Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up

Incident 1646: Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Description: From July 1–4, 2026, suspected China-linked hackers reportedly used a multi-agent framework built on Hermes and OpenClaw to compromise Taiwanese government systems. The agents reportedly compromised 85 credentials and used persistent access to connected systems to exfiltrate more than 2,564 personnel records. Taiwan later confirmed an overseas AI-assisted campaign against government agencies, without attributing it to China.

Tools

New ReportNew ResponseDiscoverView History

Entities

View all entities
Alleged: Peter Steinberger , Nous Research , Large language model developers and AI agent system developers developed an AI system deployed by Threat actors , hackers , China-linked threat actors , AI agent system deployers and Agentic threat actors, which harmed Taiwanese government employees , Taiwanese government agencies , Taiwan Ministry of Justice , Privacy , National security and intelligence stakeholders , Information security , Governments , Government of Taiwan and Government agencies.
Alleged implicated AI systems: OpenClaw , Large language models , Hermes Agent and AI agent systems

Incident Stats

Incident ID
1646
Report Count
4
Incident Date
2026-07-01
Editors
Daniel Atherton

Incident Reports

Reports Timeline

Incident Occurrence+3
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan
Loading...
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan

Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan

cyberscoop.com

Loading...
Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia

Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia

dreamgroup.com

Loading...
Taiwan says it was targeted last month in AI-driven hacking campaign

Taiwan says it was targeted last month in AI-driven hacking campaign

reuters.com

Loading...
Taiwan says it was hit by ‘abnormal’ AI-assisted cyber-attack

Taiwan says it was hit by ‘abnormal’ AI-assisted cyber-attack

theguardian.com

Loading...
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan
cyberscoop.com · 2026

Suspected Chinese hackers used open-source artificial intelligence models to run a cyberattack against the Taiwanese government in the first publicly known case of an autonomous AI hack hitting a government target, according to research pub…

Loading...
Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia
dreamgroup.com · 2026

Executive Summary

AI-enabled offensive operations are now at an inflection point. This is driven by the convergence of three curves:

  • Model capability keeps climbing, and it climbs on open weights that puts frontier-adjacent reasoning in th…
Loading...
Taiwan says it was targeted last month in AI-driven hacking campaign
reuters.com · 2026

TAIPEI/WASHINGTON, Aug 13 (Reuters) - Taiwan ​detected AI-assisted cyberattacks on government agencies last month coming from overseas but the affected bodies successfully "handled" the incident, the ‌Ministry of Digital Affairs said on Thu…

Loading...
Taiwan says it was hit by ‘abnormal’ AI-assisted cyber-attack
theguardian.com · 2026

Taiwan says it detected AI-assisted cyber-attacks on government agencies that came from overseas last month, a new kind of threat that has been reported as “first-of-a-kind breach”.

The Ministry of Digital Affairs (MDA) said its cybersecuri…

Variants

A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?

Similar Incidents

By textual similarity

Did our AI mess up? Flag the unrelated incidents

Loading...
Wikipedia Vandalism Prevention Bot Loop

Wikipedia Vandalism Prevention Bot Loop

Feb 2017 · 6 reports
Loading...
Hackers Break Apple Face ID

Hackers Break Apple Face ID

Sep 2017 · 24 reports
Loading...
Bug in Facebook’s Anti-Spam Filter Allegedly Blocked Legitimate Posts about COVID-19

Bug in Facebook’s Anti-Spam Filter Allegedly Blocked Legitimate Posts about COVID-19

Mar 2020 · 1 report
Previous IncidentNext Incident

Similar Incidents

By textual similarity

Did our AI mess up? Flag the unrelated incidents

Loading...
Wikipedia Vandalism Prevention Bot Loop

Wikipedia Vandalism Prevention Bot Loop

Feb 2017 · 6 reports
Loading...
Hackers Break Apple Face ID

Hackers Break Apple Face ID

Sep 2017 · 24 reports
Loading...
Bug in Facebook’s Anti-Spam Filter Allegedly Blocked Legitimate Posts about COVID-19

Bug in Facebook’s Anti-Spam Filter Allegedly Blocked Legitimate Posts about COVID-19

Mar 2020 · 1 report

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • dd3f754