Sev0AI security incidents, tracked

All incidents / AI-run attack

Hermes AI agent automated intrusion into Thailand's Ministry of Finance

Thailand Ministry of Finance, disclosed Jul 2026. AI-run attack Data exposed High

Researchers found exposed attacker directories showing an AI agent running unattended post-exploitation against Thailand's Ministry of Finance, enumerating hosts, browsing personnel records and staging webshells and implants. No evidence of file exfiltration was found; the activity was assessed as a Chinese-speaking espionage actor.

Disclosed
Jul 2026
Organization
Thailand Ministry of Finance
Vendor
Unknown
Product
Hermes agent (open source)
Type of AI
AI agent
How it happened
AI-run attack: Autonomous intrusion
Harm
Data exposed
Data involved
Credentials, Internal documents
Reach
One organization
Severity
High
Model at fault
No
Status
Confirmed
Country
TH

Sources

  1. https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent
  2. https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Hermes AI agent automated intrusion into Thailand's Ministry of Finance", https://sev0.fyi/incidents/2026-07-01-thailand-finance-ministry-hermes-agent/