← Back to search

AI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopens

Cybersecurity Today · 2026-07-29 · 12 min
relevance 34 1841 words Episode page ↗ Audio ↗
Show full episode description
Hospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand's Finance Ministry. South Carolina's AnMed reopened some physician offices four days into a ransomware attack with phones, internet, and systems still offline, forcing manual processes and in-person medication refills, as broader healthcare ransomware totals hit 410 attacks worldwide in the first half of the year and a HIPAA Security Rule update was delayed to 2027 while class-action efforts began. Researchers report the Dysphoria IoT botnet moved command-and-control to blockchain name services and victim relays, making takedowns harder, with estimates above 200,000 bots and DDoS offerings up to 4 Tbps. Shared Claude chats were briefly indexed by Google, exposing sensitive data via public share links, before results stopped appearing. Hunt.io found attackers running a Hermes autonomous AI agent in Thailand's Finance Ministry, plus new "Hades" malware, suggesting reconnaissance. Stadler Rail refused a 10M CHF extortion demand tied to supplier data theft.
0:00 / 0:00
📑 Chapters — tap a time to jump there
00:00
Introduction and Headlines
00:30
South Carolina Hospital Ransomware Attack
02:07
Healthcare Ransomware Crisis
03:25
IoT Botnet Uses Blockchain
05:40
Shared AI Chats Exposed
08:00
AI Agent Infiltrates Thailand Ministry
10:45
Swiss Train Maker Refuses Ransom
12:31
Closing Remarks
A South Carolina hospital system reopens its doors with many systems still offline. An IoT Botnet moves its command and control onto the blockchain. An autonomous AI agent roams through a national finance ministry. Shared AI chats turn up in Google search results again. And a Swiss train maker tells an extortion crew to get lost. This is Cybersecurity Today, and I'm your host, David Shipley. Let's get started. South Carolina's AnMed reopened its physician offices on Tuesday for scheduled appointments, four days into a ransomware attack that still has some of its phones, internet, and computer systems offline. Patients walking in were asked to bring their own medications in their original containers and were asked to recite their own medical history. Urgent refill requests required showing up in person, and staff were working through a backlog of canceled appointments by hand. At the peak of the disruption, AnMed had to close 80 of its 106 facilities temporarily. Imaging, OBGYN, primary care, oncology, and radiation all went dark on Monday. Every group medical office had to be closed, and every elective procedure had to be canceled. The system runs hospitals and physician practices across upstate South Carolina and northeast Georgia. AnMed first told the public Sunday morning that it had a phone and internet outage. By Sunday afternoon, that had become a cybersecurity disruption involving malware. Patients inside the emergency department describe what happened. Blue-black screens and a countdown. One patient told a reporter that the message on the screens gave AnMed 72 hours to pay before everything was leaked. Another patient was discharged with handwritten paperwork and sent to a different hospital because no tests or scans could be done. AnMed says the forensic review remains in its early stages, and it cannot yet describe the nature or scope of the incident. Healthcare is having a brutal year. Comparatex ransomware tracker counted 410 attacks on healthcare organizations worldwide in the first half of the year, up 14% from the last six months of 2025. That works out to an average of 2.3 healthcare ransomware attacks every single day. The United States accounted for 225 of the 410 accounts, with Killen, The Gentleman, Lockbit, and the Inc. ransomware gang leading the field. At the same time of the onslaught of ransomware attacks, regulatory requirements in the United States for healthcare organizations have been pushed back. The HIPAA security rule update that would have mandated annual penetration testing, a defined risk analysis methodology, and multi-factor authentication was pushed from May of 2026 to July 2027. That decision followed pushback from healthcare organizations on the timeline for the changes and the costs. Meanwhile, lawyers aren't waiting for their forensics or regulatory rule improvements. ClassAction.org put up an AnMed page within the first 48 hours, soliciting current and former patients as well as employees for a potential class action lawsuit. An IoT botnet called Dysphoria has rebuilt its command and control infrastructure around blockchain name services, as well as a mesh of relays running on its own victims. Researchers say the result is a considerably harder to take down botnet. The use of blockchain as a C2 mechanism is a direct response to the take down of Jackskid, one of four IoT botnets hit by a coordinated American, German, and Canadian law enforcement action on March 19th. What's changing here is that the use of Ethereum name services or blockchain in general is going from a secondary redundancy trick to being the primary method to ensure that C2 infrastructure remains free from disruption. XLAB, a Chinese threat researching firm, published an analysis on dysphoria on July 25th alongside a notice from China's National CERT, or CNCERT. Over a fast run of builds this spring, dysphoria's operators moved command and control onto blockchain name records that pointed to distribution nodes handing out server lists. Those lists were made entirely of infected machines. So trying to seize a controller now means trying to seize a victim's router. CNCERT and XLAB put the dysphoria botnet population above 200,000 bots. With about 4,400 of those bots active inside China between July 14th and 20th, and a single-day peak of infected devices of about 239,000 observed abroad. The two also published different vulnerability lists, though they both agree that weak telnet and SSH credentials remain the most reliable way in. The dysphoria DDoS storefront advertises attacks of up to roughly 4 terabits per second for tens to hundreds of dollars. The capability of the botnet has not been independently confirmed. The biggest botnet to date clocked in at more than 31 terabits per second this year. Defenders should patch exposed IoT gear, retire devices that can no longer be updated, kill default and weak credentials, and switch off remote management and UPnP on devices wherever they are not needed. Shared, clawed conversations turned up in Google search results over the weekend, and reporters who went looking found medical records, internal corporate documents, and