AEV-2026-0012
A multi agent campaign ran against Taiwanese government systems
An operation in early July 2026 ran up to eight open source AI agents against Taiwanese government systems, mapping 21 systems, compromising at least 85 accounts and extracting more than 2,500 records. Retained as a candidate: all sources are journalism and attribution is a security firm's high probability assessment.
Affected
- Organisation
- Taiwanese government systems
- Product
- unknown
- Component
- Up to eight concurrent open source AI agents run against the targets
- Versions
- unknown
Execution authority facts
Fields the evidence does not establish are shown as unknown rather than guessed.
- Intended task
- An offensive campaign against government and energy systems
- Agent
- Up to eight open source AI agents running concurrently
- Delegating actor
- China linked actors, attributed with high probability
- Action
- Mapped systems, compromised accounts and extracted personnel records, searching for alternative routes when one failed
- Target resource
- 21 government systems, a nuclear safety agency and at least seven energy companies
- Environment
- Taiwanese government and energy networks
- Credentials used
- unknown
- Privileges available
- unknown
- Authority presented
- None: an adversarial operation
- Authority required
- Not applicable
- Applicable policy
- unknown
- Approval mechanism
- unknown
- Required approver
- unknown
- Independent approval
- unknown
- Action binding
- unknown
- Sequence context
- Concurrent agents where each individual action can look defensible while the aggregate is not
Impact
- Consequence
- At least 85 accounts compromised and more than 2,500 personnel records extracted
- Reach
- Multiple government systems, a nuclear safety agency and energy companies
- Reversibility
- unknown
- Detectability
- Found via a cache the operators left exposed online
- Propagation
- Expanded across systems and sectors over four days
- Recovery
- unknown
Evidence
Primary sources
- No primary source. This is why the entry is a candidate.
Supporting sources
- Researchers observe first 'near-autonomous' AI attack on government target in Taiwan (CyberScoop)
- Taiwan says it was targeted last month in AI-driven hacking campaign (Reuters)
- Reproduction status
- Reported by journalism based on a security firm's finding; not independently reproduced
- Evidence state
- Observed
Known unknowns
- The specific attacking group; attribution names no group and rests on a high probability assessment.
- The execution authority detail of the operation, which the reporting does not establish.
Limitations
- All sources are journalism; the primary technical account belongs to a security firm and was not independently available.
- As an adversarial operation, several execution authority fields are not applicable and are recorded as unknown.
Claim provenance
- independent-reporting
Journalism relaying a security firm's finding; attribution is a high probability assessment.
When Several AI Agents Act at Once, Who Is Actually in Control?
