AI Agents Crack 85 Government Accounts and Steal 2,500+ Personnel Records
Brief
A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85 employee accounts, and stole more than 2,500 personnel records, according to research from Dream.
The campaign demonstrates how coordinated AI agents can now execute large parts of an intrusion operation at machine speed. Dream researchers uncovered a 160 MB archive containing 1,395 files linked to the operation. The material documented 12 attack waves conducted between July 1 and July 4, 2026.
The framework used Hermes and OpenClaw, deploying up to 8 sub-agents in parallel to perform reconnaissance, credential attacks , API testing, data collection, and lateral movement. The researchers did not identify the affected entities or the operator.
All credited sources
Highest-trust first. Dates are the publisher's original publish time.
AI Agents Crack 85 Government Accounts and Steal 2,500+ Personnel Records
A suspected near-autonomous intrusion campaign that compromised government entities in Asia, cracking 85 employee accounts and extracting at least 2,564 personnel records over roughly four days in July 2026.
The Dream Research Labs said the campaign archive contained 1,395 files and showed an AI-operated framework performing reconnaissance, credential attacks, lateral movement, data collection, and persistence attempts at a scale normally associated with coordinated human teams.
According to the report, the operation used Hermes and OpenClaw agent frameworks, deploying as many as eight letter-designated sub-agents concurrently across 12 attack waves.
AI Agents Crack Government Accounts
The agents reportedly decompiled Angular JavaScript bundles, enumerated 21 connected systems, mapped OIDC and Keycloak configurations , and identified more than 36 API endpoints on one target.
Several APIs allegedly exposed user information without authentication, including names, departments, and SSO identifiers, which were used to support subsequent password spraying.
Full Attack Chain (Source: Dream)
The framework paired harvested usernames with predictable password patterns and Tesseract OCR to defeat small CAPTCHA challenges, researchers said. It initially cracked 12 accounts, then 73 more after expanding its pattern set.
The report also describes three exposed debug-style authentication endpoints that issued valid sessions, as well as a JWT validation weakness in which tokens using the none algorithm were accepted.
Of the compromised accounts, 84 reportedly authenticated through an SSO bridge into an internal information system, a 98.8 percent pivot rate.
Data theft extended beyond the cracked accounts. Dream said the attackers obtained 1,409 employee records, 916 records from an unauthenticated API and 239 legal-professional records from a Ministry of Justice endpoint.
Eight AI Agents Breach Government Systems, Crack 85 Accounts and Steal 2,500+ Records
A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85 employee accounts, and stole more than 2,500 personnel records, according to research from Dream.
The campaign demonstrates how coordinated AI agents can now execute large parts of an intrusion operation at machine speed. Dream researchers uncovered a 160 MB archive containing 1,395 files linked to the operation. The material documented 12 attack waves conducted between July 1 and July 4, 2026.
The framework used Hermes and OpenClaw, deploying up to 8 sub-agents in parallel to perform reconnaissance, credential attacks , API testing, data collection, and lateral movement. The researchers did not identify the affected entities or the operator.
However, Dream said the operational documentation used Simplified Chinese in internal reporting and Traditional Chinese in target analysis, suggesting a Chinese-language operator. Public reporting identified Taiwan as the target, though Dream’s report described the victims only as government entities in Asia.
AI Agents Breach Government Systems
The AI-driven framework began by downloading and analyzing JavaScript bundles from a government portal. It extracted API endpoints, OAuth client IDs, Keycloak configuration data, and authentication details.
This enabled the agents to map 21 connected government systems, including single sign-on infrastructure. One target reportedly exposed more than 36 API endpoints for account management, user data, uploads, and administration.
Some endpoints were unauthenticated, allowing the system to retrieve employee information, including names, departments, and SSO account identifiers . The agents also harvested publicly available SSO integration documentation and SDK examples.
