Hermes AI agent automated intrusion into Thailand's Ministry of Finance
What happened
Researchers found exposed attacker directories showing an AI agent running unattended post-exploitation against Thailand's Ministry of Finance, enumerating hosts, browsing personnel records and staging webshells and implants. No evidence of file exfiltration was found; the activity was assessed as a Chinese-speaking espionage actor.
Between 9 and 13 July, threat intelligence firm Hunt.io and researcher Bob Diachenko found three publicly accessible folders on a Hong Kong-hosted staging server, holding 585 files and about 470 MB of attack material: exploit code, webshells, traffic-tunnelling tools, stolen credentials and scripts aimed at the ministry's mail systems and Hadoop data platform. Logs showed the open-source Hermes agent running in its unattended mode, which removes the approval step before each command, as it enumerated ministry hosts, searched for ways to raise its privileges and browsed files including the web root and personnel records. The material also included a previously unknown backdoor the operator called Hades, and active session cookies suggested several internal systems had been compromised. How the attackers first got in is not clear. Clues on the server, such as a Chinese search-engine key and earlier use for known espionage tools, point to a Chinese-speaking operator, but Hunt.io did not attribute it to a specific group.
How it happened
AI-run attack: Autonomous intrusion. The attacker's own AI agent carried out the break-in, working through the steps with little human involvement.
Sources do not say whose AI model was involved. The product was Hermes agent, which is open source, a type of AI agent.
Impact
Data was exposed. Data involved: credentials and internal documents. The impact was confined to one organization and its users or customers.
Severity is rated High, calculated from how far the incident reached and how sensitive the data was.
Was the AI at fault?
No. The failure was in the systems, settings or people around the AI, not in the model's behaviour.
Status and timeline
Confirmed by the affected organization, the AI vendor, a regulator or a named security research firm.
It became public on 23 Jul 2026.
Thailand's national CERT and cybersecurity agency were notified on 15 July and acknowledged it the same day; publication followed a seven-day disclosure window. The ministry has not publicly confirmed a breach.