In a hacking campaign last month believed to be linked to China, artificial intelligence (AI) agents launched 12 waves of attacks against the government in four days, which is believed to be the first disclosed case of a fully AI autonomous attack against a government.
The Financial Times on Wednesday last week reported that researchers at Dream Security, an Israeli AI company, were the first to detect the intrusion. Dream Security showed that the attackers used open-source AI agents, such as OpenClaw, to build an autonomous hacking tool that coordinated the cyberintrusion, describing it as “a first-of-its-kind breach.”
Researchers said that internal communications linked to the cyberattack were in simplified Chinese, suggesting the operators were likely connected to China.
Taiwan is no stranger to China’s “hybrid warfare,” from military drills and disinformation campaigns to escalating cyberattacks. According to the National Security Bureau, Taiwan’s critical infrastructure and government networks faced an average of 2.6 million cyberbreaches per day from China last year, a 6 percent increase from 2024.
However, last month’s AI-driven cyberintrusion was an advanced tactic, involving a hybrid approach combining manual operations and conventional hacking with AI agents. AI might become the main player in cyberattacks, moving beyond simply assisting human hackers.
The reports have triggered deep concern domestically and internationally.
The Ministry of Digital Affairs said in a statement that its Administration for Cybersecurity detected last month’s cyberattack, which it said originated overseas, and immediately launched an investigation. The ministry warned that AI agents could rapidly integrate multiple attack techniques.
The threat of AI-assisted hacking has escalated dramatically with international AI labs releasing more advanced models that can rapidly conduct reconnaissance, identify vulnerabilities and take advantage of their findings.
Numerous reports have documented cases of advanced AI models conducting unauthorized actions without human intervention, raising fears of the proliferation of AI-enabled cyberattacks. OpenAI and Anthropic reported that their new models have escaped test environments and hacked into other systems.
The cyberattack on Taiwan has demonstrated how autonomous AI agents could change the nature of cyberwarfare. If AI with autonomous decisionmaking capabilities were weaponized by malicious nations or criminal groups, all individuals, corporations, critical networks and infrastructure, or even entire countries, would be targets. It could also significantly reduce the cost of attacks, while the effort to defend against them becomes more difficult.
Taiwan faces a challenge that Western democracies also have to confront. Dream Security chief strategy officer Amir Becker, a former head of the Israel Defense Forces’ cyberoperations and signals intelligence division, said that the advent of AI tools means governments must assume that they face a permanent cyberattack.
The spread of autonomous AI systems has raised pressing questions about legislative responses, technical protections and the ability of governments to respond to threats.
President William Lai (賴清德) has vowed to make Taiwan a “Smart Nation 2.0,” with plans to invest more than NT$1.5 trillion (US$46.99 billion) by 2040 in the “Ten New AI infrastructure Projects.”
Besides promoting the AI economy, Taiwan urgently needs to upgrade its cyberdefense strategy to safeguard digital sovereignty, which is crucial to national sovereignty.
In addition to improving information systems, a robust national digital defense is needed, meaning that legislation and technical capabilities need to be enhanced. That includes the digital resilience of critical infrastructure and networks, advanced surveillance to oversee system vulnerabilities and operational risks, multiple lines of defense to block attacks in a timely manner, and backup systems to ensure operational sustainability.
Cybersecurity cannot be a matter of “each taking care of their own business.” Governments, businesses and the cybersecurity community must work together to improve defensive resilience to minimize the damage from attacks.
Taiwan also needs to deepen cooperation with like-minded countries to establish a cross-border real-time AI security intelligence-sharing mechanism, partnering with international AI security organizations to enhance algorithmic defenses and combat cyberattackers’ supply chains.
If a country cannot protect its digital sovereignty, it might lose its national autonomy. Taiwan must be prepared in every aspect of national defense.
For the last 15 years, China has relied on gray zone operations to advance its territorial ambitions across Asia. And for 15 years, the US has struggled to respond. But the open door on which China has been pushing may finally be closing. Gray zone operations involve the assertive use of a variety of tools in ways that create conditions that can be described as neither peace nor war. Military forces might act provocatively — even dangerously — while carefully avoiding violence, whereas law enforcement employs nonlethal violence as a first resort. Such an approach creates difficult calculations for its targets.
EDITORIAL CARTOON
President William Lai (賴清德) late last month received a delegation of Polish members of the European Parliament at the Presidential Office — the first single-party, single-nation delegation from the EU legislature to visit Taipei in nearly two terms. The group, led by former Polish prime minister Beata Szydlo, also met Legislative Yuan Speaker Han Kuo-yu (韓國瑜), a gesture spanning Taiwan’s political divide. For most Taiwanese observers, this was a pleasant, if minor, diplomatic event. It was much more than that — and the timing matters. Within the same fortnight, Hudson Institute senior fellow Ken Moriyasu said in the Washington Examiner
It was shocking to hear Legislative Speaker Han Kuo-yu (韓國瑜) say that the legislative branch is somehow now under the control of “dark forces.” Frustrated at the glacial pace of the passage of the government’s annual budget for this year — it was finally passed at 6:08pm on Friday after a record delay of 266 days — Han had lost his temper during a cross-caucus negotiation meeting on Tuesday. The target of his ire was Chinese Nationalist Party (KMT) caucus whip Fu Kun-chi (傅崐萁), who was absent that day. Fu had failed to attend the cross-caucus negotiations on a total of