Suspected China-linked hackers used autonomous AI agents in a cyber campaign against Taiwanese government systems, compromising at least 85 user accounts and taking more than 2,500 personnel records, according to Tom's Hardware, citing a Financial Times report based on findings from Israeli cybersecurity company Dream. Dream's researchers described the activity as the first observed end-to-end autonomous cyberattack against a government target. That characterization should be treated as Dream's assessment, not an independently established industry milestone: the cluster includes only Tom's Hardware's account of the Financial Times report and Dream's findings. According to the report, the attackers assembled an autonomous hacking platform from open-source AI-agent frameworks. Dream said multiple agents were able to work in parallel to map networks, look up vulnerabilities, try intrusion paths and change tactics when an approach failed. At times, the campaign reportedly used as many as eight autonomous agents at once. The operation reportedly ran for four days at the beginning of July. Dream said the system mapped 21 government systems before compromising user accounts and extracting personnel information. Tom's Hardware also reports that the activity later expanded to Taiwan's nuclear safety agency, at least seven energy companies, government suppliers and other government systems. The evidence came from a 160MB online archive that Dream found while tracking cyberthreat actors, according to the report. The archive reportedly contained 1,395 files and showed that the tool was built on Hermes and OpenClaw, two open-source AI-agent systems that can be downloaded freely and are designed to let large language models carry out multi-step tasks. Dream's researchers could not determine which underlying model powered the agents. The data reportedly showed that the model's safeguards were bypassed by presenting the activity as an authorized penetration test rather than a real intrusion. The more concrete concern is not that a bespoke offensive model was used, but that the alleged tool was assembled from general-purpose components available to ordinary developers. Dream did not attribute the campaign to a named hacking group or a specific country. The company said internal communications were written in Simplified Chinese, which it said suggested a high probability of a China connection. Dream also declined to name the victim, saying only that it had notified a country in the Asia-Pacific region; Tom's Hardware says the Financial Times cited a person familiar with the incident who identified the target as Taiwan. The most important technical claim is that the tool did not merely execute a fixed script. Dream said it evaluated evidence, ranked possible attack paths and reprioritized as conditions changed. When one technique failed, the platform reportedly assigned another agent to search the internet and devise an alternative approach. Who benefits: Attackers with modest engineering capacity could benefit if open-source agent frameworks can be assembled into effective intrusion tooling. Security vendors that can detect agent-driven behavior may also gain a clearer use case for defensive automation. Who's exposed: Government agencies, energy companies and suppliers are the exposed parties in the reported campaign. Organizations relying on model safeguards alone are also exposed if attackers can reframe malicious activity as authorized testing.