TL;DR

Taiwan’s Ministry of Digital Affairs says government systems were hit during July by attackers running autonomous software alongside human operators. Warnings began on 20 July and every affected body has now closed the incident out. Separately, the Israeli security firm Dream reconstructed four days of agent activity after recovering the attackers’ working environment.

An intrusion run partly by software

The ministry’s account is deliberately narrow. Monitoring units picked up abnormal activity aimed at government agencies during July, and its National Institute of Cyber Security started issuing alerts on 20 July while the investigation ran. The findings pointed to an overseas origin, and to a method pairing conventional hands-on intrusion with agent tooling — Open Claw among the examples named. Sources, methods and the extent of the damage have all been established, the ministry said, and the departments involved have finished dealing with it. China went unmentioned, and Beijing’s Taiwan Affairs Office did not respond to a request for comment.

What the security firm found

A day earlier, Dream had published its own account of a campaign against an unnamed Asian government. It described agents working in concert: dozens of officials’ passwords pulled out, staff records taken from a justice department, and a nuclear regulator probed for weaknesses, all inside four days. The firm says it recovered the agents’ “complete operational workspace”, which is what let it retrace the sequence. It declined to identify the target or hand over data, but the Financial Times, briefed first, named the agencies as Taiwan’s.

That sits against a volume problem Taipei already had. Attacks on Taiwanese infrastructure, hospitals and banks included, averaged 2.63 million a day last year on the National Security Bureau’s January count — 6% up year on year, some timed to coincide with military exercises.

Looking forward

For UK organisations the transferable detail is the labour model rather than the attribution. Semgrep’s security advocate Cris Thomas cautioned against overstating agent autonomy: someone still chose the target and set the objective. What has changed is throughput. Reconnaissance and exploitation used to be the slow, expensive stages that gated an operation; run by machine, they compress the gap between a weakness existing and somebody using it. Defence built around human-shift response times is what that compression breaks.