
On August 13, Taiwan’s Ministry of Digital Affairs disclosed details of a cyberattack on government agencies involving AI agents. This was reported by Reuters, citing a statement from the ministry.
According to the regulator, the attack originated from abroad. The perpetrators operated manually and through AI-based assistants, including OpenClaw.
Anomalous activity in the digital security system was detected in July. At that time, the National Institute of Cybersecurity began issuing warnings to government agencies and investigating the incident. All organizations affected by the incident have taken necessary measures and are now secure, the ministry stated.
Following the attack, authorities prepared guidelines to protect against similar threats and enhanced monitoring of government systems.
In 2025, the number of cyberattacks on Taiwan’s critical infrastructure increased by 6%. According to the National Security Bureau, the average number reached 2.63 million per day. The island’s authorities have previously linked some of this activity to “hybrid threats” from China.
How the Attack Occurred
On July 29, Israeli cybersecurity company Dream reported an attack on an unnamed Asian government. Reuters journalists believe it was Taiwan.
Researchers managed to reconstruct the working environment of the system used for the breach. Over four days, it conducted 12 waves of attacks using publicly available tools.
Eighty-five employee accounts were compromised, with 84 of them voluntarily granting attackers access to internal networks. The attackers obtained over 2,500 personnel documents, logins and passwords for internal databases, and network infrastructure diagrams.
The attack then spread to contractors of government IT systems, the nuclear safety agency, government email, and seven energy companies. Dream emphasized that the key factor was not technical novelty but autonomy.
AI agents allowed for simultaneous scanning of multiple systems for vulnerabilities and conducting attacks at a pace unattainable by humans. Experts believe such tools shift the balance of power: attackers increasingly need only typical infrastructure weaknesses, provided they can exploit them at machine speed.
In late March, analysts at CertiK warned of the risks associated with OpenClaw. Potential threats included data leaks, local gateway hijacking, prompt injections, and attacks via third-party plugins. The Cyber Center of China also issued a warning.
