221 — Chinese-speaking operator incident: autonomy evidence, no swarm established Reviewed September 6, 2026 UTC. PRIMARY EVIDENCE Unit 42 reports a Chinese-speaking operator using DeepSeek through Hermes, directed via Telegram. Researchers attribute their visibility to an accidentally exposed home-directory file server and describe a May 7 session with no recovered operator input after the initial task. The reported autonomous workflow changed targets after failures. The report separates unsuccessful autonomous attempts from successful manual operations; its 460-plus target count combines both. Multiple configured model tools do not establish a cooperating agent fleet. Attribution to a Zhuhai-based operator is Unit 42's assessment, not our independent finding. No Chinese laboratory affiliation is established. Source: https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ The fetched page metadata lists publication July 30 and modification August 11, 2026. These are publisher metadata, not archive timestamps. SOURCE CORRECTION A Permission Protocol incident page presents the target count and successful compromises as one autonomous chain. That conflicts with the primary report's separation of manual and autonomous operations. Its purported Unit 42 link returned 404 through the web reader; the real report was recovered by searching the operator alias within Unit 42's domain. Secondary: https://www.permissionprotocol.com/agent-incident-tracker/unit42-deepseek-hermes-autonomous-malicious-exploit-scanning Broken cited destination: https://unit42.paloaltonetworks.com/chinese-actor-telegram-deepseek-hermes Do not use the secondary account to claim 460 autonomous attacks or three autonomous compromises. ASSESSMENT This is a substantially better lead for externally active, operator-directed agent behavior than a model-labelled dataset or a scripted social demonstration. It still does not answer the narrower escaped-swarm question. The evidence we possess is a researcher's published account, not the underlying authenticated session archive. Parallel shell/scanner work would not itself prove independently reasoning peers. The useful investigative lesson is to look for legitimate published incident analyses and voluntarily published run exports with evidence of operator input, session boundaries and actual destinations. Accidental workspace exposure is a possible explanation for agent-looking public artifacts; it is not a reason to retrieve private workspace contents. PRESERVATION AND NEXT 221-private/unit42.html: public article capture, HTTP 200, 260376 bytes; SHA256SUMS preserved. No actor server, victim, exploit or private workspace was accessed. No investigated commands were executed. Next separate lead: March 10–12 GitHub discussion of a Chinese-language agent community and its linked public release, https://github.com/ythx-101/openclaw-qa/discussions/75 . Its conversation alone cannot authenticate agent authorship.