The ‘first’ AI-run ransomware attack still needed a human

Researchers identified an 'agentic' ransomware attack where an AI agent executed technical steps of a cyberattack. However, experts clarify that human operators were still required to provision infrastructure and select targets.
Why it matters
This highlights the evolving threat landscape where AI can accelerate cyberattacks, while emphasizing that human oversight remains a critical component of malicious operations.
Last week, researchers at cloud security firm Sysdig said they’d documented the first known case of “agentic ransomware.” It was an extortion operation, dubbed JadePuffer, in which an AI agent — not a human — handled the technical execution of a real-world cyberattack from start to finish. The agent broke into a vulnerable server, stole credentials, moved through the target’s network, encrypted files, and even wrote its own ransom note, adapting to obstacles along the way like a human hacker would. Coverage of the funding described it as run “without any human oversight,” with “no human at the keyboard.”
The article provides a technical clarification of a security claim, balancing the AI's capabilities with human involvement.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in