Intelligence
AEV-2026-0012

A multi agent campaign ran against Taiwanese government systems

An operation in early July 2026 ran up to eight open source AI agents against Taiwanese government systems, mapping 21 systems, compromising at least 85 accounts and extracting more than 2,500 records. Retained as a candidate: all sources are journalism and attribution is a security firm's high probability assessment.

Candidate: below the publication gate, not a published vulnerabilityObservedStatus: candidateEvent: 12 August 2026Execution AuthoritySequence IntegrityDelegated Authority

Affected

Organisation
Taiwanese government systems
Product
unknown
Component
Up to eight concurrent open source AI agents run against the targets
Versions
unknown

Execution authority facts

Fields the evidence does not establish are shown as unknown rather than guessed.

Intended task
An offensive campaign against government and energy systems
Agent
Up to eight open source AI agents running concurrently
Delegating actor
China linked actors, attributed with high probability
Action
Mapped systems, compromised accounts and extracted personnel records, searching for alternative routes when one failed
Target resource
21 government systems, a nuclear safety agency and at least seven energy companies
Environment
Taiwanese government and energy networks
Credentials used
unknown
Privileges available
unknown
Authority presented
None: an adversarial operation
Authority required
Not applicable
Applicable policy
unknown
Approval mechanism
unknown
Required approver
unknown
Independent approval
unknown
Action binding
unknown
Sequence context
Concurrent agents where each individual action can look defensible while the aggregate is not

Impact

Consequence
At least 85 accounts compromised and more than 2,500 personnel records extracted
Reach
Multiple government systems, a nuclear safety agency and energy companies
Reversibility
unknown
Detectability
Found via a cache the operators left exposed online
Propagation
Expanded across systems and sectors over four days
Recovery
unknown

Evidence

Primary sources

Supporting sources

Reproduction status
Reported by journalism based on a security firm's finding; not independently reproduced
Evidence state
Observed

Known unknowns

  • The specific attacking group; attribution names no group and rests on a high probability assessment.
  • The execution authority detail of the operation, which the reporting does not establish.

Limitations

  • All sources are journalism; the primary technical account belongs to a security firm and was not independently available.
  • As an adversarial operation, several execution authority fields are not applicable and are recorded as unknown.

Claim provenance