Tools AI Risk Radar ai-incident-0039
Incident record
Dream documents a near-autonomous multi-agent framework used against Taiwanese government systems
- Severity
- High
- Status
- In the wild
- Type
- Agent Hijack
- Target
- Taiwanese government systems: 21 connected systems, 85 accounts, 2,564 personnel records on Dream's count
- Actor
- unknown
What happened
Dream Security published an analysis of an exposed 1,395-file operational workspace belonging to a multi-agent AI attack framework. Across 12 attack waves between 1 and 4 July 2026, with up to eight lettered sub-agents running in parallel, the framework enumerated 21 connected government systems and six SSO sub-realms, cracked 85 accounts, exfiltrated 2,564 personnel records, took six database credentials and seven SSO client secrets that had already been rotated, and planted persistent backdoors. Dream identifies the framework as built on the Hermes and OpenClaw agent stacks from two workspace identifiers it recovered, .hermes and .openclaw; both are legitimate open-source projects, Hermes Agent from Nous Research and OpenClaw from the OpenClaw Foundation, and neither is accused of any wrongdoing.
Dream describes the operation as near-autonomous, with limited human direction, and says guardrails were bypassed by framing the activity as authorised penetration testing. Taiwan's Ministry of Digital Affairs published its own account on 13 August 2026 and characterises it differently: its investigation found a hybrid pattern of hacker operation combined with AI-agent assistance such as Open Claw, with backup and test systems used as stepping stones. The ministry says its monitoring units found the abnormal activity during July, that its National Institute of Cyber Security issued alerts from 20 July, and that affected units have completed remediation. It names Open Claw and not Hermes, and publishes no figures of its own, so every count here rests on Dream alone. The operation expanded beyond government targets to IT supply-chain vendors, a nuclear safety agency, a government email system and at least seven energy companies. Linguistic evidence points to a Chinese-language operator; Dream names no actor. It withheld the targets' identity and shared initial details with the Financial Times, which reported the research first and named Taiwan.
Sources
- Dream Security: Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia (12 August 2026)www.dreamgroup.com/blog/inside-a-multi-agent-ai-framework-us…
- Taiwan Ministry of Digital Affairs: its own account of the attacks on government agencies (13 August 2026)moda.gov.tw/ACS/press/news/press/20394
- Financial Times: China-linked hackers hit Taiwan in unprecedented autonomous AI cyber attack (12 August 2026)www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026