Autonomous AI agents reportedly compromised government accounts in a four-day cyber campaign
Dream Security's investigation, reported by Tom's Hardware, says attackers used Hermes and OpenClaw agent frameworks to run a four-day campaign that compromised at least 85 government accounts and exfiltrated more than 2,500 personnel records. Dream did not publicly name the affected Asian government or the underlying language model; later reporting identified Taiwan.
0 comments · 0 votes
Sign in to join the discussion →
No comments yet. Start the discussion.
Why it moved the index
This was reported as a real operational misuse campaign, not a simulated evaluation and not a model escaping its developer's sandbox. Dream says it recovered a 160 MB working archive containing 1,395 files and observed up to eight agents conducting twelve attack waves, adapting when paths failed, and expanding from government systems to suppliers, a nuclear-safety agency, and energy companies. The reported account compromises and data theft are consequential external effects. Confidence is moderated because Dream's public account did not name the victim or attackers, the Taiwan and China-linked attributions came through later reporting, and researchers could not identify the underlying model. Hermes and OpenClaw are agent frameworks, not verified exact models for this item.
Assessment history
- R1Toward 72 · confidence 82
Adds a newly verified real-world autonomous multi-agent cyber campaign with reported government account compromise and data exfiltration; durable context contained no matching event.
14 Aug 2026