Taiwan confirms it was targeted by an AI-driven hacking campaign linked to China

Started by Dean95, Today at 07:44 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Taiwan confirms it was targeted by an AI-driven hacking campaign linked to China   Views(Read 19 times)
Active members in this topic:
Dean95(1)

Dean95

Taiwan says it detected an AI assisted cyberattack on government agencies last month coming from overseas, confirming findings from Israeli cybersecurity company Dream, which said in a blog post that a coordinated team of AI agents worked together over four days to steal credentials, personnel records and scan government infrastructure for vulnerabilities

Dream said the AI agents extracted scores of passwords from unidentified officials, stole personnel records from Taiwan's justice ministry, and scanned its nuclear safety agency for vulnerabilities, according to a separate report from Cyber Security News the operation compromised at least 85 government accounts, extracted more than 2,500 personnel records, and expanded its reach to Taiwan's nuclear safety agency and at least seven energy companies before being detected, at its peak the attack ran as many as eight AI agents working simultaneously, surveying 21 different government systems over the four day window in early July, Dream said it was able to reconstruct the entire campaign after recovering the agents' complete operational workspace, though the company's own policy prevented it from formally naming a specific hacking group or officially confirming the identity of the victim when approached by Reuters, the Financial Times, which was first briefed on Dream's findings, identified the target agencies as Taiwanese

Taiwan's own statement described the incident as a hybrid approach combining manual operations with assistance from AI agents such as OpenClaw, and said the affected government bodies successfully contained the intrusion, evidence pointed toward a China link specifically, internal communications tied to the operation used Simplified Chinese, while the stolen material that came back from the targeted systems appeared in Traditional Chinese, the specific written form used on government websites in Taiwan, Hong Kong and Macau, a detail Dream said made it highly likely the operator was linked to China, Amir Becker, Dream's chief strategy officer and a former head of cyber operations at Israel's elite Unit 8200, called the incident an unprecedented end to end autonomous attack on a government target, saying the system behaved like a coordinated cyber team rather than a single automated script

The threat of AI assisted hacking has been building for years but has genuinely accelerated over the past few months specifically following the release of more capable AI models from top labs, including Anthropic's Mythos, that are considerably better suited to autonomous, multi step offensive operations than earlier generations, in a related but separate case documented by Palo Alto Networks' Unit 42, a different Chinese speaking threat actor using the aliases knaithe and KnYuan used the DeepSeek AI model, run through the same Hermes Agent system, specifically to find targets, retrieve exploit code, and attack seven separate security systems

Cris Thomas, a security researcher and advocate at code security company Semgrep, offered a genuinely important note of caution about how this story should actually be understood, saying the spy campaign illustrates just how quickly AI assisted hackers could hit their mark, but explicitly warned against exaggerating the power of AI agents involved, there's still a human in there somewhere, he said, somebody had to choose who to attack, had to establish an objective and give it a directive, it's not totally 100 percent autonomous, there was a capable operator in charge that did that

Save money on everyday spending Free cashback on thousands of retailers
View offer