Taiwan AI Agent Swarm: Suspected Chinese Operators Used Free Open-Source Tools to Breach 21 Government Systems, Nuclear Safety Agency, and 7 Energy Firms in Four Days — 85 Cracked Accounts, 98.8% SSO Pivot Rate, Guardrails Bypassed by Calling It “Authorized Penetration Testing”
In early July 2026, suspected Chinese operators assembled a multi-agent AI attack framework from freely available open-source tools — Hermes and OpenClaw — and directed it at Taiwanese government infrastructure. Over four days (July 1–4), 8 parallel sub-agents across 12 attack waves mapped 21 government systems, cracked 85 employee accounts, exfiltrated 2,500+ personnel records, harvested 7 SSO client secrets and 6 internal database credentials, reached the nuclear safety agency and 7 energy firms, and installed persistent backdoors. DREAM Security recovered the complete 160MB operational workspace. The guardrail bypass: labeling the operation “authorized penetration testing.” CAPTCHA solving accuracy: 100%. SSO lateral movement success: 84/85 accounts (98.8%). Built entirely on free downloads. “The cost of running a competent attack has collapsed. The cost of defending against one has not.” OpenAI’s Michael Dalton at Black Hat: “Fully automated attacks orchestrated by AI now exist.”
