Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Taiwan Autonomous AI Agent Cyberattack 2026: How Up…
Breach analysis Incident: 1 Jul 2026

Taiwan Autonomous AI Agent Cyberattack 2026: How Up to Eight AI Agents Cracked 85 Government Accounts and Pivoted Through SSO

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 11 min read
On this page

Between 1 and 4 July 2026, an attacker used a framework of autonomous AI agents to break into government systems in Asia. Taiwan's Ministry of Digital Affairs later confirmed an "AI agent-assisted" attack on its government agencies. Dream Security, which found the attacker's full operational workspace, says the agents mapped 21 connected government systems from a single portal, cracked 85 employee accounts, used single sign-on to reach internal systems, and exfiltrated more than 2,564 personnel records. They then widened the campaign to government IT suppliers, a nuclear safety agency and energy companies. Almost every step ran through identity: OAuth and Keycloak configuration scraped from JavaScript, predictable passwords, SSO bridges that trusted each other's sessions, and a government API that accepted unsigned tokens. Experts suspect a China-linked operator, but neither Taiwan nor Dream has confirmed attribution.

Key takeaways

  • Dream Security says a multi-agent framework built on the open-source Hermes and OpenClaw agents ran 12 attack waves over about four days, with up to eight sub-agents working in parallel per wave.
  • The agents started by extracting API endpoints, OAuth client IDs and Keycloak configuration from a government portal's JavaScript, then mapped the national SSO architecture and 21 connected systems.
  • They cracked 85 accounts by spraying password patterns derived from employee IDs, solving CAPTCHAs with OCR. 84 of those accounts then logged in to an internal system through an SSO bridge with no further authentication or MFA.
  • Dream also reports hidden debug endpoints that returned authenticated sessions, a government API that accepted JWTs with the algorithm set to "none", and exfiltration of 2,564+ personnel records, SSO client secret names and six internal database credentials.
  • Taiwan's Ministry of Digital Affairs confirmed an AI agent-assisted attack on 13 August 2026 and says affected units have completed their handling. Dream's report describes the victims only as "government entities in Asia"; media reporting links the two.

At a glance

OrganisationsTaiwanese government agencies (confirmed by Taiwan's Ministry of Digital Affairs); per Dream Security, also government IT suppliers, a nuclear safety agency, a government email system and at least seven energy companies
WhenAttack waves 1 to 4 July 2026; Dream report and Financial Times coverage 12 August 2026; Taiwan confirmation 13 August 2026
AttackerUnattributed operator, suspected by experts to be China-linked, running an autonomous multi-agent framework built on Hermes and OpenClaw. Dream later found evidence of a DeepSeek-V4-Flash model in the framework
Entry pointA government portal's JavaScript bundles, which exposed API endpoints, OAuth client IDs and Keycloak configuration; unauthenticated APIs and hidden debug endpoints
Identities abused85 employee accounts cracked with password spraying; SSO sessions trusted across systems; forged JWTs accepted with algorithm "none"; SSO client secrets and internal database credentials exposed
Impact21 systems mapped, 85 accounts compromised, 2,564+ personnel records exfiltrated, persistent footholds and a web shell upload; campaign widened to suppliers and critical infrastructure
CategoryAgentic AI and AI agents, Human identity, NHI. Incident class: confirmed AI-agent breach (AI agents used as the attacker against real government systems)

What happened

In early July 2026, Dream Security's research team, Dream Lab, found the complete operational workspace of an AI attack framework: an archive of more than 160 megabytes and 1,395 files. It documented 12 attack waves between 1 and 4 July. The framework was built on two open-source agent projects, Hermes and OpenClaw, and dispatched lettered sub-agents, from Agent A to Agent Q across the campaign, with up to eight working at once. Each sub-agent had its own target and technique. A Bayesian scoring engine ranked findings and attack chains and decided where to spend effort next. When a method was blocked, "Learning Cycles" searched vulnerability databases, GitHub and security research for new techniques. Dream says the framework got past its own model's refusals "by framing all activity as 'authorized penetration testing'".

