China-linked hackers hit Taiwan in first autonomous AI attack

Share
China-linked hackers hit Taiwan in first autonomous AI attack

A government breach in Taiwan shows the AI-agent era of cyber warfare has arrived — and the operator may not have needed much of a team at all.

Suspected Chinese hackers used publicly available AI agents to build an autonomous hacking tool that broke into Taiwanese government systems in early July, according to the Financial Times — a breach researchers describe as unprecedented. Over four days, the tool mapped 21 government systems, researched vulnerabilities, and changed tactics whenever it was blocked. Government user accounts and tens of thousands of personnel records were accessed, and the campaign also hit Taiwan's nuclear safety agency and at least seven energy companies.

Researchers at Israeli AI group Dream first identified the breach. Dream declined to attribute the attack to a specific group and did not confirm which government was targeted, but a source with knowledge of the operation told the FT it was Taiwan. Researchers concluded the operator was probably connected to China because internal communications were in simplified Chinese. Neither Taiwan's agencies nor Chinese authorities responded to requests for comment.

The significance goes beyond one intrusion. This is the first publicly documented case of an autonomous agentic tool running a campaign against a sovereign government's infrastructure — a step past the earlier milestones we've tracked, like the DeepSeek-powered Hermes Agent campaign against 460+ servers that Palo Alto's Unit 42 documented last month, and Anthropic's disclosure of Chinese hackers abusing Claude Code in 2025. The Taiwan operation looks more consequential: confirmed access to government accounts and a nuclear safety regulator, executed by an agent that planned its own next move. When the barrier to a state-level intrusion is a handful of open-source agents instead of a team of operators, the defense problem stops being about catching hackers and starts being about outrunning them.

What to watch: whether Taiwan's government confirms the breach and names the affected agencies — and whether Dream publishes the full technical report.


CoreWeave raised its 2026 capital-spending forecast to $35–39 billion after beating second-quarter estimates, sending shares up more than 14% in extended trading. The AI cloud provider now expects to spend well above its prior $31–35 billion range as demand for GPU capacity keeps outstripping supply — its revenue backlog topped $100 billion in the June quarter, and CEO Michael Intrator says available capacity is effectively sold out. Revenue more than doubled to $2.58 billion, capex hit $9.4 billion in the quarter, and customers including Meta, Anthropic, and Jane Street are signing multi-billion-dollar commitments. It's the strongest signal yet that the AI buildout's spending phase is accelerating, not cooling — and that the biggest constraint is power and infrastructure, not orders.


Singapore-based data center operator DayOne has confidentially filed for a US IPO, aiming to raise around $5 billion and list as soon as next quarter, Bloomberg reports. The company, which closed a $4.5 billion Series C in June led by Coatue and Hillhouse, could target a valuation of about $20 billion — one of the larger data-center listings in a wave that includes Switch and Nscale. Since launching in 2022, DayOne has booked more than 1.5 gigawatts of capacity across Asia-Pacific and Europe. It's a direct bet that AI's compute appetite keeps the data-center land grab financed, public markets included.

What to watch: CoreWeave's Q3 numbers and whether DayOne's IPO prices near its private valuation — both are tests of how much longer the AI infrastructure boom can keep raising capital.

A state-linked autonomous hacking tool just walked into a government's network — does your organization have any defense that moves at agent speed? Tell us in the comments.

Sources: Financial Times — China-linked hackers hit Taiwan in unprecedented 'autonomous' AI cyber attack · FT News Briefing transcript · Techmeme · Unit 42 — Autonomous AI Cyber Attack Campaign · BleepingComputer — Hacker uses DeepSeek AI to autonomously attack vulnerable servers · Reuters — CoreWeave boosts 2026 spending plan · CoreWeave Q2 2026 results (SEC) · Bloomberg — DayOne files for $5B US IPO · The Straits Times — DayOne 'confidentially files' for $6.4b IPO