Skip to content

AI agents conduct multi-day, largely autonomous attack on Asian government networks

Bottom line: A framework based on open-source AI agents compromised government networks in Asia during a four-day, largely autonomous campaign, generating 1,395 files, cracking 85 credentials, and exfiltrating thousands of personnel records.

Over four days, multiple autonomous AI agents coordinated to map government systems in Asia, crack credentials, and exfiltrate data — according to security firm Dream, a turning point for AI-powered attack operations. Taiwan’s Ministry of Digital Affairs independently confirmed a concurrent, AI-assisted attack on government agencies.

According to research by cybersecurity firm Dream, a multi-day campaign ran in early July in which multiple autonomous AI agents operated in parallel against government networks in Asia. The system, based on the open-source frameworks Hermes and OpenClaw, divided sub-agents among individual targets and tasks and carried out reconnaissance, credential attacks, and exploitation steps across twelve waves of attacks, complete with planning and feedback loops. According to Dream, the “agentic attacker” produced 1,395 files, cracked 85 credentials, exfiltrated thousands of personnel records, and established persistent access within government infrastructure over the course of roughly four days. The company describes this as a “near-autonomous attack” and classifies the activity as an inflection point for AI-powered offensive operations. The attack began with automated reconnaissance: the system extracted API endpoints and authentication configurations from publicly accessible code, in the process identifying unauthenticated APIs containing user data and, in one case, a complete user database with no access protection whatsoever.

According to Reuters, Taiwan’s Ministry of Digital Affairs reported an “AI agent-assisted” cyberattack on government agencies during the same period, in which AI-powered tools such as OpenClaw were reportedly used. A ministry representative stated that the sources, methods, and extent of damage of the attack had been fully investigated and were already being addressed by the affected agencies. Neither side has officially confirmed an explicit link between Dream’s report and the incident reported by Taiwan. Dream itself declined to name either the target or the attacker when speaking with CSO, stating that its own research had not confirmed an actual system breach at the affected institution — the report merely describes the framework observed at the time of analysis. After publishing the original blog post, Dream also identified indications of the use of a DeepSeek-V4-Flash model within the framework, while unable to rule out the involvement of additional models.

For CISOs, this case fundamentally shifts the cost-benefit calculus of offensive operations: Colin Ferris, Head of Threat Hunting and Incident Response at Silverfort, compares the effect to the impact of cheap drones on conventional warfare — attackers can use a handful of low-cost AI agents to continuously search for and exploit unpatched vulnerabilities. Dream sums it up pointedly: the cost of carrying out a competent attack has fallen, but the cost of defending against one has not. Attack surfaces such as unauthenticated APIs, exposed authentication configurations in public code, and weak identity systems are being addressed by parallelized, self-learning agents at a speed that classic manual defense cycles can barely match.

For security leaders in government agencies and regulated industries, this creates a need to consistently remove or harden API inventories and authentication configurations found in publicly accessible code, since exactly these attack vectors formed the initial entry point in the case described. In addition, detection of multi-stage, coordinated attack patterns spanning several parallel vectors — as produced by multi-agent frameworks — should be prioritized, since traditional signature-based or single-incident-focused detection loses effectiveness against orchestrated, adaptive campaigns.


Source: www.csoonline.com · Published August 13, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: