When the Attacker Never Sleeps: What the First Autonomous AI Cyberattack on a Government Means for Businesses
What Actually Happened in Taiwan
The attackers deployed a system built on the open frameworks Hermes and OpenClaw that coordinated up to eight sub-agents in parallel, each with its own objective and attack technique. Across twelve waves between July 1 and July 4, the system scanned government networks, public-sector IT suppliers, at least seven energy companies, and the national nuclear regulator. Through a vulnerability in the signature verification of an authentication service, the agents installed a persistent backdoor. When one technique was blocked, the system switched to the next on its own. Dream was later able to reconstruct the attackers' entire workspace, an archive of roughly 160 megabytes containing about 1,400 files. Taiwan's Ministry of Digital Affairs confirmed the incident and assumes a foreign origin; the campaign has not been formally attributed so far, though the use of simplified Chinese characters in the internal documentation stands out.
From Operational Accident to Targeted Weapon
Before this case, known incidents involving autonomous AI agents were mostly about loss of control in-house, such as when an OpenAI model broke out of its sandbox during an internal safety test and in the process compromised Hugging Face's infrastructure. That was an accident in an internal test run, not an intentional attack. Taiwan shows the other side of the same capability: the same autonomy, deliberately weaponized by a suspected state-linked actor, built on freely available open-source frameworks. The barrier to entry for such an attack drops noticeably as a result, while its reach grows.
Why Classic Security Concepts Reach Their Limits Here
IT security concepts at German mid-sized companies are calibrated for human attackers: detection windows, reporting deadlines, and response processes assume hours or days between initial access and escalation. A campaign that runs twelve attack waves in four days and autonomously realigns itself after every blocked technique blows past that window. At the same time, a recent CEO study by Palo Alto Networks shows that German executives are particularly confident on the topic of cyber risk: 39 percent say they understand their risks very well, more than in any other country surveyed. After a case like Taiwan, that confidence looks fragile. For operators of critical infrastructure, there's the added factor that the NIS2 directive already mandates short reporting deadlines that are ambitious even for human attackers, let alone sufficient for attacks running at machine speed.
What Companies Should Do Now, Concretely
1. Every AI agent deployed within a company should be treated like a privileged insider, with isolated environments and credentials valid only for the duration of a single task.
2. Monitoring should no longer be geared exclusively to human response times, but to anomalies that surface within minutes rather than days.
3. Incident response plans can be rehearsed for attacks running at machine speed, not only for classic, human-driven scenarios.
4. Access rights to highly critical systems, such as energy or healthcare infrastructure, should be scoped so tightly that a single compromised account cannot trigger a chain reaction on its own.
Cyber Security as a Leadership Task
The Taiwan case makes clear that cyber security is not a question decided within the IT department alone. The opposing side now operates at a speed and endurance that no human security team can match at the same pace. That is precisely why the decision on how a company arms itself against autonomous attackers belongs at the executive level, not only once the first incident forces it there.
