The “First” AI-Driven Ransomware Attack Still Depended on Human Participation
Recently, researchers from the cloud security firm Sysdig disclosed the first documented case of “agentic ransomware.” Dubbed JadePuffer, this extortion scheme featured an AI agent acting independently — without human intervention — to conduct a comprehensive cyberattack. The agent breached a vulnerable server, obtained credentials, traversed the victim’s network, encrypted files, and even generated its own ransom note, demonstrating an ability to adapt like a human hacker. It was emphasized that the operation was carried out “without any human oversight,” suggesting “no human at the keyboard.”
Nevertheless, this is not the whole picture. In a Monday interview with CyberScoop, Mike Clark, Sysdig’s senior director of threat research, clarified that a human was indeed involved — albeit not in the execution phase. “A human was responsible for setting up and managing the operation, provisioning the essential infrastructure, such as the command-and-control server, the staging server for the stolen data, and choosing a victim,” Clark explained. He also pointed out that the credentials used to infiltrate the victim’s database weren’t acquired by the AI agent; instead, they were previously compromised and provided for the operation.
These clarifications do not contradict Sysdig’s initial claim, and the complexities of the attack remain both significant and impressive. The agent capitalized on a known vulnerability in Langflow, a popular open-source tool for developing LLM applications, subsequently moving to a production MySQL server and exploiting another identified weakness to gain admin access. It encrypted over 1,300 configuration records and created its own ransom note, complete with a Bitcoin address for the ransom payment. Sysdig has not disclosed the identity of the targeted entity.
While the techniques used were generally standard, the rapid and clear execution distinguished this incident. The agent corrected a failed login attempt in just 31 seconds, documenting its thought process through natural-language code comments throughout the operation.
A detail that initially clouded the situation has now been clarified. Clark informed CyberScoop that Sysdig detected “multiple models were involved in the attack,” mentioning keys harvested from OpenAI, Anthropic, DeepSeek, and Gemini, raising questions about whether various models were utilized at different stages of the breach. Upon further investigation, Clark explained to TechCrunch that these keys were part of what the agent stole, not indicators of the models responsible for its operation.
“The agent scoured the Langflow host for valuable items — provider API keys, cloud credentials, cryptocurrency wallets, and database configurations — and those provider keys were part of the loot,” he stated via email. “They indicate what the attacker deemed worth targeting but do not clarify which model made the decisions.”
Regarding the model powering JadePuffer, Clark mentioned that Sysdig “could not determine the specific model driving the agent” and lacks insight into its system prompt or configuration.
A theory from Microsoft researcher Geoff McDonald, shared on LinkedIn a few days ago, is pertinent in this context. McDonald speculated that an open-weight model with stripped safety training, rather than a cutting-edge model, could have been responsible for the attack, based on his red-teaming experiences suggesting that frontier lab safety measures are effective. Sysdig’s account neither confirms nor refutes this theory.
McDonald also warned that ransomware operations might now be limited primarily by the attackers’ budget rather than human effort, raising the possibility of “thousands or tens of thousands of simultaneous campaigns.” This concern somewhat conflicts with Clark’s description from Monday. (If a human still needs to select each victim, provision infrastructure, and source database credentials for every operation, that creates a bottleneck.)
Nonetheless, Clark told CyberScoop that while Sysdig has not seen the same operation targeting other victims thus far, given the low cost of deploying an agent, he expects this to change shortly.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


