AIPolicyTracker

AI incident ·

Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

4 news reports Synced from source · record last edited 4 Sep 2026

In brief

An AI system built by Nous Research and AI agent system developers and deployed by Threat actors, hackers and 3 others allegedly harmed Thailand Ministry of Finance, Privacy and 5 others.

Risk domain
Not classified
Occurred
Coverage
4 reportsJul 2026

What happened

Hunt.io reported that an unidentified threat actor used Nous Research's Hermes agent in unattended "YOLO" mode during an intrusion targeting Thailand's Ministry of Finance. Recovered logs showed Hermes conducting privilege-escalation reconnaissance within ministry systems and recursively searching a directory containing personnel records. Researchers found evidence of compromise but no data exfiltration; the ministry had not publicly confirmed a breach.

Laws that address this harm

No recorded instrument yet addresses this use case where it happened. See the open queue.

Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).

News reports (4)

Titles link to the original publisher; report text is not reproduced here.

Who was involved

Alleged harmed party
Thailand Ministry of Finance Privacy National security and intelligence stakeholders Information security Governments Government of Thailand Government agencies

AI systems implicated

Hermes AgentAI agent systems

Classification (MIT AI Risk Repository taxonomy)

Risk domain
—
Risk subdomain
—
Causal entity
—
Intent
—
Timing
—
Harm level
—
Sectors
—
Countries
—

Linked by editors or by text similarity in the source dataset.

Other incidents involving Threat actors

Source record: incident #1669 on the AI Incident Database · all 4 reports