Skip to Content
logologo
AI Incident Database
寄付する
発見する
投稿する
  • ようこそAIIDへ
  • テーブル表示
  • リスト表示
  • 組織
  • 分類法
  • 空間ビュー
  • ブログ
  • AIニュースダイジェスト
  • おまかせ表示
  • サインアップ
発見する
投稿する
  • ようこそAIIDへ
  • テーブル表示
  • リスト表示
  • 組織
  • 分類法
  • 空間ビュー
  • ブログ
  • AIニュースダイジェスト
  • おまかせ表示
  • サインアップ
組織

Threat actors

Incidents involved as Deployer

インシデント 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

2026-07-01

From July 1–4, 2026, suspected China-linked hackers reportedly used a multi-agent framework built on Hermes and OpenClaw to compromise Taiwanese government systems. The agents reportedly compromised 85 credentials and used persistent access to connected systems to exfiltrate more than 2,564 personnel records. Taiwan later confirmed an overseas AI-assisted campaign against government agencies, without attributing it to China.

もっと

インシデント 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

2026-07-09

Hunt.io reported that an unidentified threat actor used Nous Research's Hermes agent in unattended "YOLO" mode during an intrusion targeting Thailand's Ministry of Finance. Recovered logs showed Hermes conducting privilege-escalation reconnaissance within ministry systems and recursively searching a directory containing personnel records. Researchers found evidence of compromise but no data exfiltration; the ministry had not publicly confirmed a breach.

もっと

インシデント 16703 Report
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

2026-05-10

An unidentified attacker reportedly used an LLM agent during a May 10 intrusion after exploiting a vulnerable marimo Python notebook. The agent reportedly reused harvested AWS credentials to obtain an SSH key, then pivoted through a bastion host and exfiltrated the schema and contents of an internal PostgreSQL database. Sysdig attributed the post-compromise command stream to real-time agent execution rather than a prebuilt script.

もっと

関連団体
同じインシデントに関連するその他のエンティティ。たとえば、インシデントの開発者がこのエンティティで、デプロイヤーが別のエンティティである場合、それらは関連エンティティとしてマークされます。
 

Entity

hackers

Incidents involved as Deployer
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

もっと
Entity

China-linked threat actors

Incidents involved as Deployer
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

もっと
Entity

AI agent system deployers

Incidents involved as Deployer
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

もっと
Entity

Agentic threat actors

Incidents involved as Deployer
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

もっと
Entity

Peter Steinberger

Incidents involved as Developer
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

もっと
Entity

Nous Research

Incidents involved as Developer
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

もっと
Entity

Large language model developers

Incidents involved as Developer
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

もっと
Entity

AI agent system developers

Incidents involved as Developer
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

もっと
Entity

Taiwanese government employees

影響を受けたインシデント
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

もっと
Entity

Taiwanese government agencies

影響を受けたインシデント
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

もっと
Entity

Taiwan Ministry of Justice

影響を受けたインシデント
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

もっと
Entity

Privacy

影響を受けたインシデント
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

もっと
Entity

National security and intelligence stakeholders

影響を受けたインシデント
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

もっと
Entity

Information security

影響を受けたインシデント
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

もっと
Entity

Governments

影響を受けたインシデント
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

もっと
Entity

Government of Taiwan

影響を受けたインシデント
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

もっと
Entity

Government agencies

影響を受けたインシデント
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

もっと
Entity

OpenClaw

Incidents implicated systems
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

もっと
Entity

Large language models

Incidents implicated systems
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

もっと
Entity

Hermes Agent

Incidents implicated systems
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

もっと
Entity

AI agent systems

Incidents implicated systems
  • インシデント 1646
    4 レポート

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

もっと
Entity

Cybercriminals

Incidents involved as Deployer
  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

もっと
Entity

Thailand Ministry of Finance

影響を受けたインシデント
  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

もっと
Entity

Government of Thailand

影響を受けたインシデント
  • インシデント 1669
    4 レポート

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

もっと
Entity

Victims of automated cybercrime

影響を受けたインシデント
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

もっと
Entity

Enterprise IT systems

影響を受けたインシデント
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

もっと
Entity

Amazon Web Services (AWS) customers

影響を受けたインシデント
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

もっと
Entity

Amazon Web Services (AWS)

Incidents implicated systems
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

もっと
Entity

Amazon Web Services (AWS) cloud infrastructure

Incidents implicated systems
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

もっと
Entity

marimo

Incidents implicated systems
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

もっと

リサーチ

  • “AIインシデント”の定義
  • “AIインシデントレスポンス”の定義
  • データベースのロードマップ
  • 関連研究
  • 全データベースのダウンロード

プロジェクトとコミュニティ

  • AIIDについて
  • コンタクトとフォロー
  • アプリと要約
  • エディタのためのガイド

インシデント

  • 全インシデントの一覧
  • フラグの立ったインシデント
  • 登録待ち一覧
  • クラスごとの表示
  • 分類法

2026 - AI Incident Database

  • 利用規約
  • プライバシーポリシー
  • dd3f754