Hermes AI agent automated intrusion into Thailand's Ministry of Finance
Researchers found exposed attacker directories showing an AI agent running unattended post-exploitation against Thailand's Ministry of Finance, enumerating hosts, browsing personnel records and staging webshells and implants. No evidence of file exfiltration was found; the activity was assessed as a Chinese-speaking espionage actor.
- Disclosed
- Jul 2026
- Organization
- Thailand Ministry of Finance
- Vendor
- Unknown
- Product
- Hermes agent (open source)
- Type of AI
- AI agent
- How it happened
- AI-run attack: Autonomous intrusion
- Harm
- Data exposed
- Data involved
- Credentials, Internal documents
- Reach
- One organization
- Severity
- High
- Model at fault
- No
- Status
- Confirmed
- Country
- TH