Israeli cybersecurity firm Dream said it has documented what it calls the first known cyberattack on a government carried out almost entirely by autonomous AI agents, with minimal human steering throughout the operation.

According to a Dream research report published August 12, the campaign ran for four days in early July against government networks in Taiwan. Attackers deployed up to eight AI sub-agents at once, built on the open-source Hermes and OpenClaw agent frameworks, alongside custom tooling for automated vulnerability scanning and CAPTCHA solving.

How the operation unfolded

Dream said the agents ran “learning cycles” — autonomous sessions in which the models searched vulnerability databases, GitHub repositories, and security research for exploitable weaknesses, then tested and refined their own attack chains using probability-based scoring to prioritize findings. Across 12 documented waves, the system mapped 21 connected government systems, found more than 36 unauthenticated API endpoints, and cracked 85 credentials, according to the report. It went on to obtain seven single sign-on client secrets and six database credentials, exfiltrate over 2,500 personnel records, and install persistent backdoors. The operation later expanded from its original targets to IT supply-chain vendors, a nuclear safety agency, a government email system, and more than seven energy-sector companies, Dream said.

Who’s behind it

Dream has not formally attributed the campaign to a specific group. But researchers said linguistic analysis of the operators’ internal notes — which mixed Simplified Chinese in planning documents with Traditional Chinese in target-facing analysis — points to a mainland Chinese-language operator. The attackers reportedly bypassed the AI models’ safety guardrails by framing their activity as authorized penetration testing.

Why it matters

The findings arrive amid mounting evidence that AI agents are already being weaponized for real intrusions: a Chinese hacker used DeepSeek’s models for autonomous cyberattacks earlier this year, and OpenAI’s own Cyber model recently crossed a “high” risk threshold for cyber capability. Dream’s report suggests government networks are now a live target for this kind of largely unsupervised operation, not just a hypothetical risk.

Dream said each of its findings underwent six separate retests before publication, and that Taiwanese authorities had not publicly confirmed the details as of its report.