For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/ai-security/ai-agents-breached-taiwan-government.md.
AI Security ↗

Dream reports an AI-agent campaign against government systems

Dream's research describes a four-day intrusion using AI agents. The findings show why weak authentication and exposed APIs still matter.

AI-generated illustration: Administrator reviewing access paths to personnel records.

The cover image is an AI-generated editorial illustration. Screens and documents are illustrative concepts.

A government intrusion described by Dream Research Labs shows how AI agents can coordinate familiar attack techniques. In its 12 August report, Dream says a recovered workspace documented roughly four days of activity, 85 cracked credentials and thousands of extracted personnel records.

The researchers describe agents built around Hermes and OpenClaw. Dream does not identify the affected organisations or attribute the operation to a named group. Those limits matter: evidence of an intrusion is not evidence for every claim about who directed it.

The weaknesses remain recognisable

The practical lesson is to examine how one exposed service can help an attacker reach another. A public API, a weak account and a connected authentication service should not be assessed as unrelated findings.

We recommend reviewing internet-facing applications with that chain in mind. Does an endpoint reveal information without authentication? Does the application check what an authenticated user may access? Can a compromised account reach another system without an additional decision?

An inventory is only the beginning. Each exposed service needs an owner who can explain why it is public and demonstrate the access controls around it.

Make response work across systems

Repeated login failures are useful evidence, but an investigation should also consider successful logins and subsequent activity. A response that disables one account may leave sessions, tokens or other access in place.

Test an authorised scenario that crosses the systems your business actually connects. Agree in advance what is permitted and how to stop the test. The question is whether your team can recognise and interrupt the sequence, not whether an alert can be made to appear.

The report strengthens the case for preparing for AI-assisted attacks. It does not make conventional controls obsolete. It makes unresolved gaps between them harder to justify.

← Back to all insights
Questions or inquiry? [email protected] Contact us →