carry out tasks on their own. However, Dream could not pin down which underlying model was doing the reasoning. It did find that the model’s security measures had been sidestepped by disguising the intrusion as a sanctioned security test. 

Amir Becker, Dream’s chief strategy officer and a former head of cyber operations at Israel’s Unit 8200 signals-intelligence arm, said he had not seen a government hit by this kind of “end-to-end autonomous attack” before. He stated that every government should now treat itself as permanently under assault. 

Why is China being suspected? 

Dream stated that its company policy prevents it from naming a hacking group or officially confirming the victim, but it said it had alerted a country in the Asia-Pacific region. A person familiar with the matter told the researchers the target was Taiwan.

Internal communications tied to the attack used Simplified Chinese, which Dream said made it highly likely the operator was linked to China. Even the stolen material came back in the written form of Traditional Chinese used on government sites in Taiwan, Hong Kong and Macau. 

Are Chinese hackers targeting other countries?

Similar to the Dream case, Palo Alto Networks’ Unit 42 documented an incident involving a separate Chinese-speaking actor, using the aliases knaithe and KnYuan. 

This hacker used the DeepSeek AI model, run through the same Hermes Agent system, to find targets, get exploit code, and attack seven security flaws, all commanded over Telegram. 

Anthropic reported in November that it suspected Chinese state-backed hackers had manipulated its Claude tool to go after 30 companies and agencies, though with limited success.

Taiwan’s National Security Bureau reported that the island absorbed an average of 2.63 million Chinese cyberattacks a day in 2025, representing a 6% rise from 2024. The attacks have been increasingly aimed at energy grids, hospitals and financial systems. 

Separately, Forescout’s Vedere Labs counted roughly 210 hacking groups operating out of China, close to double Russia’s 112.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It’s free.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.