CRBC News
Security

Taiwan Detects AI-Assisted Hacking Campaign From Overseas; Agencies Say Breach Contained

Taiwan Detects AI-Assisted Hacking Campaign From Overseas; Agencies Say Breach Contained
Silhouettes of laptop users are seen next to a screen projection of binary code are seen in this picture illustration taken March 28, 2018. REUTERS/Dado Ruvic/Illustration

Taiwan's Ministry of Digital Affairs reported that AI-assisted cyberattacks in July originated overseas but were contained by affected government units. Investigators said the campaign combined manual operations with AI agents — including a tool called Open Claw — and prompted cross-agency warnings beginning July 20. Israeli firm Dream separately described a four‑day AI-driven operation that stole passwords and personnel records; the Financial Times identified the targets as Taiwanese agencies. Authorities have issued protective guidelines and bolstered monitoring as experts warn human operators still direct AI-enabled hacking.

Taiwan's Ministry of Digital Affairs said on Thursday that cybersecurity teams detected AI-assisted attacks last month that targeted several government agencies and originated from overseas. Officials said the affected units successfully contained the incident and completed remediation.

The ministry said its monitoring systems flagged an "abnormal attack" in July. Beginning on July 20, the National Institute of Cyber Security issued a series of warning alerts while investigators examined the activity. The probe found clear signs of an overseas origin and a hybrid approach that combined manual operations with AI-agent assistance, including a tool identified as Open Claw.

"The relevant attack sources, methods, and scope of impact have all been fully investigated, and the affected units have successively completed their handling," the ministry said.

Separately, Israeli cybersecurity firm Dream published a blog post describing an AI-driven campaign that exfiltrated credentials and personnel data from an unnamed Asian government. Dream said it reconstructed the operation after recovering the agents' "complete operational workspace," and described a coordinated set of AI agents working together to extract scores of passwords, copy personnel records from the justice ministry and scan a nuclear safety agency for vulnerabilities over four days. Dream declined to share the raw data or formally name the target; the Financial Times, which was briefed on Dream's findings, identified the targeted agencies as Taiwanese.

Broader Context and Expert View

Cyber intrusions are part of what Taipei calls China's "hybrid warfare" campaign — a mix of military pressure, disinformation and cyber activity. In January, Taiwan's National Security Bureau reported a 6% rise in cyberattacks on critical infrastructure in 2025, to an average of 2.63 million attempted attacks per day, and said some intrusions were timed to coincide with military drills.

Security experts say the arrival of more capable AI models has accelerated reconnaissance and exploitation, enabling attackers to scan targets and escalate operations faster than before. Cris Thomas, a security advocate at code‑security firm Semgrep, stressed that human operators still direct these campaigns: "There's still a human in there somewhere. Somebody had to choose who to attack, had to establish an objective and give it a directive. It's not totally 100% autonomous."

Government Response

In response to the incident, Taiwan said it has issued protective guidelines and strengthened cross-agency monitoring to detect and block similar attacks earlier. The ministry's statement did not name China, and China's Taiwan Affairs Office did not immediately respond to a request for comment.

(Reporting based on statements from Taiwan's Ministry of Digital Affairs and public reporting by cybersecurity firm Dream and media outlets.)

Help us improve.

Related Articles

Trending