/
Cyber Resilience

The Automated AI Attack Has Arrived

Over four days in July, a set of AI agents mapped 21 connected Taiwanese government systems. The agents cracked 85 accounts and pulled out more than 2,500 personnel records. They ran 12 waves of attacks. Human operators set up the operation. The agents handled much of what came next.

Researchers at Dream disclosed the campaign in August. It came in the same month U.S. agencies warned that attackers were using AI-generated code against the machines that run water plants and power grids.

Together, they mark a shift in what AI does for an attacker. For years, it handled single tasks: a phishing email, a block of exploit code. Now it's automating the stretch in between, the research and testing that carries an attacker from a first foothold to something worth stealing. That work used to take skilled people days or weeks. Agents run it in parallel and change course when something fails.

Attacks are compressing. A security team still needs time to investigate an alert, test a fix, and get approval. That gap is what makes containment the sharper question. If an AI-driven attack gets in, where can it go next?

Inside the automated attack chain

The Taiwan framework mapped its own target. It could run several attack paths at once and change course based on what it learned.

Dream found the framework could run up to eight AI agents per wave. Each agent got a different target or technique. One might test credentials while another hunted for exposed APIs.

The agents could:

  • Research targets and vulnerabilities
  • Test several attack paths at the same time
  • Change course when a technique failed
  • Score each path by its odds of success
  • Shift effort toward the paths most likely to work
Up to eight AI agents could work at the same time, letting the framework pursue several targets and attack paths in parallel.

Dream calls the research phase “Learning Cycles.” When a technique failed, the agents searched vulnerability databases, GitHub, and published security research for something new. They fed those findings into later waves. They also dropped leads that didn't hold up under repeated testing.

The framework expanded its targeting across Taiwan. It scanned government IT suppliers, a nuclear safety agency, a government email system, and more than seven energy companies, looking for exposed interfaces, misconfigurations, and bugs it could use.

Research firm Dream traced how the operation moved from reconnaissance and initial access to lateral movement, persistence, and data theft across connected government systems.

Dream doesn't name the operator. But the group's internal notes switch between Simplified and Traditional Chinese, which points to a Chinese-language operator.

The agents helped decide what to try next.

The warnings kept coming

While Dream tracked the Taiwan attack, agencies in the U.S. issued warnings, and reports of attacks continued. Each one pointed at programmable logic controllers, or PLCs. These are the small computers that control the physical processes in water plants, power stations, and factory lines.

Attacking a PLC used to take deep knowledge of industrial systems. AI is lowering that bar. Agencies say attackers can now build working exploit tools faster, with far less skill.

AI is moving from assistant to operator

Taiwan fits a pattern. In 2025, Anthropic disclosed a China-linked espionage campaign in which Claude Code did most of the tactical work. The AI ran reconnaissance. It found and tested vulnerabilities. It helped write exploit code, collect credentials, spot valuable accounts, and sort the stolen data. Anthropic estimated the AI carried out 80% to 90% of the campaign. People stepped in mainly for key decisions.

For years, AI has helped attackers write phishing emails, research targets, and generate code. Now it strings those tasks together. It can find a weakness, research it, test it, and move to another option when it fails. In Taiwan, several agents did that at once.

The next shift may be agents that keep working with even less direction. OpenAI is testing an unreleased model called Astra that can turn an idea into code, run the experiment, and report back. The company says that work can replace a week of a researcher's time. OpenAI has also said early evaluations may place Astra at the “Critical” cybersecurity threshold under its Preparedness Framework. It responded by tightening monitoring, sandboxing, and network limits.

Astra hasn't been tied to any attack. But it points the same direction as Taiwan: agents that work longer, handle more tasks, and need less human input to keep moving.

Same attacks, less time

Strip away the automation and the attack underneath looks familiar.

“It hasn't introduced a new threat vector,” said Christer Swartz, director of industry solutions at Illumio. “It's just dramatically speeding up what attackers can already do.”

Attackers still need a foothold. They still need credentials, exposed services, or weak systems. And once inside, they still need a path to something worth stealing, breaking, or holding for ransom.

What changes is the clock. A security team may need to investigate an alert, work out what happened, test a fix, and get approval before changing anything. An automated attacker doesn't wait for any of that.

Contain the attack before it spreads

That's why Rajoo Nagar, senior product marketing manager for Illumio, says the focus has to reach past the perimeter. Initial access alone rarely causes the damage.

“It's really lateral movement that does that,” she said.

So the question gets simpler. If an AI-driven attack gets in, where can it go next?

  1. Start with visibility. Teams need to see which systems and workloads talk to each other, and where connections exist that nobody needs.

“You can't protect what you can't see,” Nagar said.

  1. Then close the paths.
  2. Then segment. Illumio Segmentation separates critical applications and production systems, so one compromised machine doesn't open a route across the environment. The goal is to keep a foothold small.

Speed matters on defense, too. Swartz argues teams may no longer have time to understand every detail before they act. His analogy is simple. If someone is breaking down your front door, you lock it before you ask why.

“We will isolate that breach, and then we can understand it later,” he said.

AI can move faster. It still needs somewhere to go.

The Taiwan attack, the PLC warnings, the Anthropic campaign, and Astra all point the same way. AI is automating the work between finding a weakness and reaching something valuable. That gives attackers speed, scale, and more shots on goal for less effort.

Defenders may not win every race to a vulnerability. But they still control what happens after the foothold. If AI makes an attack move faster, make sure it has nowhere useful to go.

See how Illumio Segmentation contains breaches before they spread. Explore Illumio Segmentation

Related articles

Experience Illumio Insights today

See how AI-powered observability helps you detect, understand, and contain threats faster.