Threat-intelligence researchers found open directories on attacker-controlled infrastructure running Hermes, an open-source, minimally-restricted AI agent, in an unattended mode against Thailand’s Ministry of Finance. Given objectives by a human operator, the agent then autonomously performed privilege escalation, system enumeration, and network reconnaissance without step-by-step supervision, and logs showed it was also instructed to enumerate personnel and financial records. Researchers found no confirmation that files were actually exfiltrated, and the ministry has not publicly confirmed a breach occurred.