Reports have emerged that Chinese-linked hackers have deployed autonomous AI agents to breach Taiwanese government systems — and cybersecurity experts are warning that financial institutions could be next.
Jonathan Frost, Director of Global Advisory for EMEA at BioCatch, says the attack signals a dangerous new era for digital fraud. "News of another AI-based cyber compromise is fast becoming a daily occurrence," he said. "This latest attack on the Taiwanese government is notable for several reasons. The use of open-source models, whilst unremarkable, highlights low barriers to entry for organised criminals and state actors."
What makes this attack particularly concerning is the level of autonomy the AI demonstrated. When blocked, the system deployed new agents to adapt its strategy, researching and developing alternative tactics on the fly — all without human intervention. "The models operated autonomously, mirroring a human hacker's approach," Frost explained. "Unlike humans, the AI likely worked continuously, scaled operations efficiently, and did not require rest."
Frost warns that this threat won't stay confined to government targets for long. "Criminals will inevitably adopt similar strategies in digital fraud," he said, adding that traditional fraud controls are ill-equipped to handle attackers that can constantly learn and change tactics.
For banks, this raises an urgent question: how do you distinguish between a legitimate customer, a trusted AI agent, and a malicious one — in real time? Frost argues that institutions need to move beyond static fraud controls, focusing instead on detecting non-human interactions in digital channels.
"Institutions that can identify and block malicious agents without disrupting legitimate customers will reduce losses and enhance customer experience," he said.