Hackers suspected of being linked to China reportedly used artificial intelligence (AI) agents to attack Taiwan government agencies. Multiple AI agents simultaneously looked for vulnerabilities and changed infiltration routes depending on the situation. With at least 85 government agency account users in Taiwan hacked and more than 2,500 personnel records leaked, and with targets expanding to nuclear safety authorities and energy corporations, concerns are growing that AI-enabled cyberattacks are becoming more sophisticated.

Illustration=ChatGPT

According to the Financial Times (FT) and Reuters on the 12th local time, Israel AI and cybersecurity corporation Dream confirmed that an AI agent–based cyberattack occurred over four days early last month against a government in the Asia-Pacific region. A person familiar with the target told the FT that the country was Taiwan.

The hackers are said to have built an autonomous attack tool that made multiple AIs move like a single hacking group by using open-source AI agents available to anyone. Up to eight AI agents operated at the same time during the attack.

The AI agents mapped the structures of 21 government systems and probed for vulnerabilities. If a particular intrusion method was blocked, another AI agent searched the internet for related information and devised a new attack method in response. Based on the information obtained, they kept filtering for the most promising routes and continually adjusted the attack priorities.

As a result, at least 85 Taiwan government agency account users were hacked, and more than 2,500 personnel records were leaked. The targets then expanded to Taiwan's nuclear safety authorities and at least seven energy corporations.

Dream did not conclude that a particular hacking group was responsible for the attack. However, it analyzed that the hackers were likely linked to China, citing factors such as the discovery of simplified Chinese characters commonly used in mainland China in internal communications exchanged during the operation. Traditional Chinese characters, commonly used in Taiwan, Hong Kong and Macau, were found in materials obtained from the targets.

Taiwan has long been a prime target of China-origin cyberattacks. According to Taiwan's National Security Bureau (NSB), China's cyberattacks targeting Taiwan averaged 2.6 million a day last year, up 6% from the previous year.

Taiwan's government also confirmed that the cyberattack did in fact occur. According to Reuters, the Ministry of Digital Affairs said government agencies were hit by AI-enabled cyberattacks and that the authorities' cybersecurity systems detected them early and the agencies responded. It did not provide specifics about the attack, citing confidentiality. Chinese authorities also did not provide a separate comment to the FT on the matter.

The attack used the open-source AI agent systems Hermes and OpenClaw. Dream's researchers discovered 160 megabytes (MB) of online materials while investigating the activities of cyber threat actors. An analysis of 1,395 files included in the materials confirmed that the two AI agent systems were used in the hack.

A device used to run OpenAI is pictured. The photo is unrelated to the article. /Courtesy of Reuters·Yonhap News

However, it was not identified which base AI model powered the agents. The researchers analyzed that the hackers bypassed safety features applied to the base model by instructing the AI in a way that disguised the real attack as an authorized security check to assess system vulnerabilities.

What makes this attack notable is that AI did not merely assist the hackers' work but carried out a significant part of the operation on its own. Amir Becker, Dream's chief strategy officer (CSO), said he had not previously seen a case in which AI autonomously executed an attack from start to finish against government agencies. Becker, the CSO, once led cyber operations in Israel's Unit 8200.

The cyber capabilities of AI models have recently emerged as a major security concern for tech corporations. Anthropic, OpenAI and Meta have also reported instances in which unexpected cyberattacks were attempted during tests of new AI models.

In the industry, there are also concerns that if AI agents are fully leveraged for hacking, the speed and scale of cyberattacks could grow further. Becker, the CSO, advised that governments should prepare on the premise that they are effectively exposed to constant cyberattacks due to the advent of AI tools. As autonomous attacks using AI spread, the cybersecurity defense burden on government agencies and key infrastructure such as energy is expected to increase.

※ This article has been translated by AI. Share your feedback here.