The attack began with reconnaissance. The agents downloaded and decompiled the JavaScript of an Angular-based government portal and extracted every URL, API endpoint, OAuth client ID and Keycloak configuration object. From that they mapped the national SSO architecture, which Dream lists as six sub-realms, all OIDC endpoints and two RSA signing keys, plus 21 connected government systems. One system exposed its entire user database with no authentication. The agents also found a GitBook portal hosting the national SSO integration guide and downloaded its SDK samples, although Dream says nothing found in them led to a confirmed exploit.

Access then came several ways at once. Dream describes three hidden developer endpoints on a government web application that "accept any request body and return a valid authenticated session". Using employee usernames from an unauthenticated API, the agents sprayed predictable password variations based on each employee's ID against an office automation portal. They solved its CAPTCHA with Tesseract OCR and cracked 85 accounts. A separate government API accepted JWTs with the algorithm field set to "none", so anyone could forge identity tokens. The cracked credentials were then tried against every system connected through SSO. Dream says 84 of the 85 accounts authenticated to an internal information system through an SSO bridge endpoint, with "no additional authentication, MFA, or user confirmation required". The agents also uploaded a web shell, but a second layer of authentication stopped it from running.

Dream says the agents exfiltrated 2,564+ personnel records, a full export of a department's user database, the naming conventions of seven SSO client secrets (which had been rotated), six internal database credentials and internal network ranges. They then expanded to supply-chain vendors, a nuclear safety agency, a government email system and at least seven energy companies. Dream shared details with the Financial Times, which reported the case on 12 August. On 13 August, Taiwan's Ministry of Digital Affairs said the investigation "found clear indications that the attacks originated overseas and involved a hybrid approach in which hackers combined conventional operations with AI agents such as OpenClaw". CSO Online notes that neither Dream nor Taiwan has explicitly confirmed the link between Dream's report and Taiwan's incident, and quotes a Dream spokesperson declining to identify the target or attacker.

Timeline

DateEvent
1 July 2026First of 12 documented attack waves by the multi-agent framework.
4 July 2026Last documented attack wave, about four days after the first.
30 July 2026Palo Alto Networks Unit 42 reports a separate Chinese-speaking operator using the same Hermes agent framework (Tenable).
12 August 2026Dream Security publishes its analysis; the Financial Times reports the case.
13 August 2026Taiwan's Ministry of Digital Affairs confirms an AI agent-assisted attack on government agencies.

How it happened: the identity attack path

  1. Identity configuration published in client code. OAuth client IDs, Keycloak realm configuration and OIDC endpoints in the portal's JavaScript gave the agents a map of the whole SSO estate.
  2. Unauthenticated APIs leaking the user list. An API exposed employee usernames and IDs without authentication, which fed the password attack.
  3. Predictable passwords, weak CAPTCHA. Passwords derived from employee IDs fell to automated spraying, and OCR solved the CAPTCHA every time.
  4. Debug endpoints and unsigned tokens. Hidden endpoints returned authenticated sessions for any request, and a government API accepted JWTs with algorithm "none", so identity tokens could be forged.
  5. SSO trust without step-up. Each internal system trusted the office automation session through an SSO bridge. One set of weak credentials opened many systems, with no MFA in between.
  6. Secrets and service credentials harvested. The agents collected SSO client secret names and internal database credentials for MSSQL, Oracle and Sybase, laying groundwork for deeper access.

Impact

  • Accounts: 85 employee accounts cracked, 84 of them used to reach an internal system through SSO.
  • Data: 2,564+ personnel records exfiltrated, including 239 legal professionals from an unauthenticated Ministry of Justice endpoint, plus a complete department user database.
  • Persistence: persistent backdoors on government web applications, according to Dream, and a web shell upload blocked from execution.
  • Reach: scanning and targeting of government IT suppliers, a nuclear safety agency, a government email system and energy companies. Dream's report does not state the level of access achieved there.
  • Government response: Taiwan's Ministry of Digital Affairs says the attack sources, methods and scope have been investigated and affected units have completed their handling.

