Skip to content Skip to footer

Eight Agents, Four Days: AI Runs a Government Intrusion in Taiwan

THE BIG DEAL Taiwan’s Ministry of Digital Affairs confirmed on 13 August that government agencies were hit in July by a campaign in which open-source AI agents did most of the work. Researchers at Dream recovered the attackers’ archive: over four days from 1 July, up to eight parallel agents mapped 21 systems, harvested usernames from an unauthenticated API, solved CAPTCHAs, guessed passwords derived from staff identifiers and cracked 85 accounts. They took more than 2,564 personnel records, six database credentials and seven single sign-on secrets, then moved on to the nuclear safety agency and seven energy companies. Everything taken was stored in readable form. The agents needed no exploit, only machine-speed patience.

TAKEAWAY Machine-speed attackers exhaust weak controls in hours, so the data must survive the perimeter’s failure. Encrypt personnel records and credentials at rest, vault every secret, and assume that anything an unauthenticated API returns is already in an adversary’s hands.

You cannot monitor what you haven’t mapped. You cannot protect what you haven’t found. DISCOVER is step one of the GuardWare data-first security sequence. INSIGHT monitors everything including AI. PROTECT encrypts every sensitive file, so data that leaves your environment is worthless to anyone without your keys.

Subscribe to our newsletter and stay ahead of the breaches.

Download Data Risk Assessment Report..

Download Data Discovery Assessment Report..

Webinar

The Insider Threat You Can't Fire: Cybersecurity in Education.

Jun 24, 2026 12:00PM AEST