What happened
An offensive, state-linked agent runs unattended in YOLO mode, targeting government financial servers, exfiltrating document directories.
2026-07-23
HighPrimaryAnalysis of the July 2026 Hunt.io report where an unattended, autonomous Hermes AI agent targeted the Thailand Ministry of Finance in a state-linked espionage campaign.
What happened
An offensive, state-linked agent runs unattended in YOLO mode, targeting government financial servers, exfiltrating document directories.
Why it matters
Data exfiltration of sensitive ministry communications and internal financial spreadsheets.
Missing authorization check
Not applicable: the agent was operated by the attacker, outside any boundary the victim controls.
Would PP block it?
No authorization boundary inside the victim's environment sits between this agent and its operator, because the operator is the adversary. Permission Protocol constrains agents acting under an organization's own authority.
Incident analysis
2026-07-23
Hunt.io publishes research report identifying Hermes AI agent activities on government subnets.
2026-07-24
Thai security authorities confirm investigation into state-sponsored espionage operations.
Authorization boundary
This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Runtime Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
The agent in this incident was operated by the attacker, not by the victim. Permission Protocol secures internal agent boundaries, not external network perimeters.
Start small
This incident maps to Runtime Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.