AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

AI Incident Database · article · Jul 23, 2026 · UTC

Hunt.io reported that an unidentified threat actor used Nous Research's Hermes agent in unattended "YOLO" mode during an intrusion targeting Thailand's Ministry of Finance. Recovered logs showed Hermes conducting privilege-escalation reconnaissance within ministry systems and recursively searching a directory containing personnel records. Researchers found evidence of compromise but no data exfiltration; the ministry had not publicly confirmed a breach.

Read original source ↗ Open in workspace

recordType
incident-report
evidenceStatus
reported
region
Global

Reported occurrence date: 2026-07-09T00:00:00.000Z

Evidence & attribution

AI Incident Database, Responsible AI Collaborative; McGregor (2021), Preventing Repeated Real World AI Failures by Cataloging Incidents. Incident-specific contributor credits are available at each citation link. Metadata adapted; article text excluded.

License: CC BY-SA 4.0

First collected: 2026-09-19T22:50:59.123Z. This is not the publication date.

Observed changes

AIIC observation times, not verified publisher revision times. Up to eight recent revisions.

2026-09-20T23:22:28.549Z

  • publishedAt: Not provided2026-07-23T00:00:00.000Z