Home Cyber Security News AI Agents Crack 85 Government Accounts and Steal 2,500+ Personnel Records

AI Agents Crack 85 Government Accounts and Steal 2,500+ Personnel Records

0

A suspected near-autonomous intrusion campaign that compromised government entities in Asia, cracking 85 employee accounts and extracting at least 2,564 personnel records over roughly four days in July 2026.

The Dream Research Labs said the campaign archive contained 1,395 files and showed an AI-operated framework performing reconnaissance, credential attacks, lateral movement, data collection, and persistence attempts at a scale normally associated with coordinated human teams.

According to the report, the operation used Hermes and OpenClaw agent frameworks, deploying as many as eight letter-designated sub-agents concurrently across 12 attack waves.

AI Agents Crack Government Accounts

The agents reportedly decompiled Angular JavaScript bundles, enumerated 21 connected systems, mapped OIDC and Keycloak configurations, and identified more than 36 API endpoints on one target.

Several APIs allegedly exposed user information without authentication, including names, departments, and SSO identifiers, which were used to support subsequent password spraying.

Full Attack Chain (Source: Dream)

The framework paired harvested usernames with predictable password patterns and Tesseract OCR to defeat small CAPTCHA challenges, researchers said. It initially cracked 12 accounts, then 73 more after expanding its pattern set.

The report also describes three exposed debug-style authentication endpoints that issued valid sessions, as well as a JWT validation weakness in which tokens using the none algorithm were accepted.

Of the compromised accounts, 84 reportedly authenticated through an SSO bridge into an internal information system, a 98.8 percent pivot rate.

Data theft extended beyond the cracked accounts. Dream said the attackers obtained 1,409 employee records, 916 records from an unauthenticated API and 239 legal-professional records from a Ministry of Justice endpoint.

The archive also contained a full JSON user export, seven SSO client secrets that had been rotated, six database credentials, and internal network ranges.

An unrestricted upload function accepted a web shell, although a Forms Authentication layer prevented execution and stopped the attempt from becoming confirmed remote code execution.

Researchers characterized the framework’s decision process as a two-layer Bayesian prioritization engine. Individual findings began with a 0.50 prior and were promoted or discarded after tool output, manual confirmation, impact analysis, and blocker evidence.

Hermes and OpenClaw Usage (Source: Dream)

It then assembled validated findings into attack chains, scoring the likelihood that every precondition would hold. The report documented five “Learning Cycles” that searched public vulnerability sources and code repositories when techniques failed, plus structured after-action reports that reshaped later waves.

The system also rejected seven false positives, including an apparent time-based SQL injection ultimately traced to an SMTP timeout. Dream said the incident illustrates how agentic orchestration, not a model alone, can lower the cost and speed of offensive operations.

Defenders should prioritize exposed APIs, production debug routes, JWT verification, SSO trust boundaries, MFA, and credential-spraying controls.

Organizations should continuously test these paths, correlate identity telemetry, and rapidly remove secrets and artifacts exposed to public access.

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version