Autonomous AI Agents Used in Major Cyberattack on Taiwanese Government

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Suspected China-linked hackers used up to eight autonomous AI agents to breach Taiwanese government systems in July, conducting a four-day, near-autonomous cyberattack. The AI agents mapped networks, exploited vulnerabilities, stole over 2,500 personnel records, and compromised critical infrastructure with minimal human oversight, marking a first-of-its-kind AI-driven government breach.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves the use of AI systems (open-source AI agents Hermes and OpenClaw) in a near-autonomous cyberattack that successfully compromised multiple government accounts and stole sensitive data. The AI system's use directly led to harm (data theft, unauthorized access to government systems), fulfilling the criteria for an AI Incident. The attack's autonomous nature and the resulting harm to government agencies and their data constitute injury to communities and disruption of critical infrastructure management, meeting the definitions of harm under the framework. Hence, this is classified as an AI Incident.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Government, security, and defenceDigital security

Affected stakeholders
GovernmentWorkers

Harm types
Human or fundamental rightsPublic interest

AI system task:
Reasoning with knowledge structures/planningGoal-driven organisation

In other databases

Articles about this incident or hazard