Cyber Security

AI Agents Are Starting to Hack Without Waiting for Humans

IT Club Editorial9 minutes read5 September 2026
WhatsAppEmail
AI Agents Are Starting to Hack Without Waiting for Humans

Keep up with IT Club

Add IT Club as a preferred source in Google Search.

A reported cyberattack against Taiwanese government and critical-infrastructure systems shows how quickly AI is changing offensive cyber operations. Suspected China-linked operators reportedly used multiple AI agents to investigate systems, find weaknesses, change tactics and continue an attack with limited human intervention. The important point for UK businesses is not who carried out this particular attack. It is what the technology was able to do.

AI-assisted hacking is not new. Attackers already use software to write convincing messages, search for information, generate scripts and speed up reconnaissance. What is changing is the amount of work that can be coordinated and automated once an attacker gives a system an objective, access to tools and enough time to keep trying.

Recent reporting about a four-day campaign against Taiwanese government and critical-infrastructure systems shows why this matters. Researchers reported that suspected China-linked operators used several AI agents at the same time to map systems, look for weaknesses, try different attack routes and adjust their activity as new information appeared.

The short version

The reported campaign is important because the attackers appear to have automated more of the investigation and decision-making loop than a conventional scripted tool would normally handle.

It does not mean that every public AI product can independently break into any organisation. It does mean that existing weaknesses may be found, tested and pursued faster, more cheaply and at greater scale.

Attribution remains sensitive. This article uses suspected and reportedly because researchers' indicators and Taiwan's acknowledgement of AI-assisted malicious activity do not, by themselves, establish who was responsible.

What happened?

According to reporting from cybersecurity researchers, Security Affairs and other international media, a four-day campaign targeted Taiwanese government and critical-infrastructure systems. Researchers reported that up to eight AI agents were used simultaneously, allowing the operation to pursue several lines of investigation at once.

The reported system was able to map more than 20 government systems, look for vulnerabilities, try different attack routes, reassess and reprioritise targets as information changed, and search online for more information when an approach failed.

The reporting also described the compromise of at least 85 accounts and the extraction of more than 2,500 personnel records. Activity reportedly expanded towards a nuclear safety agency and several energy organisations. These are reported figures and should be checked against the latest source material before being used in a formal threat assessment.

The toolkit was notable because it was reportedly assembled using publicly available AI-agent frameworks. It was not described as a completely new class of malware or as proof that an AI model had developed its own motives. The significance is more practical: existing attack techniques can be connected to systems that investigate, retry and adapt with less manual intervention.

Why does the autonomy matter?

In a traditional operation, a person may decide what to scan, which account to investigate, which weakness to test and what to do after a defensive control blocks the first route. Automation can handle parts of that sequence, but a fixed script usually follows a narrow set of instructions.

An AI-agent system can potentially interpret results, choose between several next steps, search for additional context and continue the investigation. Multiple agents can work in parallel, with information from one line of activity changing what another line attempts. The human operator remains important, but may spend less time directing every individual move.

That changes the economics of cybercrime and cyber espionage. An attacker does not necessarily need eight skilled people working continuously if software agents can perform part of that workload themselves. It also shortens the time available for a business to notice and respond to weak signals.

The practical risk is not that AI has made every attacker unstoppable. It is that an exposed weakness can be investigated and revisited more quickly than before.

The barrier to entry is falling

Publicly available frameworks do not turn an unskilled person into an advanced operator overnight. Reliable offensive activity still depends on access, infrastructure, technical judgement, operational security and the ability to interpret results. But lowering the amount of repetitive manual work can make capable operations easier to scale.

Over time, this could allow attackers to:

  • Scan more organisations with the same human effort.
  • Investigate weaknesses faster.
  • Run several attack paths simultaneously.
  • Work continuously across time zones and outside office hours.
  • Adapt more quickly when a defensive control blocks the first approach.
  • Reuse successful investigation patterns against many organisations.

AI does not need to invent a new vulnerability to make cyberattacks more dangerous. Making existing attack methods faster, cheaper and more scalable is enough.

What does this mean for a small business?

Most SMEs are not going to be individually targeted by the state-backed operation described in this reporting. That does not make the story irrelevant. Technology demonstrated at the high end of cyber operations tends to spread, and automation makes it easier to apply the same basic checks to a much larger number of organisations.

A business with exposed remote access, weak passwords, old software or poor Microsoft 365 security may increasingly be discovered and tested automatically rather than because somebody specifically selected it. The defensive priority is therefore not to buy the most fashionable AI security product. It is to remove the simple routes that automated investigation can find.

