← The Desk 2026-07-25 The Wire
The Perimeter Site

The AI is Autonomous. The Target is Government.

Ingrid Solheim
2026-07-25
# The AI is Autonomous. The Target is Government. The Thai Finance Ministry has been hit by an AI agent called Hermes. This is not a story about a clever hacker using a chatbot to write a more convincing email; it is a story about the removal of the human bottleneck. Hermes didn't just suggest a strategy; it automated the attack. We have spent the last two years terrified of "superintelligence"—the kind of AI that might decide humans are redundant. Meanwhile, we have ignored the arrival of automated mediocrity. An AI agent does not need to be a genius to be dangerous; it only needs to be faster than the person tasked with filing the incident report. The argument from the AI optimists is usually that these tools are too prone to "hallucinations" to be effective weapons. They claim the error rate is too high for a sophisticated breach. This is a misunderstanding of the economics of attack. A human attacker might have a high success rate per attempt, but they are limited by sleep, appetite, and the need for a social life. An autonomous agent with a 10 per cent success rate that can launch ten thousand attempts per hour is an existential problem for any ministry that still relies on a manual patching cycle. The bottleneck has shifted from the attacker's skill to the defender's bureaucracy. The second-order effect here is not just a compromised Thai server, but the inevitable ripple through the regional financial ecosystem. When a Finance Ministry is breached, the trust in the data flowing to and from that office evaporates. Every auditor, every central bank, and every foreign investor now has to ask if the figures they are seeing are authentic or the work of a loop running in a data centre halfway across the world. Then we have the paperwork. North Carolina is receiving $666,000 as part of a settlement following the 23andMe data breach. I find the sum almost poetic in its specificity, though I suspect the state treasury will treat it with the same enthusiasm one reserves for a moderately sized tax rebate. There is something deeply satisfying about the lag between a data breach and a settlement payment. The breach happens in an instant; the data is exfiltrated in minutes; the records are sold on a forum within a week. But the legal machinery moves with the grace of a glacier. By the time the $666,000 arrives in Raleigh, the victims have likely already changed their passwords, found new identities, or simply given up. It is a classic example of the "settlement industrial complex." The money moves from the corporate balance sheet to a government fund, often after years of litigation. I wonder how the state intends to spend it. Will it go toward "cyber resilience" programmes—which usually means buying more software that no one knows how to configure—or will it simply vanish into the general fund? In Oslo, we see similar patterns with GDPR fines, though the regulators there tend to be slightly less patient with the "we're sorry" press releases. The law, as written, is often a blunt instrument. It demands disclosure and mandates fines, but it cannot un-leak a genetic profile. The settlement is a financial tidying exercise, not a security solution. Looking at this week's wire, the volume of noise is staggering. There were 548 data breaches reported this week, with 18 of them landing on my desk today alone. The sector rankings remain stubbornly consistent. Technology is at #1, followed by Government at #2 and Healthcare at #3. It is a helpful reminder that the people selling the security solutions are often the first to be compromised. In the healthcare sector, Centers Lab NJ LLC is currently under investigation for a breach involving over 542,000 patient records. I would be curious to see their disclosure timeline. Usually, there is a gap of several months between the moment the attackers leave the building and the moment the victims receive a letter in the post telling them their medical history is now public. It is the regulatory equivalent of telling someone their house has burnt down while you are handing them a voucher for a new toaster. On a more tactical note, we have a reminder that the most sophisticated encryption in the world is useless if you trust the hotel Wi-Fi. Attackers are currently hijacking hotel DNS settings to redirect users to fake Microsoft 365 login pages. It is a beautifully simple play. You arrive in a city, you connect to the "Guest_WiFi," and you are presented with a familiar login screen. You enter your credentials, and you have just handed over the keys to your corporate kingdom. The technical failure here is a lack of DNSSEC or simply a failure of the hotel's outsourced IT provider to secure the gateway. The real danger is the "trusted device" problem. A consultant logs in at a hotel in Brussels or London on a Tuesday. They are phished. They don't notice because the redirect is seamless. On Wednesday, they return to the office and connect their laptop to the internal corporate network. The attacker, now possessing a valid M365 session, doesn't need to "hack" the firewall; they simply walk through the front door using the consultant's identity. The hotel is the bait; the corporate network is the prize. I am often asked if there is a "silver bullet" for these issues. There isn't. There is only the slow, grinding work of ensuring that DNS is signed, that MFA is phishing-resistant, and that governments stop treating cybersecurity as a series of cheques to be written after the damage is done. I suspect we will see more of these "agentic" attacks. The Thai Finance Ministry is likely just the first of many. The question is whether our regulatory frameworks can adapt to a threat that operates at machine speed, or if we will continue to rely on settlements that arrive three years too late. I'll be watching the UK's Cyber Security and Resilience Bill. Andy Burnham has reappointed Liz Lloyd as minister to ensure continuity, which is a polite way of saying the paperwork is too complex to let a new person start from scratch. One can only hope the Bill has more teeth than the average settlement agreement. Until then, I suggest you avoid the hotel Wi-Fi. Or at least, assume that the "Free High-Speed Internet" comes with a complimentary subscription to a credential harvesting site.
◼
← More from the Desk Live Wire →

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.