The AI Agent Attack Built From Public Parts

Taiwan confirmed AI agent-assisted attacks on government agencies in July. A security vendor separately documented one campaign built from open-source frameworks. No frontier model gate was crossed, which is why vendor safety cases were never going to cover it.
AI generated image - a padlocked iron gate standing alone in a field with a worn footpath curving around it, illustrating how an AI agent attack bypasses frontier model controls

On Friday 7 August a frontier lab paused some of its own internal work because it could not rule out top-tier cyber capability in an unreleased model. On Wednesday 12 August researchers published an AI agent attack that had already run against a government, assembled from tools anyone can download.

The two events are unconnected. Read together, they show where our controls are pointed and where the problem actually sits.

What Taiwan confirmed about the AI agent attack

Taiwan’s Ministry of Digital Affairs said on 13 August that its monitoring units had detected an abnormal attack on government agencies during July. Warning alerts began on 20 July. The ministry described a hybrid approach in which attackers combined manual work with AI agent-assisted intrusion. It named Open Claw among the tools.

The sources, methods and scope had been fully investigated, the ministry said, and affected units had completed their handling. Protective guidelines and stronger system monitoring are now in place.

That statement stopped short of naming a country. It referred instead to characteristics indicating an overseas source.

Two accounts, not one story

A day earlier, the Israeli security company Dream published research describing an autonomous AI agent attack on government systems, which the Financial Times reported the same day.

It is tempting to read the ministry’s statement as confirmation of that research. It is not, and the dates are the reason. Dream places its campaign between 1 and 4 July. The ministry’s alerts began on 20 July, more than a fortnight later. Asked about specifics, the ministry declined to discuss them.

So there are two accounts with an overlapping subject. A government confirms that AI agent-assisted attacks hit its agencies during July. A vendor documents one specific AI agent attack in early July. Nobody has publicly established that these are the same events.

That is a more useful position than a false certainty, and it is the position to take into a board meeting.

Where the AI agent attack numbers come from

Dream’s evidence is a 160 MB archive of 1,395 files, recovered during broader threat tracking rather than handed over by a victim. From it the company documents twelve attack waves, up to eight sub-agents running concurrently, 21 government systems mapped, at least 85 accounts compromised and more than 2,500 personnel records taken. The AI agent attack then reached a nuclear safety agency, at least seven energy companies and government suppliers.

Attribution deserves the same care. Dream named no group and, citing company policy, would say only that the target was a government in Asia. The FT identified Taiwan through a person familiar with the matter. The inference pointing towards China rests on the operators’ own documentation appearing in Simplified Chinese while the exfiltrated data was in Traditional Chinese.

That is a reasonable inference. It is not an attribution, and the difference is worth preserving.

Every part was already public

Here is the detail that changes the governance question. The operators did not need privileged access to a frontier system. Dream reports a platform built on Hermes and OpenClaw, both open source and freely downloadable. The ministry named only Open Claw. Researchers could not identify which underlying model was driving either framework.

Capability that governance frameworks treat as a controlled substance turned out to be available on general release. An AI agent attack needs no gatekeeper’s permission.

The tool also adapted. When one route failed, another agent went looking for information and worked out a different approach. Options were reordered continuously against whatever the tool had just learned. That behaviour is what separates an AI agent attack from automation. A script repeats. This reprioritised.

The AI agent attack that frontier controls do not reach

Almost every control built for advanced AI capability points at the frontier. Capability thresholds, preparedness frameworks, staged release, model evaluations, vendor safety evidence. We wrote about that architecture in reading AI evaluation reports. The board conversation it produces appeared in AI cyber risk.

All of it assumes a gate. Someone builds the dangerous thing. Someone else decides whether to release it. Governance sits at that decision point.

An AI agent attack assembled from open frameworks walks around the gate entirely. No release decision was made. No threshold was crossed by any single component. Capability emerged from orchestration rather than from any one model, so no vendor’s preparedness framework was ever going to catch it.

That is not an argument against frontier governance. It is an argument that frontier governance was never the whole control set. Treating a vendor’s safety case as your own coverage leaves a gap the size of this week’s news. An AI agent attack lives in that gap.

Three questions worth putting on the agenda

The useful response here is unglamorous and mostly predates AI:

  • Would we detect eight parallel sessions probing our systems across twelve waves, or would that read as normal noise?
  • Do our credential controls assume an attacker works at human speed and gets tired?
  • When our own staff or suppliers run agents inside our environment, how do we tell authorised agent activity from unauthorised?

That third question is the newest and the least answered. Dream states that the operators got past the model’s safety training by presenting the whole campaign as an authorised penetration test. The system had no way to verify that framing. Any organisation running internal agents faces the mirror image of the problem.

What an EU organisation should actually do

The regulatory position has not shifted, which is a mercy. NIS2 incident reporting duties still apply. So does DORA operational resilience testing for financial entities, alongside Article 15 of the AI Act on accuracy and cybersecurity. An AI agent attack changes none of that. What moved is the threat model underneath those duties.

Where an organisation deploys agents of its own, the duty to assign oversight to a competent and trained person sits in Article 26. Article 14 is the provider’s obligation to build a high-risk system that can be overseen effectively in the first place. Deployers inherit the second and owe the first, and we set out how that split works for systems that act rather than advise in agentic AI governance.

For everyone else, the honest read is plainer. An AI agent attack of this kind succeeds through patching gaps, credential weaknesses and monitoring blind spots. Those are old failures moving at a new speed.

Reading the next one

Expect more AI agent attack reports of this kind. Expect the figures in them to come from vendors who found the evidence themselves. The test is the one we applied to Airbnb’s numbers earlier this week. Ask who counted and on what basis. Ask what a government or regulator confirmed separately, and whether it confirmed the same events at all.

Taiwan confirmed that AI agents were used against its agencies. A vendor documented an operation it found in an archive. Both facts are usable, provided you say which is which.

Our AI cyber risk analysis sets out the board questions underneath all of this.

Newsletter
Releted Blogs
LATEST NEWS

AI governance is not a future problem

Regulation is already in effect. Your competitors are already building internal capability. The gap between ‘we are aware of AI’ and ‘we have operational control’ is closing, and it closes faster with a structured framework.

 

Book a 30-minute discovery call. No obligation. We will assess where your organisation stands and what a realistic starting point looks like.

No sales pressure. No jargon. Just a structured conversation about your organisation's AI readiness.

Scroll to Top