Last month, over the course of four days, an AI system mapped 21 government networks, cracked 85 accounts, and pulled 2,500 personnel records out of Taiwan's government systems. No human was in the loop making the calls. When one approach got blocked, the system researched a new one and kept going.
That's not a hacker using AI to write better phishing emails. That's an autonomous agent running the whole operation (reconnaissance, credential attacks, lateral movement, strategy) coordinating up to eight sub-agents along the way. Experts are calling it the first known fully autonomous attack on a government. It won't be the last.
It's not that AI can hack. We've known that for a while. It's that the economics just flipped. As Dream, the firm that caught the attack, put it: the cost of running a competent attack has collapsed, but the cost of defending against one hasn't moved. That gap is the whole story. An attacker used to need a team, time, and skill. Now they need a goal and a system willing to iterate toward it, all night, without getting tired or careless.
Most security stacks today are built around a simple assumption: attacks happen at human speed, with human patience, and human-sized blind spots. Someone probes a system, someone reviews an alert, someone decides what happens next. That model breaks the moment the attacker is a system that adapts in real time and never sleeps. If your defenses are still tuned to "detect and respond within hours," you're already behind an adversary that adjusts in seconds.
The Taiwan attack succeeded partly because it moved across systems and accounts fast enough that stitching together what was happening, in time to stop it, was genuinely hard. That's the exact problem we think about constantly at Bonfy: not just whether sensitive data is protected at rest, but whether an organization actually has real-time visibility into how data and accounts are being accessed, by what, and whether that behavior looks like the start of something. Autonomous attackers don't trip the same wires human ones do. They don't need a phishing email to land, they need one weak credential and a foothold, and they'll find both faster than most monitoring cycles can catch.
Kenny Huang of the Taiwan Network Information Center didn't mince words: every country, not just Taiwan, is still unprepared for this. That's not a knock on Taiwan's defenses specifically, it's an honest read of where the entire industry is. Legal frameworks, technical capabilities, incident response playbooks, most of it was designed for a slower, more human adversary.
The organizations that adapt first will be the ones that stop treating AI-driven attacks as a future threat model and start treating them as the current one. That means real-time visibility into where sensitive data lives and moves, security postures that assume adaptive rather than static threats, and a willingness to rethink "good enough" defense in a world where the attacker's OODA loop is measured in seconds, not days.
The technology that made this attack possible isn't going away. Neither is the gap it exposed. The only real question is who closes it first.
Get in touch with us to discuss your system's readiness.