Find notable cyber news and cases, enriched with sources, timelines, and signals.

Thailand's Ministry of Finance hit by network compromise

Incident
First reported
Last updated
Happening score
H score 23
2 unique sources, 2 articles

Summary

Hide ▲

Thailand's Ministry of Finance is linked to a post-exploitation intrusion in which an operator used Hermes AI agent in unattended YOLO mode to automate activity inside the ministry network. Hunt.io and Bob Diachenko tied the activity to July 9–July 13-era artifacts from three exposed directories on a server hosted in Hong Kong, with 585 files totaling about 470 MB that included web shells, stolen credentials, and Hermes logs. The recovered material points to checks for root access, filesystem crawling, and access to staff records dating to 2012, while the ministry has not confirmed a breach and the recovered files do not show data leaving the network.

Related Happenings

Shadow-Aether-040 AI-augmented campaign against Mexican government entities

Campaign
H score41 First: 13.05.2026 16:00 Last: 13.05.2026 16:00 Sources 1

About this happening: The Shadow-Aether-040 campaign used AI agents and custom tooling to compromise six government entities in Mexico, increasing the risk of follow-on intrusion and data...

Timeline

  1. 24.07.2026 13:15 3 articles · 9h ago

    Hermes-assisted post-exploitation is linked to Thailand's Ministry of Finance

    Initial Disclosure

    Hunt.io and Bob Diachenko linked recovered Hermes logs, a hidden web shell, and custom Hadoop scripts to post-exploitation inside Thailand's Ministry of Finance network. The recovered material shows host checks for root access, filesystem crawling, and access to staff personnel records dating to 2012, with no evidence of data leaving the network; Thailand's national CERT and cybersecurity agency were notified on July 15.

    Show sources