On August 17, 2026, the world faced an unprecedented challenge in the field of cybersecurity. According to data from the Israeli company Dream, Taiwan's government infrastructure became the first victim of a successful cyberattack carried out by an autonomous artificial system. The perpetrators, allegedly acting on behalf of China, used advanced algorithms to steal over 2,500 personnel records and disrupt the operation of critical state systems.

A New Era of Cyberwarfare: Autonomous AI Agents

The operation revealed by Dream marked a shift from traditional cyberattacks to the use of fully autonomous systems. Unlike previous incidents where AI required constant human control, in this case, the attackers configured the system to adapt to the target's defenses independently. The attack was built on two popular open-source AI frameworks — Hermes and OpenClaw — which allowed the system to conduct "learning cycles" in real-time.

The AI independently searched for vulnerabilities in databases, GitHub repositories, and security publications, using the obtained information to continue the operation. The system also analyzed its own errors and corrected its subsequent actions, making it practically invulnerable to traditional defense methods.

Scale of the Attack: From Personnel Data to the Energy Sector

The perpetrators did not limit themselves to the initial targets. The AI simultaneously expanded its search to IT system suppliers for government organizations, included the nuclear safety agency, the state postal system, and more than 7 energy sector companies. The system looked for misconfigurations, open administrative interfaces, and exploitable vulnerabilities.

As a result of the attack, over 2,500 personnel records were stolen, posing a serious threat to Taiwan's national security. Furthermore, the disruption of the energy sector could lead to serious economic consequences and destabilization in the region.

Technical Details: How to Bypass Defenses

Dream discovered traces of the operation in an online archive of 160 MB containing almost 1,400 files. They revealed the architecture of a multi-agent AI system which, according to the company's assessment, actually gained access to government systems. To bypass built-in AI limitations, the perpetrators presented the executed work as authorized penetration testing.

The discovered system used Bayesian prioritization (selecting the most promising targets based on updated probability assessments), self-correction cycles, and adaptive search stages. These technologies allowed the system to effectively avoid detection and continue the attack even in the presence of complex security measures.

Contradictory Data: The Role of Humans in the Operation

While Dream claims that the attack was almost entirely autonomous, the company notes that such an operation required system configuration for a specific task, optimization of AI agent interaction, and adjustment of decision-making logic. This means that the attack did not happen completely without human involvement.

Previously, the company Anthropic also reported the first autonomous cyberespionage campaign, but at that time, experts pointed out a significant volume of human participation. This creates a contradiction in assessing the degree of AI autonomy in cyberattacks and requires further research.

Conclusions and Consequences

The cyberattack on Taiwan, carried out using an autonomous AI system, represents a serious challenge for global cybersecurity. It demonstrates that attackers are already capable of using advanced technologies to conduct complex operations without constant human intervention. This requires a rethinking of approaches to protecting critical infrastructure and the development of new methods to counter autonomous AI attacks.