Circuit Wire — a daily news update from the Circuit.

Taiwan's Ministry of Digital Affairs confirmed on August 13 that overseas hackers used artificial intelligence agents to attack government agencies in July, after Israeli security firm Dream published research describing what it called a near-autonomous campaign, The Register reported. Over four days, the system cracked 85 government user accounts and extracted more than 2,500 personnel records.

Dream said the attackers built their framework on Hermes and OpenClaw, two popular open-source AI agent tools, and bypassed the models' safety guardrails by framing the operation as authorized penetration testing. The system deployed up to eight sub-agents across 12 attack waves between July 1 and July 4, CyberScoop reported. Starting from a single government portal, the agents mapped 21 connected government systems, harvested employee usernames from an unauthenticated API, solved CAPTCHAs and cracked accounts through repeated password-spray rounds.

The haul included a full export of one department's user database, seven single sign-on client secrets and six sets of internal database credentials. The agents did not stop at their primary targets. They expanded to government IT supply chain vendors, a government email system, Taiwan's nuclear safety agency and at least seven energy companies, scanning them in parallel for misconfigurations and exploitable flaws. Dream found the operation through a 160-megabyte archive of nearly 1,400 files that the attackers left exposed online.

Dream did not attribute the campaign to a specific group. Internal communications tied to the operation were written in simplified Chinese, which researchers said pointed to a Chinese-language operator. Taiwan's Administration for Cyber Security said its monitoring detected the attacks last month, alerts went out from July 20, and affected agencies have completed their responses. The ministry did not say where the attacks came from.

Taiwan's National Security Bureau said in January that Chinese cyberattacks on the island's infrastructure averaged 2.63 million a day last year, up 6 percent from the year before. Researchers cautioned against overstating the machines' independence. "There's still a human in there somewhere. Somebody had to choose who to attack," said Cris Thomas, a researcher at the security company Semgrep. The case is the first publicly known autonomous AI attack on a government target, following AI-orchestrated campaigns against companies reported over the past year.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.