Between July 1 and July 4, two open-source AI agent frameworks compromised 85 Taiwanese government accounts and took over 2,500 personnel records, then expanded on their own to a nuclear safety agency and seven energy firms. Researchers call it the first documented near-autonomous cyberattack on a government.

Read the full story: AI Agents Ran a Four-Day Breach of Taiwan's Nuclear Agency →

Transcript

Over four days in early July, two AI agent frameworks worked through Taiwanese government networks with almost nobody steering them. Eighty-five accounts compromised. More than two thousand five hundred personnel records taken. Then the part that makes this different: the system decided where to go next. It spread to supply chain vendors, a nuclear safety agency, and seven energy companies. The agents ran what the framework called learning cycles, reading vulnerability databases and GitHub mid-operation, then feeding that back into the next attempt. Both frameworks are open source. And the guardrails? Operators just told the models it was an authorized penetration test. That was enough. This was not fully autonomous. Building the rig still took real skill. But once built, the cost of the next target dropped to almost nothing. Being boring used to protect you.