Insurance
Home›Insurance›Reinsurance›AI agents run largely on their own in Taiwan cyber att…
AI agents run largely on their own in Taiwan cyber attack
Researchers say the autonomous operation compromised at least 85 government accounts and more than 2,500 personnel records, underscoring how attribution gaps can leave cyber coverage questions unresolved for insurers.
Cyber underwriters have been weighing a scenario in which an AI system executes an attack with minimal human control, and new findings from an Israeli cyberdefense firm describe a real-world example that exposes gaps in how US cyber policies are written.
According to research by Dream, reported by the Financial Times, a hacking tool built from two open-source AI agent frameworks, Hermes and OpenClaw, ran largely autonomously over four days in early July inside Taiwanese government systems. Dream said up to eight agents reportedly operated in parallel, mapping 21 government systems, probing for weaknesses, and shifting tactics when blocked.
The operation reportedly compromised at least 85 government accounts and took more than 2,500 personnel records, with activity that also reached Taiwan's nuclear safety agency and at least seven energy companies. Dream said it did not confirm the target on the record, citing company policy, though internal messaging in simplified Chinese and data in traditional Chinese led analysts to suspect a China-linked operator.
Insurance officials have highlighted that cyber policy exclusions for war and nation-state activity can depend on being able to confidently identify who was behind an attack. The story also notes that insurers have been tightening nation-state language, while analysts at Conning have argued that systemic state-driven cyber losses may exceed what the private market can absorb alone.