AI Incidents
Back to incident register
Source reviewedSecurity breachHigh

Taiwan confirms AI-agent-assisted attacks on government agencies

Taiwan's cybersecurity authority confirmed a foreign-origin attack wave in which attackers combined OpenClaw and other agents with conventional vulnerabilities.

First observed
Jul 1, 2026, 2:00:00 AM
Disclosed
Aug 13, 2026, 2:00:00 AM
Status
Monitoring
Confidence
96%
Organization
Taiwan Administration for Cyber Security, Taiwan government agencies
Last reviewed
Sep 1, 2026

Observed

Facts supported by sources

  • The authority reported detecting the attacks in July and distributing warnings from July 20 onward.
  • The investigation found indicators of foreign origin and a combined use of OpenClaw-assisted attack methods.
  • The monthly report lists data exfiltration and exploited SQL injection, path traversal, and arbitrary file download vulnerabilities.
  • Claims involving 2,564 records or 85 accounts are excluded because the primary sources do not confirm them.

Assessment

Interpretation, not observation

  • The authority describes AI agents as accelerators and orchestrators; it does not publish a forensic attribution of individual actions to a specific model.

Impact

Impact

Compromised government and cloud systems and confirmed data exfiltration of an unspecified scale.

Response

Response

Affected agencies completed remediation; Taiwan strengthened monitoring, cross-sector information sharing, and protection guidance.

Methodology: Facts, interpretations, and uncertainty are kept separate. Confidence describes the strength of the evidence, not a probability estimate.