On August 13, Taiwan's Ministry of Digital Development revealed information regarding a cyberattack on government institutions utilizing AI agents. According to Reuters, this was disclosed in a statement from the ministry.
The ministry reported that the attack originated from abroad. The attackers operated both manually and with the assistance of AI-based tools, including OpenClaw.
Unusual activity in the digital security system was detected in July, prompting the National Cyber Security Institute to issue warnings to government bodies and initiate an investigation. All organizations impacted by the incident have taken necessary steps to ensure their security, the ministry stated.
In response to the attack, authorities developed recommendations to mitigate similar threats and enhanced monitoring of government systems.
In 2025, cyberattacks targeting Taiwan's critical infrastructure rose by 6%. According to the National Security Bureau, the average number of daily attacks reached 2.63 million. Some of this activity has previously been attributed to "hybrid threats" from China.
Details of the Attack
On July 29, the Israeli cybersecurity firm Dream reported an attack on an unnamed government in Asia. Journalists from Reuters believe this incident pertained to Taiwan.
Researchers managed to reconstruct the operational environment used for the hacking, which conducted 12 waves of attacks over four days using publicly available tools.
85 employee accounts were compromised, with 84 individuals inadvertently granting attackers access to internal networks. Over 2,500 personnel documents, login credentials for internal databases, and network infrastructure schematics were obtained.
The attack subsequently extended to contractors of government IT systems, the nuclear safety authority, government email, and seven energy companies. Dream emphasized that the key factor in this breach was not technical novelty but the level of autonomy.
AI agents enabled simultaneous scanning of multiple systems for vulnerabilities and executing attacks at a pace unattainable by humans. Experts believe that such tools are shifting the balance of power, allowing attackers to exploit common infrastructure weaknesses, provided they can do so at machine speed.
It’s noteworthy that in late March, CertiK analysts alerted about the risks associated with OpenClaw, identifying potential threats such as data leaks, local gateway hijacking, prompt injections, and attacks via third-party plugins. The Cyber Center of China also issued similar warnings.
