
AI agents are moving from demos and productivity tools into real cyber operations. A new report says suspected China-linked hackers used publicly available AI agents in an autonomous cyberattack against Taiwanese government-linked systems, making the warning around agentic AI much more concrete.
The Financial Times reports that researchers at Israeli AI cybersecurity company Dream found evidence of an autonomous AI-based attack that ran over four days in July. The system reportedly used eight agents to map systems, compromise targets and extract data, including more than 2,500 personnel records.
The reported targets included Taiwanese government infrastructure, Taiwan’s nuclear safety agency and energy companies. Dream did not publicly name Taiwan in its own materials, but the FT said evidence such as language patterns and the affected systems pointed strongly in that direction. Taiwanese authorities declined to comment on the specific case.
This is important because it suggests AI agents are beginning to compress parts of the hacking workflow. Traditional cyber operations involve reconnaissance, vulnerability discovery, exploitation, persistence, data extraction and cleanup. If agents can coordinate parts of that process, even imperfectly, the cost of running more attacks could fall.
That does not mean AI agents have replaced human hackers. Human operators still choose targets, supply infrastructure, interpret results and decide what to do with stolen data. But agentic tools can make the process faster and more scalable. They can test systems, chain actions and run tasks continuously in a way that changes the economics of cyber conflict.
Taiwan is already one of the world’s most heavily targeted cyber environments because of its strategic position and tensions with China. CSIS has tracked repeated cyber incidents involving Taiwan and Chinese groups, including attacks on government systems and critical infrastructure. AI agents add a new layer to that existing pressure.
The story also connects directly to the wider agent-risk debate. We recently wrote about xAI’s Grok Bot and always-on AI teammates, and about how a Claude-powered agent exploited a gym API flaw. Those were consumer and enterprise examples. This Taiwan-linked case shows the same agentic pattern moving into geopolitical cyber activity.
For governments and companies, the response has to be practical. Cybersecurity teams need to assume that attackers will use agents for reconnaissance, phishing, vulnerability testing and data extraction. That means more attention to API security, identity controls, segmentation, monitoring and rapid detection of automated behaviour.
AI will also be used defensively, and that is the other side of the story. Security teams need agentic tools that can triage alerts, inspect code, validate vulnerabilities and patch systems faster. OpenAI’s Daybreak program and GPT-5.6-Cyber push show how major AI labs are already thinking about giving stronger tools to vetted defenders.
The uncomfortable reality is that cyberwarfare is becoming more automated. The question is not whether AI agents will be used in attacks. The question is how quickly defenders can adapt before agentic hacking becomes ordinary. Taiwan may be one of the first visible warning signs, but it will not be the last.







