A financially motivated, Chinese-speaking threat actor ran a five-and-a-half-month campaign (July–September 2026) using autonomous AI agent frameworks named Hermes, Cairn, and Strix to scan, exploit, and plant payment-card skimmers on more than 100 e-commerce sites, including a Fortune 500 hospitality company, a major U.S. airline, and a large industrial-supplies distributor. The Hermes orchestration agent used Claude Opus 4.6 and DeepSeek models to make tactical hacking decisions and direct post-exploitation activity with minimal human input, ultimately stealing over 600,000 valid credit card records. Anthropic confirmed it identified and banned the account behind the Claude usage after the campaign was disclosed.