A successful multi-agent AI attack on a government's agencies in the Asia-Pacific region by a Chinese-language operator has put nations and businesses on notice that near- and fully-autonomous AI-enabled attacks are now a reality.
The attack used as many as eight simultaneously-operated AI agents to conduct reconnaissance, find and evaluate vulnerabilities, attack networks and systems, and then evaluate and improve successive attacks, according to research from sovereign AI firm Dream published on Aug. 12. The company did not attribute the attack to a specific actor or group, but researchers did point to strong evidence that the attackers spoke simplified Chinese — typically a sign of speakers from mainland China.
While the company also limited the identification of the targets to "government entities in Asia," Taiwan's Ministry of Digital Affairs (MODA) issued a statement the following day, giving details of its response to an attack matching much of Dream's description, including that it used "AI agents like OpenClaw."
Overall, the incident should be a warning that fully autonomous attacks could be used against major targets, says Amir Becker, chief business and strategy officer at Dream and a former commander of the cyber operation division of Israel's 8200 Unit, more formally known as the Central Collection Unit of the Intelligence Corps.
"The speed and the scale of the attacks are changing and the economics of cyberattacks are changing dramatically as well," he says. "The defensive side of the house ... cannot continue ... just running [operations using] humans. If the attackers are using AI to attack, the defensive side must adapt the same attitude and direction at the same scale and speed as well."
Automated attacks have quickly risen as a concern for governments and large enterprises. Between December 2025 and February 2026, attackers targeted the Mexican government using an automated attack with AI capabilities, but that attack failed in many ways. The more recent attack on Hugging Face by OpenAI AI models is a fully automated examples of what an agent-based attack framework can do: The frontier model used agents to escape the company's sandboxed research environment by finding a previously unknown vulnerability in a package manager and creating a tool to exploit the issue.