What this means for NHI and AI agent security

This is the clearest public case yet of AI agents acting as the attacker rather than the victim, and nearly every step was identity. The agents did not need a novel exploit. They needed identity configuration left in client code, a user list with no authentication, passwords built from employee IDs, an SSO bridge that trusted one weak login everywhere, and a token validator that accepted unsigned tokens. Tenable, which tracks a cluster of seven agentic AI incidents, names discoverable federation endpoints, weak credentials and misconfigured SSO as the common entry point across them.

What agents change is speed and breadth. Dream counts 1,395 files produced in about four days, 14 attack chains ranked in parallel, and a framework that researched new techniques when it was blocked. Weaknesses that a human attacker might never get round to are now found and chained automatically. The non-human side matters too. JWT validation, SSO client secrets and service database credentials are machine identities, and agents harvested or abused all of them.

For defenders, the lesson is to treat federation and token infrastructure as a primary attack surface. Our Identity Provider and SSO Security Guide and Token and Session Security Guide cover the controls this case turns on.

Recommendations

  • Audit what your front-end code reveals. Review JavaScript bundles, discovery endpoints and public documentation for OAuth client IDs, realm configuration and internal API paths that map your identity estate.
  • Validate every token properly. Reject JWTs with algorithm "none", pin accepted algorithms and keys, and test every API that consumes identity tokens. See our OAuth 2.0 and OpenID Connect Guide.
  • Require step-up at SSO boundaries. Do not let one weak session silently open every connected system. Enforce MFA and re-authentication for sensitive applications behind SSO. See our MFA Guide.
  • Stop password spraying before it works. Ban passwords derived from usernames or IDs, detect distributed spraying, and use CAPTCHAs that resist OCR. See our Password Security Guide.
  • Remove debug endpoints and authenticate every API. Scan production for developer endpoints and unauthenticated APIs that return user data or sessions.
  • Protect service credentials and client secrets. Vault database credentials and SSO client secrets, rotate them after exposure and alert on their use from new locations. See our Secrets Management Guide.
  • Detect machine-speed reconnaissance. Alert on rapid API enumeration, mass credential testing and parallel scans across connected systems. Our ITDR Guide covers the signals.

Frequently asked questions

Was the Taiwan attack really carried out by AI agents?

Taiwan's Ministry of Digital Affairs says hackers combined conventional operations with AI agents such as OpenClaw. Dream Security's analysis of the attacker's workspace describes up to eight agents working in parallel across 12 waves, researching techniques and adapting without human intervention. Experts quoted by CNN call it the first known autonomous attack on government agencies.

Who was behind it?

It has not been confirmed. Dream found Simplified Chinese in the operator's internal reports and says this points to a Chinese-language operator, and experts suspect a China link. Neither Taiwan nor Dream has formally attributed the attack, and China's foreign ministry told CNN it was not familiar with the situation.

Why is this an identity breach?

The agents got in and moved around almost entirely through identity weaknesses: exposed OAuth and Keycloak configuration, weak passwords, SSO sessions trusted across systems, forged unsigned tokens and exposed service credentials. Strong authentication and token validation would have stopped most of the chain.

JADEPUFFER agentic ransomware 2026 · Anthropic GTG-1002 AI-orchestrated espionage campaign · Storm-2949 cloud identity breach · Public Sector Identity Security Guide · Zero Trust Identity Guide

How NHI Mgmt Group can help

Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as attackers hand reconnaissance and credential attacks to autonomous agents. Our NHI Foundation Level Training Course gives teams the practical grounding to harden the tokens, secrets and service identities these agents target.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org