Israeli security firm Dream published forensics on 12 August of a multi-agent intrusion into Taiwanese government systems — including the country's nuclear safety agency — that it describes as near-autonomous.

What ran, and for how long

The campaign spanned roughly four days, 1-4 July 2026, in 12 documented waves. Each wave orchestrated up to eight lettered sub-agents in parallel — Agent A through Agent Q across the full campaign — built on the open-source Hermes and OpenClaw frameworks. The agents used Bayesian posterior probability scoring to prioritise targets and adapt attack chains without an operator in the loop.

What it took

The framework produced 1,395 files and cracked 85 credentials by password spraying with a 100% CAPTCHA solve rate. Exfiltration covered 2,564+ personnel records — 1,409 employees via an SSO API, 916 from unauthenticated endpoints and 239 from the Ministry of Justice — plus 7 SSO client secrets, 6 internal database credentials across MSSQL, Oracle and Sybase, and internal IP ranges. Reconnaissance mapped 21 connected government systems and found 36+ unauthenticated API endpoints on one target alone.

Where attribution stops

Dream does not name a state actor. Its evidence is linguistic: code-switching between Simplified Chinese in internal status reports and Traditional Chinese in target-facing analysis, which it says points to a Chinese-language operator. That is a long way from state sponsorship, and the gap should not be filled in by inference.

The uncomfortable detail

Nothing here required a bespoke offensive model. The tooling is open-source agent scaffolding of the kind used for ordinary automation, pointed at government infrastructure. The differentiator was orchestration — parallelism and adaptive prioritisation — not capability.

Read it as a vendor report

This is single-sourced research from a commercial security company with an incentive to publicise, and there is no independent confirmation and no statement from Taiwanese authorities. "Near-autonomous" is Dream's framing rather than a measured autonomy level.