AI incident #1669 ·

Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Open on the AI Incident Database 4 news reports Synced from the AIID API · record last edited 4 Sep 2026

What happened

Hunt.io reported that an unidentified threat actor used Nous Research's Hermes agent in unattended "YOLO" mode during an intrusion targeting Thailand's Ministry of Finance. Recovered logs showed Hermes conducting privilege-escalation reconnaissance within ministry systems and recursively searching a directory containing personnel records. Researchers found evidence of compromise but no data exfiltration; the ministry had not publicly confirmed a breach.

Only the incident metadata is stored here. The underlying news reports are on the AI Incident Database (CC BY-SA 4.0); use the links above to read them.

News reports (4)

Coverage catalogued by the AI Incident Database. Titles link to the original publisher; the text is not reproduced here.

Who was involved

Alleged harmed party
Thailand Ministry of Finance Privacy National security and intelligence stakeholders Information security Governments Government of Thailand Government agencies
On AIID: Thailand Ministry of Finance, Privacy, National security and intelligence stakeholders, Information security, Governments, Government of Thailand, Government agencies

AI systems implicated

Hermes AgentAI agent systems

Classification (MIT AI Risk Repository taxonomy)

Risk domain
Risk subdomain
Causal entity
Intent
Timing
Harm level
Sectors
Countries

Linked by AIID editors or by its text-similarity model.

Other incidents involving Threat actors