Suspected China-linked hackers used AI agents to attack Taiwan government networks
Translated from Korean, summarized and contextualized by DistantNews.
At a glance
- Suspected China-linked hackers used autonomous AI agents to attack Taiwan's government computer networks.
- The AI agents, based on open-source systems, explored government systems for vulnerabilities over four days, compromising at least 85 accounts and leaking personnel data.
- The attack expanded to Taiwan's nuclear safety agency and energy companies, marking the first confirmed fully autonomous cyberattack on government institutions.
Suspected China-linked hackers deployed autonomous artificial intelligence agents to breach Taiwan's government computer networks, according to a report by the Financial Times citing Israeli cybersecurity firm 'Sygnia'. The hackers utilized open-source AI agent systems, 'Hermes' and 'OpenCLO', to construct a hacking tool capable of running up to eight agents simultaneously. These AI agents are designed to autonomously plan and execute tasks based on user instructions.
This is the first confirmed autonomous attack from start to finish targeting government agencies.
Over four days in early July, the AI agents systematically scanned 21 government systems for vulnerabilities. When encountering blocked infiltration routes, they deployed other agents to gather information from the internet and devise new attack methods. Sygnia reported that this process compromised at least 85 government user accounts and led to the leakage of over 2,500 personnel-related documents. The attack subsequently expanded to Taiwan's nuclear safety regulatory body and at least seven energy companies.
Amir Eitan, Sygnia's Chief Strategy Officer, told the Financial Times that this was the first confirmed autonomous cyberattack from start to finish targeting government agencies. He advised governments worldwide to operate under the assumption that they are under constant cyberattack. Sygnia did not identify the specific hacking group but inferred a connection to China based on the use of simplified Chinese characters during the attack, although the leaked data was in traditional Chinese, commonly used in Taiwan.
Governments worldwide should operate under the assumption that they are under constant cyberattack.
Taiwan's Digital Development Ministry declined to comment on the extent of the damage. However, the ministry acknowledged that AI is transforming cyberattacks, stating that AI agents present a dual challenge by automating attacks while also becoming a new vulnerability themselves.
AI agents automate attacks and also become a new vulnerability themselves.
Originally published by Dong-A Ilbo in Korean. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.