SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Autonomous AI agents hit Asian government in four-day breach

Autonomous AI agents hit Asian government in four-day breach

Thu, 13th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Dream has published research on a cyber intrusion into a government in Asia carried out by an autonomous multi-agent AI framework. The campaign appears to be one of the first documented cases of autonomous AI agents conducting a government-scale breach.

The research describes a four-day operation that compromised 85 government accounts, extracted more than 2,500 personnel records, and moved into connected organisations, including a nuclear safety agency and at least seven energy-sector companies. It also established persistent access on a government web application and reached government technology suppliers and a government email system.

Researchers recovered a 160-megabyte archive containing 1,395 files generated during the operation. According to Dream, the material showed how the framework assigned separate agents to different targets, attack techniques, and possible paths into government systems.

Attribution remains limited. Dream said linguistic analysis pointed to a Chinese-language operator, but the campaign has not been linked to a state or a named threat group.

The account adds to growing concern over the use of widely available AI tools in offensive cyber activity. In this case, Dream said the framework was assembled from public AI models and open-source agent software rather than bespoke tools.

How it worked

Over roughly four days, the framework launched 12 attack waves and used up to eight autonomous agents in parallel, according to the research. The agents changed tactics when blocked, searched for new vulnerabilities, and checked their own findings without human direction at each step.

The recovered archive showed what Dream called "Learning Cycles," in which the system searched vulnerability databases, software repositories, and published security research for methods linked to the systems it was targeting. It then scored possible attack chains by likelihood of success and shifted effort toward the routes it judged most promising.

Researchers said the system also filtered out false positives. Separate agents then rechecked findings before they were treated as confirmed, a process that Dream said showed the framework was carrying out and validating an intrusion campaign rather than simply producing suggestions.

The reported breaches did not rely on undisclosed software flaws. Instead, the framework used known weakness classes, including exposed developer endpoints in production, an API that accepted unsigned authentication tokens, an unauthenticated user database, predictable passwords derived from employee identification numbers, and a single sign-on bridge with no extra authentication step.

Public tools

That detail may sharpen attention on how accessible such methods are. Dream said safeguards built into the underlying AI models were bypassed by presenting the activity as authorised penetration testing.

The company argued that the case shows how autonomous AI can reduce the time, cost, and human effort needed to identify and combine weaknesses across large, complex government environments. Tasks that once required a skilled team working for months can increasingly be assembled from public components and run at machine speed.

Dream said it notified the affected government entities through national computer emergency response channels. The release did not identify the countries, agencies, or companies involved.

Company background

Dream was founded in 2023 by Shalev Hulio, Sebastian Kurz, and Gil Dolev. The company says it works with governments and critical infrastructure organisations across Europe, the Middle East, and Southeast Asia, and employs about 350 people across Tel Aviv, Abu Dhabi, and Vienna.

The findings come as security teams and policymakers assess how generative AI and autonomous agents may change the scale of cyber operations. While AI-assisted coding, reconnaissance, and phishing have been widely discussed, documented examples of autonomous systems carrying out extended intrusions into live government environments have been less common in the public domain.

Dream said the recovered workspace indicated that the operation functioned like a coordinated offensive team, with different agents assigned to distinct tasks and access routes. When one route was closed, the system continued searching for alternatives and reallocated its resources accordingly.

Amir Becker, Chief Business and Strategy Officer at Dream, said the incident showed how the barriers to conducting serious cyber operations are changing. "The limit on an operation like this used to be people. You needed a sophisticated team, a budget, and months of work to go head-to-head with national infrastructure. This one ran for four days, and every component of it is publicly available. Governments simply aren't ready for the threat that autonomous AI is introducing," Becker said.