AI incident ·
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
In brief
An AI system built by Peter Steinberger, Nous Research and 2 others and deployed by Threat Actors, Hackers and 3 others allegedly harmed Taiwanese Government Employees, Taiwanese Government Agencies and 7 others.
- Risk domain
- Not classified
- Occurred
- Coverage
- 4 reports
What happened
From July 1–4, 2026, suspected China-linked hackers reportedly used a multi-agent framework built on Hermes and OpenClaw to compromise Taiwanese government systems. The agents reportedly compromised 85 credentials and used persistent access to connected systems to exfiltrate more than 2,564 personnel records. Taiwan later confirmed an overseas AI-assisted campaign against government agencies, without attributing it to China.
Laws that address this harm
No recorded instrument yet addresses this use case where it happened. See the open queue.
Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).
News reports (4)
Titles link to the original publisher; report text is not reproduced here.
Who was involved
- Alleged deployer
- Threat Actors, Hackers, China Linked Threat Actors, Ai Agent System Deployers, Agentic Threat Actors
- Alleged developer
- Peter Steinberger, Nous Research, Large Language Model Developers, Ai Agent System Developers
- Alleged harmed party
- Taiwanese Government Employees, Taiwanese Government Agencies, Taiwan Ministry Of Justice, Privacy, National Security And Intelligence Stakeholders, Information Security, Governments, Government Of Taiwan, Government Agencies
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- —
- Risk subdomain
- —
- Causal entity
- —
- Intent
- —
- Timing
- —
- Harm level
- —
- Sectors
- —
- Countries
- —
Source record: incident #1646 on the AI Incident Database · all 4 reports