Suspected China-linked hackers used several autonomous AI agents to map and attack Taiwanese government systems. The attack could be a clear sign of how generative AI is transforming the cyber threat landscape from automated tools to systems that can make their own decisions and adapt their attacks.
Artificial intelligence has been used to streamline cyberattacks for several years. AI can help attackers create phishing emails, analyze code, identify vulnerabilities, and automate parts of an attack.
The attack on Taiwan shows a potentially much more advanced development.
According to data reported by the Financial Times, Israeli cybersecurity firm Dream discovered an operation in which up to eight autonomous AI agents were working in parallel against Taiwanese government systems.
The attack was carried out in early July 2026 and involved a total of 21 systems.
At least 85 accounts were reportedly compromised and more than 2,500 personnel-related records were extracted.

AI agents worked in parallel
What makes the attack particularly interesting from a cybersecurity perspective is the degree of automation.
The AI agents were not used solely as assistants to human attackers.
According to the report, they were able to conduct mapping, identify possible paths into the systems and adapt their methods when conditions changed.
Multiple agents could simultaneously work against different parts of the infrastructure.
When one method did not work, the systems could analyze the situation, search for additional information, and re-prioritize the attack.
It is starting to resemble a distributed cyber team where several specialized actors work in parallel, but where parts of the work are performed by AI.
21 systems were attacked
The operation targeted 21 Taiwanese government systems and was reportedly expanded to include activities related to nuclear safety and energy.
At least 85 accounts were compromised.
The attackers are also said to have managed to gain access to more than 2,500 personnel records.
Dream has not formally attributed the operation to a specific Chinese state actor.
However, the presence of simplified Chinese in parts of the operation is cited as a factor that contributed to the suspicion of a connection to China.
It is therefore important to distinguish between technical indicators and confirmed attribution. Determining with certainty who is behind an advanced cyber operation typically requires significantly more evidence.
From automation to autonomy
Cyberattacks have been automated for a long time.
Botnets can scan the internet for vulnerable systems. Malware can automatically spread between computers. Attackers use scripts to test passwords, gather information, and exploit known vulnerabilities.
AI agents however, introduces another dimension.
The difference lies in the ability to analyze the results of an action and then choose the next step.
A traditional script essentially follows a predetermined sequence.
Instead, an AI agent can be given a goal, use different tools, analyze the results, and change its strategy as it works.
It is this combination of autonomy, tool use and adaptability which can change the threat landscape.
Research shows rapidly increasing capacity
The development has already been noted in security research.
A research study published in June 2026 tested 19 open and proprietary language models in environments where they would conduct autonomous penetration tests.
The models achieved success rates between 10.7 and 69.3 percent depending on the model and test environment.
The researchers also noted that the ability for autonomous penetration continues to improve as general AI models become more capable.
What was previously primarily a theoretical risk is thus beginning to take on greater practical significance.
Defenders' time window may shrink
One of the biggest consequences for companies and authorities is speed.
Traditional advanced attacks often require humans to conduct reconnaissance, analyze information, and make decisions about the next step.
If parts of this process can be delegated to autonomous AI agents, the same work can be carried out in parallel and on a significantly larger scale.
An attacker can potentially deploy multiple agents to simultaneously investigate different systems, identities, and vulnerabilities.
It can reduce the time between a weakness being identified and it actually being exploited.
For security organizations, this means that manual processes risk becoming too slow.
AI is changing both sides of cybersecurity
The same technology is used simultaneously on the defense side.
AI-based security platforms can analyze large amounts of telemetry, identify anomalous behavior, and help security teams prioritize incidents.
This creates a development where both attackers and defenders gain access to increasingly autonomous systems.
The next step in cybersecurity can therefore become an environment where AI agents do not just assist humans.
They can increasingly encounter other AI agents.
For businesses, this means that issues of identity, authorization, monitoring, and automated response are becoming increasingly important.
An organization no longer needs to be able to simply identify what a human user or traditional program is doing.
It must also be able to understand what an autonomous agent is trying to do, what resources it is using, and what permissions it should actually have.
A new phase in the cyber threat
The attack on Taiwan is particularly important because it illustrates how quickly the line between AI-assisted and AI-driven is blurring. cyber operations is changing.
That doesn't mean human attackers are going away.
People can still set the targets, choose victims, and control the infrastructure.
But increasingly large parts of the operation itself can be automated.
When AI systems can map environments, analyze results, choose tools, and adapt next steps, the economics behind it also change. cyberattacks.
A small group of attackers can potentially carry out operations that would have previously required significantly greater resources.
For CIOs, CISOs and security organizations, the question is no longer just how to protect AI.
It also becomes how the organization defends itself when AI itself becomes part of the attacker's operational capabilities.