the names and phone numbers of primary school-aged children. A Reddit user flagged it on Saturday, noting that a site-restricted Google query against clode.ai's share path returned a long list of conversations. Futurism, digging through the results, described finding a detailed medical report on a real patient, clinical trial results with patient names, documents marked internal use only, and employee reviews containing personal information about the workers being reviewed. The mechanism here is clode's own share feature, which creates a link that can be shared with anyone. Anyone with access to the link can find the conversation. Anthropic's position is that the links themselves are not the problem. The company told TechCrunch that a share link only reaches a search index if someone posts it somewhere as crawlable, like a forum or a social media thread, and that a link sent privately stays out of search. An Anthropic spokeswoman said the company does not hand out chat directories or sitemaps to search engines, and that the links are neither guessable nor discoverable on their own. Google, for its part, said search engines do not decide what gets published on the web, and that these pages were indexed across multiple engines. Site owners have controls to prevent crawling. Both statements are technically accurate, but both sidestep the more useful question, which is whether the user clicking create a public link really understood that they may be creating something that could be caught up in a search index, rather than sending something to a co-worker. Google Docs offers a comparable link sharing feature, but those documents don't show up in search results. By Monday afternoon, the query had stopped returning results, so something was remediated, though no one has said exactly what. And this has all happened before. Forbes reported hundreds of index-clode conversations last year, with Google estimating just under 600 pages before they disappeared. In the same period, 404 Media reported a researcher scraping roughly 100,000 publicly shared chat GPT conversations. Nobody has independently confirmed the scale of this weekend's chat exposure. Threat actors ran an autonomous AI agent inside Thailand's Ministry of Finance, and researchers only found out because those operators left their own server wide open while the intrusion was still running. Hunt.io published those findings last week. On infrastructure control by the attackers, the firm found hundreds of publicly accessible files. That included malware, stolen credentials, attack scripts, AI agent logs, active authentication cookies, and evidence that multiple ministry systems had already been compromised. The attack used Hermes, an open-source AI agent released earlier this year by Noose Research. The operators turned on the software's YOLO mode, which lets the agent execute commands without pausing for human approval. According to Hunt.io, the agent explored the Thai network on its own, searched internal files, collected system information, and hunted for privilege escalation opportunities. The agent made its own decisions about where to look, and no one was at the keyboard. Earlier this month, Hugging Face disclosed that it had been breached by an autonomous AI agent, and that agent turned out to belong to OpenAI. OpenAI's agent exploited two previously unknown vulnerabilities and used stolen credentials to get into Hugging Face. In the Thailand incident, the Hermes agent infrastructure held exploits for several known vulnerabilities, scripts written specifically against the ministry's administrative web portals, email systems, and document management platform, as well as tooling built to test ministry email passwords. It also included a previously undocumented malware family that Hunt.io named Hades. Both Windows and Linux builds of the malware were found, each capable of remote command execution and file transfer, functioning as a custom backdoor for persistence after the initial break-in. How the attackers first got in remains unknown. Hunt.io found no evidence that any data was exfiltrated. The activity looked like reconnaissance, credential theft, and network mapping ahead of something. The firm did not attribute the campaign to a named group, though it said multiple indicators point to Chinese-speaking operators. The malicious activity traces back to at least mid-June, and the Thai CERT and National Cybersecurity Agency were notified on July 15th. The finance ministry has not publicly acknowledged the intrusion and did not respond to a request for comment. Thai cybersecurity officials said Monday they would strengthen national defenses against attacks involving AI agents without referencing the Hunt.io investigation. Swiss train manufacturer Stadler Rail says it won't pay a 10 million Swiss franc ransom demanded after the Everest group stole technical documents from a supplier's file-sharing platform. The company said under no circumstances will it pay the ransom, and it can't be extorted. It has filed a criminal complaint and says it won't negotiate. The breach happened in mid-July and did not touch Stadler's own systems. The stolen material consisted of technical documents belonging to a third-party supplier, taken after credentials for a data exchange platform were compromised. Stadler says it lost none of its own data, that no relevant personal information was involved, and that trains running worldwide are unaffected. All production sites remain operational. Stadler is one of Europe's largest rail equipment manufacturers, supplying trains, trams, and metro cars, as well as locomotives internationally. It employs almost 18,000 people and generates more than $4.9 billion in revenue. The company has been here before. In 2020, attackers got inside some of its systems, stole internal data, and demanded around $6 million in Bitcoin. Stadler refused then, as well. The attackers published samples, reportedly financial and administrative documents, and Stadler held its ground. When it comes to paying, Proofpoint said in a survey last week of 953 organizations, that 54% had paid, and more than a third of those got hit with a second extortion demand. Everest is a Russian-speaking ransomware crew active since at least 2020, with a track record across energy, transportation, and telecommunications. And that's Cybersecurity Today for Wednesday, July 29th. I've been your host, David Shipley. Thanks for listening. We appreciate all your feedback. Feel free to reach us at technewsday.com or .ca, or you can leave a comment under the YouTube video. I'll be back on Friday with the latest headlines. Until then, I hope you have a great rest of the week, and stay safe.