For four days at the start of July, suspected Chinese hackers ran a hacking operation inside Taiwanese government systems that required almost no human input once it started. Researchers at Dream, an Israeli cyberdefense firm, say they found the evidence later in a 160MB archive: a hacking tool built from publicly available AI agents, deployed to carry out reconnaissance and intrusion largely on its own.
According to Dream's findings, first reported by the Financial Times, up to eight AI agents ran at the same time, mapping 21 government systems, probing for software weaknesses, and changing tactics when blocked. The operation reportedly compromised at least 85 government user accounts, extracted more than 2,500 personnel records, and expanded from that initial breach into Taiwan's nuclear safety agency and at least seven energy companies.
Dream has not confirmed the target on the record, citing company policy, though a person familiar with the matter identified it as Taiwan. Researchers said internal messages tied to the operation were written in simplified Chinese, the script used on the mainland, while the data taken from the target was written in traditional Chinese, the standard in Taiwan, Hong Kong and Macau. That contrast is part of why analysts suspect a China-linked operator. No formal attribution has been made, and Beijing has not responded publicly to the allegations.
Amir Becker, Dream's chief strategy officer and a former head of cyber operations at Israel's Unit 8200 signals intelligence unit, told the Financial Times he had not previously seen an attack this automated carried out against a government target. His conclusion was that governments now need to treat continuous, automated probing as the default state, not the exception.
Some details remain unconfirmed. Dream says it could not identify which underlying AI model powered the agents, only that the tool combined open-source frameworks and that whatever safety guardrails existed had been bypassed, apparently by presenting the hacking activity as an authorized penetration test. Taiwan's Ministry of Digital Affairs declined to confirm details, citing confidentiality, but said incidents involving government systems are handled under established protocols.
This is not the first time a frontier AI system has been tied to an attack at this scale. Anthropic disclosed in a November 2025 report that a suspected Chinese state-sponsored group had manipulated its Claude Code tool in September 2025 to target roughly 30 organizations, including technology firms, banks, chemical manufacturers and government agencies, with AI handling an estimated 80 to 90 percent of the operation. That followed an earlier case Anthropic disclosed in August 2025, in which a different actor used Claude to automate data theft and extortion against at least 17 organizations. At the Black Hat security conference in early August, OpenAI staff told attendees that autonomous, collaborating attack agents mark what one employee called a watershed moment for the industry, and warned that criminal groups will likely build their own coordinated agent networks rather than relying on single tools.
Taiwan is already operating under sustained pressure on this front. Its National Security Bureau reported an average of 2.6 million Chinese-origin cyberattacks a day in 2025, up 6 percent on the year before, against the backdrop of Beijing's continuing claim to the island and its stated willingness to take it by force.
Two problems in this story map directly onto arguments the cyber insurance market has been having for the past year.
The first is attribution. Dream's researchers stopped short of formally pinning the Taiwan operation on Beijing, despite pointing to evidence that suggests a China-linked operator. That kind of ambiguity is exactly what complicates claims involving nation-state exclusions. In a related dispute over attacks on U.S. water utilities, one lawyer noted that coverage outcomes can turn on whether an incident is ultimately traced to a state-backed group, and that mixed signals or incomplete forensics can leave that question open for months. Insurers have been tightening war and nation-state language for this reason, even as analysts at Conning have argued that systemic, state-driven cyber losses may be beyond what the private market can absorb alone, pointing toward a public-private backstop similar to terrorism risk pools.
The second is policy wording. A number of cyber forms still define a "hacker" as a person. Tim Johnson, head of insurance at law firm Browne Jacobson, has pointed out that this leaves open whether an autonomous AI attacker even triggers coverage as written, an ambiguity that could cut either way for a policyholder depending on how it is eventually tested. Five Eyes intelligence agencies have separately warned that AI-driven attacks of this scale could become common within months.
Some carriers are already responding. Caspar Rogers, a senior broker at Assured, expects language similar to Chubb's earlier Widespread Vulnerability Exclusion to be revisited across the market as underwriters try to limit exposure to a single AI-enabled event affecting many policyholders at once. Christopher Keegan, cyber practice leader at Brown & Brown Risk Solutions, has described the broader market as holding steady for now, competitive and profitable and not yet repriced for this specific risk, though he has also warned that once an attacker gains an initial foothold, AI is unusually effective at moving that access laterally toward an organization's most sensitive systems. On a recent industry panel, Marsh Specialty's Kelly Butler noted that the list of top-tier cyber threats no longer has one clear leader, with AI-enabled social engineering and nation-state activity against operational technology both rising fast.
Underwriters evaluating risk in critical infrastructure or government-adjacent sectors now have a documented example of what an unattributed, largely autonomous, multi-agent intrusion looks like from start to finish: reconnaissance, credential theft, lateral movement and pivot, compressed into days. Whether it changes pricing, exclusion language or claims handling will likely come down to a question nobody in this case has been able to answer with confidence: who was actually directing the attack.