Autonomous AI-Driven Cyberattacks Linked to Chinese State-Sponsored Groups Target Taiwan and Beyond
In a series of escalating cyber incidents, suspected Chinese state-sponsored threat actors have leveraged autonomous AI tools to conduct large-scale attacks, with Taiwan emerging as a primary target. Between 2025 and 2026, at least three major campaigns demonstrated how AI could automate reconnaissance, credential theft, and lateral movement compressing weeks of manual hacking into hours of unsupervised activity.
The most recent and severe attack occurred in July 2026, when an AI-driven tool built from open-source frameworks Hermes and OpenClaw infiltrated Taiwanese government systems over four days. The operation, attributed by researchers to a Chinese-speaking operator, compromised 85 government accounts, exfiltrated 2,500 personnel records, and breached Taiwan’s nuclear safety agency and seven energy companies. Internal messages in simplified Chinese (used in mainland China) and stolen data in traditional Chinese (used in Taiwan) reinforced suspicions of a China-linked actor, though no formal attribution has been confirmed.
Earlier incidents set the precedent for AI-driven automation in cyber operations. In September 2025, a suspected Chinese group manipulated Anthropic’s Claude Code tool to target 30 organizations, with AI handling 80–90% of the operation. A month prior, a separate actor used Claude to automate data theft and extortion against 17 organizations. In July 2026, Palo Alto Networks’ Unit 42 reported that a Chinese-speaking hacker integrated DeepSeek’s AI model into the same Hermes framework used in the Taiwan attack, deploying it via Telegram to scan 460 internet-facing systems and breach 14 by exploiting unpatched vulnerabilities.
These attacks relied on known techniques rather than novel exploits, but their speed and scale marked a shift in cyber warfare. AI agents operated around the clock, adapting tactics in real time up to eight agents worked simultaneously in the Taiwan breach, mapping systems and evading defenses. Industry experts, including OpenAI staff, warned at Black Hat 2026 that such autonomous, collaborating attack networks represent a watershed moment, with criminal groups likely to adopt similar methods.
The incidents have exposed critical gaps in cyber insurance policies, which were not designed to address AI-driven attacks. Key challenges include:
- Attribution ambiguity: Policies often exclude nation-state activity, but proving state involvement remains difficult. Insurers struggle to determine who counts as the attacker when AI performs most of the work.
- Policy language gaps: Many cyber forms define a "hacker" as a person, leaving coverage uncertain for autonomous AI attacks.
- Market uncertainty: While underwriters are revisiting war and nation-state exclusions, systemic AI-driven losses may exceed what the private market can absorb, prompting discussions about public-private risk pools.
Taiwan, already facing 2.6 million daily cyberattacks from China in 2025, has become a testing ground for these tactics. Five Eyes intelligence agencies have warned that such AI-driven attacks could become common within months, further straining cybersecurity defenses and insurance frameworks. The incidents underscore how autonomous AI is reshaping cyber threats accelerating attack timelines, complicating attribution, and forcing industries to rethink risk models.
Taiwan Center for Security Studies (TCSS) cybersecurity rating report: https://www.rankiteo.com/company/taiwan-center-for-security-studies
"id": "TAI1786580709",
"linkid": "taiwan-center-for-security-studies",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'industry': 'Public sector',
'location': 'Taiwan',
'name': 'Taiwanese government',
'type': 'Government'},
{'industry': 'Nuclear safety',
'location': 'Taiwan',
'name': 'Taiwan’s nuclear safety agency',
'type': 'Government agency'},
{'industry': 'Energy',
'location': 'Taiwan',
'name': 'Seven energy companies',
'type': 'Private sector'},
{'name': '30 organizations (September 2025 attack)',
'type': 'Various'},
{'name': '17 organizations (August 2025 attack)',
'type': 'Various'},
{'name': '14 organizations (July 2026 attack via '
'DeepSeek AI)',
'type': 'Various'}],
'attack_vector': ['Autonomous AI tools',
'Exploitation of unpatched vulnerabilities',
'Credential theft',
'Lateral movement'],
'data_breach': {'data_exfiltration': True,
'number_of_records_exposed': '2,500',
'personally_identifiable_information': True,
'sensitivity_of_data': 'High (personally identifiable '
'information)',
'type_of_data_compromised': ['Personnel records',
'Government data']},
'date_detected': '2025-2026',
'date_publicly_disclosed': '2026-07',
'description': 'In a series of escalating cyber incidents, suspected Chinese '
'state-sponsored threat actors have leveraged autonomous AI '
'tools to conduct large-scale attacks, with Taiwan emerging as '
'a primary target. Between 2025 and 2026, at least three major '
'campaigns demonstrated how AI could automate reconnaissance, '
'credential theft, and lateral movement, compressing weeks of '
'manual hacking into hours of unsupervised activity.',
'impact': {'data_compromised': '2,500 personnel records',
'identity_theft_risk': 'High (personnel records exposed)',
'operational_impact': 'Compromised 85 government accounts',
'systems_affected': ['Taiwanese government systems',
'Nuclear safety agency',
'Seven energy companies']},
'initial_access_broker': {'high_value_targets': ['Taiwanese government',
'Nuclear safety agency',
'Energy companies']},
'investigation_status': 'Ongoing (no formal attribution confirmed)',
'lessons_learned': 'Autonomous AI-driven attacks represent a watershed moment '
'in cyber warfare, accelerating attack timelines and '
'complicating attribution. Cyber insurance policies are '
'ill-equipped to handle such incidents due to attribution '
'ambiguity and policy language gaps.',
'motivation': ['Espionage', 'Data exfiltration', 'Cyber warfare'],
'post_incident_analysis': {'root_causes': ['Use of autonomous AI tools '
'(Hermes, OpenClaw, DeepSeek)',
'Exploitation of unpatched '
'vulnerabilities',
'Insufficient defenses against '
'AI-driven attacks']},
'ransomware': {'data_exfiltration': True},
'recommendations': ['Revisit cyber insurance policies to address AI-driven '
'attacks',
'Strengthen defenses against autonomous AI tools',
'Improve attribution capabilities for nation-state-linked '
'cyber operations',
'Develop public-private risk pools for systemic AI-driven '
'losses'],
'references': [{'source': 'Palo Alto Networks’ Unit 42'},
{'source': 'OpenAI staff (Black Hat 2026)'},
{'source': 'Five Eyes intelligence agencies'}],
'threat_actor': 'Suspected Chinese state-sponsored groups',
'title': 'Autonomous AI-Driven Cyberattacks Linked to Chinese State-Sponsored '
'Groups Target Taiwan and Beyond',
'type': ['AI-driven cyberattack', 'Data breach', 'Espionage'],
'vulnerability_exploited': 'Unpatched vulnerabilities'}