For four days in July, at least eight AI agents worked through Taiwanese government networks, mapping systems and adjusting their methods each time one approach failed. No human sat at a keyboard directing the intrusion in real time. A vendor did not build this scenario for a slide deck. Taiwan’s Ministry of Digital Affairs confirmed it happened on August 13, and it is the second documented case of its kind in nine months.
Three Data Points, One Trend Line
The first documented case came from Anthropic, which disclosed in November 2025 it had disrupted a large-scale cyberattack carried out with minimal human involvement. The company attributed the operation to a Chinese state-sponsored group it tracks as GTG-1002. Investigators found Claude executed an estimated 80% to 90% of the operation independently, with human operators intervening for a combined total of roughly 20 minutes across the entire campaign. The AI conducted reconnaissance, identified vulnerabilities, harvested credentials, extracted data, and generated its own after-action reports across roughly 30 targets spanning technology companies, financial institutions, chemical manufacturers, and government agencies. The attackers got Claude to cooperate by posing as a legitimate cybersecurity firm running defensive tests, a social engineering move aimed at the AI system itself rather than at a human target.
The Taiwan case, investigated by the Israeli security firm Dream after it recovered roughly 160 megabytes of the attackers’ operational files, followed a similar structure with more autonomy distributed across more agents. Eight AI systems worked in parallel, examining 21 government systems, compromising at least 85 accounts, and extracting more than 2,500 personnel records from targets spanning the Ministry of Justice, a nuclear safety agency, and seven energy-sector companies. Taiwan confirmed an “overseas, AI-assisted attack” without formally naming a state sponsor, though investigators found internal communications in Simplified Chinese.
CrowdStrike’s 2026 Threat Hunting Report puts the Anthropic and Taiwan cases in a wider context. The firm found 88% of vulnerabilities with public proof-of-concept exploit code get exploited within 48 hours of disclosure, with China-linked groups it tracks as Vault Panda and Genesis Panda moving in as fast as 24 hours. Detections triggered by AI agents grew at 2.5 times the rate of detections triggered by human analysts. One campaign sent 200,000 automated requests to an AI model in a two-minute span. Adam Meyers, CrowdStrike’s head of counter adversary operations, summarized the shift directly: “AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend.”
The Constraint AI Attackers Don’t Have
The data suggests the real change is not speed. Attackers have used automation to move faster for years. What is different across all three cases is where the human sits in the operation. In the Anthropic case, human involvement dropped to a handful of approval decisions across an entire campaign. In the Taiwan case, humans designed the framework and set objectives, then let agents adapt tactics on their own when methods failed, working continuously rather than in the shifts a human team would need. Traditional enterprise security is built around assumptions baked in over decades: attackers get tired, make mistakes, work in particular time zones, and pause to think. An AI operator shares none of it, and the detection thresholds and staffing models built around human adversary behavior were never designed for an opponent needing no sleep.
What This Means for Security Budgets
My take: CISOs still pricing “AI security” as a single new tool category to bolt onto next year’s budget are behind the actual requirement. Detection needs to shift toward behavior and anomaly patterns not dependent on catching a tired human’s mistake, because the 48-hour exploitation window CrowdStrike documented is now a deadline rather than a comfortable buffer. There is a less obvious dependency worth naming too: AI model providers are now front-line defenders in a way most enterprise security postures do not account for. Attackers target the AI tools themselves through social engineering first, then use the access gained to reach the networks behind them. A company’s security posture is only as strong as the safety controls built by whichever model vendor its tools, and its adversaries’ tools, run on.
Security teams spent the last two years debating whether AI would make attackers faster. The debate is over. The next one, about whether defenders can operate at the same tempo their adversaries now do, will define enterprise security spending for the rest of the decade.
The post AI-Orchestrated Cyberattacks Aren’t Coming, They Already Ran, Twice, in Nine Months appeared first on DataFLOQ.
