Security/ open-source ai · china · cyberattack · government

Chinese Hackers Used Open-Source AI in 85 Account Breach

Chinese hackers used open-source AI agents to hit 85 government accounts and steal thousands of records in about four days, a near-autonomous operation.

Hackers linked to China used two open-source AI agents to breach 85 government accounts in under a week.

The attackers deployed OpenClaw and Hermes, both open-source AI agents, to carry out what's being described as a near-autonomous intrusion. Over roughly four days, the campaign compromised 85 government accounts and extracted thousands of personal records. The available reporting attributes the operation to hackers linked to China but does not break down how much of the work the AI agents handled versus any human operators involved. What stands out is the pace: dozens of accounts and a large batch of records in less than a week.

This is a preview of what off-the-shelf AI tooling does for attackers who used to need bigger teams and more runway. Open-source agents lower the cost of running fast, semi-automated campaigns, which is a problem for any government network still leaning on slow patch cycles and manual monitoring.

Call it a warning shot: the same open weights researchers use to build useful tools are just as usable for breaking into somebody's inbox.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →