# Financial Times Reports AI Agents Ran Automated Break-Ins Against Taiwan

Researchers at Palo Alto Networks documented a separate campaign in which a Chinese-speaking attacker used the DeepSeek model to run intrusions with little human supervision, and said that operator appeared to be independent of any state.

- Published: 2026-08-12T05:04:41.290Z
- Canonical: https://polylog.news/2026-08-12/financial-times-reports-ai-agents-ran-automated-break-ins-ag
- Publisher: Polylog (Global desk)
- Section: tech
- Sources: [Financial Times](https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795?syn-25a6b1a6=1), [Palo Alto Networks Unit 42](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/), [Help Net Security](https://www.helpnetsecurity.com/2026/08/03/deepseek-ai-autonomous-cyberattacks-hermes-agent/)

[The Financial Times reports](https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795?syn-25a6b1a6=1) that China-linked hackers attacked Taiwan using artificial-intelligence agents that carried out reconnaissance and intrusions simultaneously, which it describes as a new phase of cyberwarfare.

Attribution is where accounts differ. [Palo Alto Networks' Unit 42 documented](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/) a Chinese-speaking operator using several large language models to automate attacks on internet-facing systems, and said it believed that attacker was independent rather than state-supported. The researchers found the operation only because the attacker's own agent misconfigured a file server and exposed the infrastructure.

The technical detail matters more than the label. [Help Net Security reported](https://www.helpnetsecurity.com/2026/08/03/deepseek-ai-autonomous-cyberattacks-hermes-agent/) that the operator used the Hermes Agent framework with the Chinese model DeepSeek as its reasoning engine, enumerating vulnerabilities, downloading public exploit code and attempting intrusions without human direction. In one recovered session, the agent targeted a flaw in the Langflow software rated 9.8 out of 10 for severity and identified 84 exposed servers, then failed because the required configuration was not present.

An attack that once required a trained team can now be run by one person renting inference capacity. That changes the volume of attempts far more than it changes the sophistication of any single one.

## What this means

Automating reconnaissance sharply reduces the cost of the most labor-intensive part of an intrusion, so the number of attempts against exposed infrastructure rises even if success rates do not. Defenders in finance, utilities and semiconductor manufacturing carry that cost through higher security spending and, eventually, higher cyber insurance premiums. Taiwan is the most exposed case because its chip supply chain is a single point of failure for global electronics, and any confirmed disruption there directly affects hardware pricing and delivery schedules.

## What to watch

- Whether Taiwan's government confirms which agencies or firms were targeted, which would show whether semiconductor supply chains were in scope.
- Whether model providers restrict agent frameworks that chain vulnerability scanning to exploitation, the practical control point for this kind of attack.
- Cyber insurance pricing at renewal for industrial and financial clients in East Asia, the clearest financial measure of whether insurers accept that attack volume has stepped up.
