
A multi-agent hacking platform assembled from publicly available artificial-intelligence software has been linked to a campaign against government systems in Taiwan, raising new concerns about the use of autonomous agents in cyber operations across the Asia-Pacific region.
Researchers at Israeli cybersecurity company Dream said the platform compromised at least 85 user accounts and extracted more than 2,500 personnel records. The operation reportedly ran for four days in early July and mapped 21 government systems before expanding towards a nuclear-safety agency, energy companies, government suppliers and other targets.
The attackers used as many as eight AI agents simultaneously. Individual agents were assigned functions such as mapping networks, researching vulnerabilities, attempting intrusions and developing alternative techniques when an attack route failed. Instead of executing a fixed sequence of commands, the system reportedly evaluated available information, ranked potential attack paths and redirected activity as conditions changed.
Dream reconstructed the operation from a 160-megabyte archive containing 1,395 files. The archive indicated that the platform had been assembled using two downloadable, open-source agent systems rather than a purpose-built offensive product. Researchers could not determine which underlying language model powered the agents. They found evidence suggesting that model safeguards had been bypassed by describing the operation as an authorised penetration test.
Taiwan’s Ministry of Digital Affairs separately confirmed that monitoring units detected abnormal, overseas-originated attacks against government agencies during July involving a combination of manual activity and AI-agent assistance. The ministry said the affected organisations had handled the incident. The evidence available publicly does not conclusively establish that the ministry-confirmed activity and the operation reconstructed by Dream are the same campaign.
Attribution also remains unresolved. Dream did not identify a specific state or hacking organisation. Internal communications found in the archive were written in Simplified Chinese, while material taken from the target used Traditional Chinese. Researchers said those indicators supported a high probability of a connection to China but stopped short of a definitive attribution.
Taiwan’s National Security Bureau said earlier this year that the island experienced an average of 2.6 million Chinese cyberattacks per day during 2025, 6% more than in the previous year. Energy infrastructure registered one of the sharpest increases in targeting. Taiwan’s semiconductor manufacturing base, government agencies and critical infrastructure have long faced sustained cyber-espionage pressure.
The incident expands the Asia-Pacific security implications of readily available AI-agent frameworks. Indian government systems, banks, telecommunications companies, energy operators and technology-services providers operate similarly complex identity, cloud and software-supply-chain environments. CERT-In has already warned that frontier AI systems can accelerate vulnerability discovery, exploit development, reconnaissance and multi-stage attacks, and has recommended zero-trust controls, stronger authentication and AI-assisted defensive monitoring.




