Cyber Warfare · Today's Signal

A Hacker Let an AI Agent Run an Attack on Thailand's Finance Ministry Solo

Published 2026-07-25 · SAL Cyber Command Intelligence Network
The short answer

Hermes, an AI agent, was reportedly used to automate an unattended intrusion against Thailand's Finance Ministry, signaling a shift from AI-assisted attack prep to AI-executed live operations that compress the time between initial access and damage.

According to reporting from BleepingComputer and The Hacker News, an attacker used an AI agent called Hermes to automate an intrusion against Thailand's Finance Ministry, with coverage indicating the agent was left running largely unattended to carry out the operation. The specifics of what the agent touched inside the ministry's systems aren't detailed here, but the framing is the story: a human set the objective, then stepped back while the tooling executed.

This is the shape of things to come, not a novelty. Security teams have spent two years warning that agentic AI would eventually flip from defensive copilot to offensive operator, and the appeal to attackers is identical to the appeal for legitimate ops teams: agents work at machine speed, don't get tired, and don't need a skilled operator hand-holding every step. Nation-state and criminal crews have already been documented using AI for phishing content, vulnerability triage, and code generation -- the shift here is delegating the live execution phase, not just the prep work. Once one crew proves an unattended agent can complete an intrusion against a government target, the technique gets copied, packaged, and commoditized fast, the same way ransomware-as-a-service did.

The SAL read: if your incident response plan assumes attacks move at human speed and get noticed during the slow parts, you're already behind -- start budgeting for detection and response that operates as fast as the agents attacking you, because the operator on the other end may not even be watching in real time.

What to actually do: treat this as a forcing function to review anomaly-detection thresholds and alert-to-response latency now, not after your own incident. Agentic attacks compress the window between initial access and damage, so any control that depends on a human noticing something "off" within hours rather than minutes needs to be re-evaluated this quarter.

Frequently asked questions

What happened in the Thailand Finance Ministry attack?

According to reporting from BleepingComputer and The Hacker News, an attacker used an AI agent called Hermes to automate an intrusion against Thailand's Finance Ministry. Coverage indicates the agent was left running largely unattended to carry out the operation, with a human setting the objective and then stepping back while the tooling executed the attack.

Is this the first time AI has been used in a cyberattack?

No. Nation-state and criminal groups have already been documented using AI for phishing content, vulnerability triage, and code generation. What's new in this case is delegating the live execution phase of an intrusion to an unattended agent, not just using AI for prep work.

Why does an unattended AI agent matter for attackers?

Agents work at machine speed, don't get tired, and don't need a skilled operator hand-holding every step, which is the same appeal legitimate operations teams see in agentic AI. Once one crew proves an unattended agent can complete an intrusion against a government target, the technique is likely to get copied and commoditized quickly, similar to how ransomware-as-a-service spread.

How should security teams respond to agentic AI attacks?

Security teams should treat this incident as a forcing function to review anomaly-detection thresholds and alert-to-response latency now, before facing their own incident. Any control that depends on a human noticing something "off" within hours rather than minutes needs to be re-evaluated this quarter, because agentic attacks compress the window between initial access and damage.

What is the main risk if incident response assumes human-speed attacks?

If an incident response plan assumes attacks move at human speed and get noticed during slower phases, that plan is already behind, because the operator running an agentic attack may not even be watching in real time. Organizations need to budget for detection and response that operates as fast as the agents attacking them.

Sources: BLEEPINGCOMPUTER · THE HACKER NEWS

More from SOVEREIGN SIGNAL

SAL SENTRY — your private AI security operations center.24/7 watch on network, cloud, endpoints, and email. Flat $999/mo. Live in 48 hours.