What happened
Multi-agent framework utilizes Hermes and OpenClaw to autonomously map federated authentication endpoints, bypass safety guardrails via semantic pen-test framing, brute-force government accounts, and exfiltrate database records.
2026-08-13
CriticalMedia reportAnalysis of the July 2026 cyber attack on Taiwan's government network where near-autonomous AI agents mapped 21 connected systems, compromised 85 accounts, and exfiltrated personnel records.
What happened
Multi-agent framework utilizes Hermes and OpenClaw to autonomously map federated authentication endpoints, bypass safety guardrails via semantic pen-test framing, brute-force government accounts, and exfiltrate database records.
Why it matters
Compromise of 85 government accounts, mapping of 21 interconnected national systems (including Taiwan's national nuclear safety agency and seven energy sector targets), and exfiltration of over 2,564 personnel records.
Missing authorization check
Not applicable: the agent was operated by the attacker, outside any boundary the victim controls.
Would PP block it?
No authorization boundary inside the victim's environment sits between this agent and its operator, because the operator is the adversary. Permission Protocol constrains agents acting under an organization's own authority.
Incident analysis
2026-07-01
The near-autonomous offensive AI campaign launches its first wave against Taiwanese government portals.
2026-07-04
The campaign concludes after autonomously mapping 21 systems, compromising 85 accounts, and exfiltrating over 2,564 records.
2026-07-21
Tenable’s Research Special Operations (RSO) team begins tracking the offensive agentic AI threat cluster.
2026-08-13
Taiwan’s Ministry of Digital Affairs formally discloses and confirms details of the near-autonomous AI campaign.
2026-08-17
Security researchers and media outlets publish deep-dive tradecraft profiles of the multi-agent Hermes/OpenClaw exploit mechanism.
Authorization boundary
This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Runtime Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
The agent in this incident was operated by the attacker, not by the victim. Permission Protocol secures internal agent boundaries, not external network perimeters.
Related incidents and controls
Adversa.ai Identifies Two CVSS 9.8 Zero-Click RCEs in Cursor IDE and Deeplink MCP Server Hijack Vulnerability
Cross-Site WebSocket Hijacking in OpenClaw Control UI Leads to Remote Code Execution
JADEPUFFER: First Confirmed Autonomous AI-Agent Ransomware and AI-Model Destruction Campaign: Exploited Langflow CVE-2025-3248 to Chain Credential Theft, Lateral Movement, and Ransomware Payloads Specially Built to Wipe AI Models
Start small
This incident maps to Runtime Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.