Eight AI Agents, Four Days, 2,500 Records: What the Taiwan Attack Means for Your Threat Model

Eight AI Agents, Four Days, 2,500 Records: What the Taiwan Attack Means for Your Threat Model

The Taiwan government breach shows AI agents carrying out a coordinated attack at machine speed. Here's why UK SMEs should worry about attacker economics, not just attacker skill — and what to change about detection and response.

Tony Brown
By Tony Brown ·

In September 2025, security researchers pieced together something that changes the maths of cyber defence. A campaign against a Taiwanese government target ran for four days. It used eight AI agents working in coordination. By the end, roughly 2,500 records had been exfiltrated. What made the case remarkable was not the size of the haul — plenty of breaches are bigger — but how little human hand-holding it took to get there.

Most of the reconnaissance, the probing, the writing of exploit code, the movement between systems: the agents did it. A person set the goal and stepped back. The machines handled the grind.

A dimly lit server room with rows of network equipment, illustrating a large-scale cyber breach

If you run a small or medium business in the East Midlands, your instinct might be to file this under 'nation-state problem, not mine'. That instinct is wrong, and the reason it's wrong has nothing to do with who the target was. It has everything to do with what the attack cost to run.

Stop asking how sophisticated the attackers were

For twenty years, the security industry has trained everyone to think about attackers in terms of skill. Was it a script kiddie or a state actor? Advanced persistent threat or opportunist? The whole vocabulary sorts adversaries by capability, and it shapes how businesses spend money. If you believe the dangerous attackers are rare and highly skilled, you assume they'll go after banks and defence contractors, not a 40-person accountancy firm in Beeston.

The Taiwan attack breaks that logic. The agents were competent, not brilliant. They didn't invent new exploits. They chained together known techniques, tried things, failed, adjusted, and tried again — the way a patient junior analyst might, except thousands of times faster and without needing sleep, salary, or supervision.

That is the shift worth understanding. The barrier to running a competent, coordinated intrusion has just collapsed. What used to require a team of skilled operators over weeks can now be run by a small number of people directing software agents over days. The scarce resource — human expertise — has been partly automated away.

When the cost of doing something falls, the volume of it rises. This is not a security observation; it's a basic one about economics. Cheaper attacks mean more attacks, and more attacks mean the targeting net widens. The 40-person accountancy firm was never worth a nation-state's time when the operation cost tens of thousands of pounds in skilled labour. At a fraction of that cost, the calculation changes.

Speed is the part your defences aren't built for

Here's the uncomfortable detail buried in the timeline. Four days.

Think about how your business would actually respond to an intrusion. An alert fires — assuming you have monitoring that catches it. Someone notices, maybe during working hours, maybe not. They investigate, rule out a false positive, escalate. A decision-maker gets involved. Perhaps your IT provider is called. Systems get isolated. By the time a coordinated human response is underway, how many hours have passed? For a lot of SMEs, the honest answer is measured in days, not hours — and often the first anyone hears of a breach is a customer, a bank, or the ICO getting in touch.

An AI-coordinated attack does not operate on human time. It probes and pivots continuously. It doesn't wait for Monday morning. It doesn't lose momentum over a bank holiday weekend. The Taiwan agents compressed weeks of attacker activity into four days, and they could have gone faster against a softer target.

Most SME security spending goes on the perimeter: firewalls, email filtering, endpoint protection. These matter and you should have them. But they're built around a model where you stop the attacker at the door. The Taiwan case is about what happens once something gets in and starts moving at machine speed. If your detection-and-response capability runs on human reaction times, you are bringing a walking pace to a race that's now run by machines.

What to actually change

None of this calls for panic, and it certainly doesn't call for a shopping spree on products with 'AI' in the name. It calls for a specific rethink about timelines. Three things matter.

Shorten the gap between compromise and detection. The single most valuable question to ask about your setup is: if an attacker got onto one of our machines right now, how long before we'd know? If you can't answer, that's your first project. Practically, this means proper logging that's actually collected and reviewed, endpoint detection that flags unusual behaviour rather than just known malware, and — this is the bit people skip — someone watching outside office hours. Attacks that run over four days will run through your nights and weekends. Monitoring that only works nine-to-five leaves three-quarters of the week uncovered.

Make response automatic where you safely can. If detection has to wake a human before anything happens, you've already lost the speed battle. Sensible automated containment — isolating a device that starts behaving strangely, disabling an account showing signs of takeover, blocking a suspicious outbound connection — buys time. It doesn't replace human judgement; it holds the line until a person can look properly. For most SMEs this is realistic through a managed detection and response service rather than something built in-house.

Reduce what an intruder can reach once inside. The Taiwan agents did damage by moving between systems. Every bit of lateral movement you prevent reduces what a fast, automated attack can achieve in its four-day window. That means multi-factor authentication everywhere it'll go, tight limits on who and what can access what, network segmentation so a foothold in one place doesn't hand over everything, and ruthless removal of old accounts and unused access. This is unglamorous work. It's also the highest-value work you can do, because it slows an attacker regardless of whether a human or a machine is at the keyboard.

The honest summary

The Taiwan attack is the first clearly documented case of near-autonomous AI agents breaching a government target at scale. It won't be the last, and the next generation of targets will be far more ordinary — the SMEs that hold useful data and assume they're too small to bother with.

The defensive lesson is not 'the attackers got cleverer'. It's 'the attackers got cheaper and faster'. Cheaper means more of them, aimed more widely. Faster means the days you assumed you had to respond have shrunk to hours.

Your firewall was never going to save you on its own, and it certainly won't now. What matters is how quickly you notice, how quickly you contain, and how little an intruder can touch once they're in. If you don't know where you stand on those three, that's the conversation to have — with us or with whoever handles your IT — before it becomes the conversation you have with the ICO.

Request a no obligation callback