AI agents were used in a July attack on Taiwan-linked government systems, and the important part isn't that they were brilliant. It's that they were cheap, open-source and good enough.
Over four days in July, attackers used a network of AI agents to map 21 government systems, crack 85 user accounts and pull more than 2,500 personnel records, according to reporting from CyberScoop, CNN and The Register based on research from Israeli cybersecurity firm Dream. The campaign ran from July 1 to July 4 across 12 attack waves. It was not magic. It was automated intrusion work, stitched together from tools anyone can download.
That should bother you.
Dream, the cybersecurity firm co-founded by former Austrian chancellor Sebastian Kurz, found the attack because the operators left a 160MB archive exposed online. The Register reported that the archive contained 1,395 files documenting the operation. The Financial Times first reported Dream's findings and identified Taiwan as the target, while Taiwan's Ministry of Digital Affairs said on August 13 that overseas hackers had used AI agents, including OpenClaw, in attacks on government agencies in July.
Dream did not name a specific hacking group. Taiwan did not name China. The evidence still points in that direction, with researchers citing Simplified Chinese in the operational material, but cyber attribution is not a parlor game. If you get it wrong, you create a new problem while pretending to solve the old one.
Microsoft Scout brings OpenClaw’s agent model into the office Microsoft launched Scout at Build as an always-on AI assistant built on OpenClaw for Microsoft 365. The product could make personal agents useful at work, but its success depends on trust, controls and whether autonomy actually reduces friction. - how to implement agent AI in enterprise workplaces - personal AI assistant software for Microsoft 365 integration
The agents did ordinary hacking faster #
Two open-source frameworks did the work. The attackers built the system on Hermes and OpenClaw, according to Dream's research and reporting from CyberScoop and The Register. The framework deployed up to eight sub-agents, each taking on part of the job: reconnaissance, credential attacks, lateral movement, vulnerability research. One agent found a weak route in. Another tested credentials. Another looked for the next place to move.
That is the point. The attack did not need a secret zero-day to matter.
The Register reported that one exposed system gave up a full user database without authentication, including names, departments and SSO account IDs. No login required. The agents also found hidden API endpoints that returned valid authenticated sessions without requiring user credentials, then used harvested usernames, predictable password patterns and automated CAPTCHA solving to break into 85 government accounts - and eighty-four of those accounts then worked against an internal information system, giving the attackers access to dashboards, equipment management pages and personnel statistics.
Those are dull failures. Dull failures count.
The target list widened as the system worked. The agents moved from government portals into a government email server, IT supply-chain vendors, Taiwan's nuclear safety agency and at least seven energy companies, according to Dream's findings as reported by CyberScoop and The Register. That does not prove every downstream target was damaged in the same way. It does show how quickly an automated system can turn one weak secondary service into a wider map of useful targets.
The open-source detail is the real warning #
Frankly, this is the part every company rushing to deploy autonomous agents should sit with. Hermes and OpenClaw were not built as hacking platforms. They are general-purpose agent frameworks. The attackers used them because agent software is good at breaking a large task into smaller jobs and then adapting when one path fails.
That same pattern is why businesses like agents in the first place. You ask for a multi-step job, the software plans, calls tools, checks results and keeps going. In customer service or coding, that can save time. In a cyberattack, it can compress the work that used to need more human attention.
Claude AI Suffers Widespread Outage Across All Its Models on August 18 Claude went down across every major model on August 18, with Downdetector logging more than 4,000 user reports within an hour and Anthropic's status page offering no root cause. The outage is the latest in a run of at least seven incidents over the prior six days, hitting Claude Chat, the mobile app and Claude Code. - claude AI outage August 18 all models down - anthropic status page confirms widespread Claude errors today
Dream told CyberScoop that the framework still showed signs of human tuning. That matters. This was not a movie version of AI waking up and deciding to attack a government on its own. It was closer to an operator setting up a machine that could keep making tactical choices after the launch. The difference may sound small until you're the defender watching it move across systems faster than your team can triage alerts.
The guardrail bypass was just as plain. Dream said the operators framed the work as authorized penetration testing, which helped the agents move through tasks they should have refused. There is no comfort in that. If a safety system can be talked around with the oldest excuse in security testing, then the barrier is not yet strong enough for the risk.
Taiwan's Ministry of Digital Affairs said the affected agencies had completed their response and that the government would keep strengthening monitoring for further attack paths. Good. But the lesson is bigger than Taiwan. If your backup system, test portal or forgotten API endpoint can hand out credentials, an agentic attack will not politely stay on the front door. It will find the side entrance and keep walking.
Also read: Moonshot AI's Kimi K3 Undercuts GPT and Claude While Proving Its Numbers • A Federal Judge Ruled Judges Are Immune Even If AI Wrote Their Rulings • CoreWeave Posts a Blowout Quarter Right as AI Bubble Fears Peak