Taiwan hit by AI-assisted cyberattacks on government agencies
Taiwan says government agencies faced an AI-assisted cyberattack, raising concerns about autonomous tools making cyber threats faster.
AI is making cyberattacks harder to ignore. Taiwan’s Ministry of Digital Affairs has reported an “abnormal” cyberattack targeting government agencies, with officials saying the activity involved AI-assisted methods and originated overseas. The incident was detected in July, with attacks beginning on 20 July.
Taiwan’s National Institute of Cyber Security issued alerts as authorities investigated the activity and assessed its impact.
How AI was reportedly used
The incident has drawn attention because of the reported use of AI agents during the attack. AI-assisted hacking does not necessarily mean an AI system carried out the entire operation independently. Attackers can use AI tools to automate tasks such as scanning systems, analysing information, identifying potential weaknesses and coordinating different stages of an intrusion.
Reports suggest the attackers built a “cyber team in a box”, using open-source AI agents to coordinate an autonomous hacking operation. At least 85 government user accounts were compromised, and more than 2,500 personnel records were extracted, according to the report.
Later on, the activity reportedly expanded towards Taiwan’s nuclear safety agency and several energy companies. The use of autonomous agents is increasing because such systems can potentially carry out repetitive cyber tasks at greater speed than human operators working manually.
Why Taiwan remains a major cyber target
Taiwan has faced persistent cyber pressure alongside military and political tensions surrounding the island. Taiwanese officials have not directly attributed this latest incident to China. However, the island has repeatedly warned about cyber operations, disinformation and other activities that it describes as part of broader hybrid warfare.
Taiwan’s strategic position and its importance to the global technology supply chain make its government agencies and critical infrastructure attractive targets for cyber operations.
The scale of attempted attacks is also substantial. Taiwan’s National Security Bureau said earlier this year that cyberattacks against critical infrastructure, including hospitals and banks, increased by 6% in 2025, reaching an average of 2.63 million attacks a day.
What Taiwan is doing
Taiwan’s Ministry of Digital Affairs said authorities investigated the sources, methods and scope of the latest incident and that affected organisations had completed their response. The ministry also said protective measures had been established and system monitoring strengthened to identify and block similar threats earlier.
The response reflects a broader shift in cybersecurity. As attackers gain access to increasingly capable AI tools, governments need to improve not only traditional security controls but also their ability to detect automated and adaptive behaviour.
The bigger AI security concern
The Taiwan incident highlights a growing challenge for cybersecurity teams: AI can strengthen both sides of the security equation. Defenders can use AI to analyse threats, monitor networks and respond more quickly. Attackers can use similar technology to automate reconnaissance, process stolen information and coordinate operations.
The reported attack does not mean AI has replaced human hackers. It does, however, show why security teams are paying closer attention to autonomous agents and their potential use in cyber operations.
For Taiwan, the immediate priority is containing and learning from the incident. For governments elsewhere, the case is another warning that cybersecurity defences will need to keep pace as AI makes digital attacks faster, more scalable and potentially more difficult to detect.


