Threats · 49 days ago
The break is not that Hermes was “hacked.” The operator turned off its permission prompts, so it could keep running commands on its own inside a live government network. That makes the agent a post-exploitation workhorse, not just a chat tool.
Recovered material tied to the Thai Ministry of Finance intrusion shows the agent checking hosts, hunting for root paths, and crawling staff records. Investigators also found an exposed `/hermes-results/` directory with logs, 585 files, and 470 MB of tooling, which let them map the operation after the fact.
The exposed output path matters because it turns the operator’s own artifacts into a discovery source. If teams deploy AI agents with shell access, the risk is unattended execution plus residual logs and scripts left where outsiders can browse them.
4 sources covering this story
AI Agent Drives Espionage Attack on Thai Ministry of Finance
Attackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finance.
The Record from Recorded Future
Hackers used autonomous AI agent to spy on Thailand's finance ministry
Hackers used an autonomous artificial intelligence agent to carry out a cyber-espionage campaign against Thailand's Ministry of Finance, researchers discovered.
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
An operator ran the Hermes AI agent with approval prompts disabled during a Thai finance ministry intrusion, then left its logs on an open directory.
Part of the PlainSec briefing for 2026-07-28