What should you do?

Focus on controls that make an automated attack harder to start, harder to extend and easier to detect. The following actions are ordinary security practice, but their value increases when attackers can work at machine speed.

1. Protect identities

Use multi-factor authentication wherever possible, particularly for Microsoft 365, administrator accounts, remote access and cloud applications. Review dormant accounts, shared administrator logins and old external users. Move towards phishing-resistant authentication and passkeys where your systems support them.

2. Keep systems updated

Known vulnerabilities are useful to automated attackers because they can be searched for and tested at scale. Keep operating systems, browsers, firewalls, applications and internet-facing services supported and patched. Unsupported software is not automatically compromised, but it is harder to defend and harder to fix when a weakness becomes known.

3. Know what is exposed to the internet

Businesses often have remote-management interfaces, VPN systems, old websites or forgotten services still reachable publicly. Make a current list of public addresses, domains, remote-access services and cloud applications. Remove what is no longer needed and restrict what must remain.

4. Monitor unusual activity

  • Unexpected logins or sign-ins from unusual locations.
  • Repeated authentication attempts or unfamiliar device registrations.
  • New administrator accounts or changes to privileged roles.
  • Unexpected mailbox forwarding rules or other mail-flow changes.
  • Changes to security settings, conditional access or MFA methods.
  • Unusual data downloads, synchronisation or access to sensitive folders.

Monitoring only helps if somebody knows what to review and what action to take. Decide which alerts are urgent, who receives them and how they are escalated outside normal working hours.

5. Separate important systems and permissions

Do not let one compromised account provide a straight path to every system. Use separate administrator accounts, least-privilege permissions and sensible separation between user devices, backups and critical services. An attacker that gets one foothold should have to overcome additional controls before reaching the next one.

6. Have a response plan

If an account or device becomes compromised, decide in advance what happens next. At minimum, identify who gets contacted, who can disable accounts, who can isolate devices, how passwords and sessions are reset, how backups are checked, and how customers, insurers or regulators are contacted if required.

Do not neglect backups

A fast-moving attacker may try to steal information, disrupt systems or damage recovery options. Backups should be protected from ordinary user credentials, monitored for failures and tested by restoring files or systems. A backup that has never been restored is an assumption, not evidence of recoverability.

The right recovery target depends on the business. A small professional firm may prioritise client files and Microsoft 365 data; a manufacturer may need to restore production systems and configuration; a retailer may need payment, stock and communications systems in a specific order. Write down the order before an incident forces the decision.

Related Reading

The IT Club view

Do not get distracted by the science-fiction version of this story. AI has not suddenly made every attacker unstoppable, and the reporting does not prove that ordinary public AI tools can independently compromise any target.

The more immediate change is simpler: attackers can increasingly automate work that previously required people. That means weak systems can be discovered, tested and attacked faster and at greater scale.

The answer remains fairly unglamorous: strong identity protection, supported and patched systems, good visibility, sensible monitoring, tested backups and a response plan. AI changes the speed of the attack. It does not make the fundamentals of good security obsolete.

Sources and further reading

This article is original IT Club commentary and explanation. The incident details and reported attribution should be treated as time-sensitive and checked against the source material before being used for formal decisions.

Security Affairs: China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan

Plain-English Takeaway

AI changes the speed and scale of an attack, but it does not make the fundamentals of good security obsolete. Strong identity protection, supported and patched systems, visibility of internet-facing services, sensible monitoring, tested backups and a response plan make automated attacks harder to progress.

Frequently asked questions

Are autonomous AI cyberattacks already targeting ordinary UK businesses?

There is no reason to assume that most small businesses are being individually selected by a state-backed operation described in this reporting. The more immediate concern is that automated tools can discover and test exposed systems at greater scale, so ordinary weaknesses may be found without a human choosing the organisation first.

Does this mean an AI can hack a business completely on its own?

Not necessarily. The reported campaign involved a configured system with AI agents, tools, access and human operators. The important change is that agents could reportedly perform more of the investigation and decision loop in parallel, not that every AI system can independently compromise any target.

What is the first security improvement a small business should make?

Start with identity protection: enable multi-factor authentication for Microsoft 365, administrator accounts, remote access and other cloud services, then review old accounts and sign-in alerts. Also confirm that internet-facing systems are supported and patched. These controls reduce the number of easy routes an automated attacker can use.

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor