Researchers document first ransomware attack run entirely by an AI agent
New CapabilitiesSysdig says an autonomous agent, dubbed JadePuffer, ran the full attack with no human directing it
July 6th, 2026: Case reported as first fully autonomous AI ransomware attackNew here? Follow stories to track developments over time. Create a free account to get updates when stories you care about change.
Overview
Updated Jul 7A ransomware attack ran start to finish with no human running the technical steps. Cloud-security firm Sysdig says an AI agent broke in, stole credentials, and encrypted data without a person directing each move — though Sysdig's Michael Clark clarified to TechCrunch that a human still set the objectives and collected payment.
The agent ran more than 600 distinct payloads, many annotated in plain language explaining its own reasoning. When a step failed, it diagnosed and fixed the bug in about 31 seconds, then continued.
Why it matters
Ransomware used to need a skilled operator. An AI agent that runs the full attack lowers the skill needed to extort a company.
Questions about this story
Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.
No questions yet — be the first to ask.
Key Indicators
Voices
Curated perspectives — historical figures and your fellow readers.
Play
Exploring all sides of a story is often best achieved with Play.
Higher or Lower
A number from this story, against one from elsewhere in the news — guess which is bigger, then keep the chain going. 5 rounds, 3 strikes; a miss costs a strike and resets your streak.
Keyboard: ↓/L lower · ↑/H higher
0 points — sign up to put that on the leaderboard.
Timeline
Order five events from this story, oldest at top. Each in the right slot scores 1 — neighbours within one slot count too. Your previous result — green ✓ for exact slots, yellow ~ for off by one. Cards now in true chronological order.
Sign up to save your score and track a streak across stories.
Connections
Sixteen names from the news. Find the four hidden groups of four. Four mistakes max.
Sign up to keep a daily streak — a new puzzle lands every day.
Exit debate?
Your progress in this debate will be lost.
- 1 Two AI personas square off on this story.
- 2 You predict who'll win each round — correct picks earn XP.
- 3 One crossfire question is yours to fire. Pick it carefully.
Couldn't generate a topic
Select Your Champions
Choose one persona for each side of the debate
DEBATE TOPIC
Choose personas with different perspectives for a more dynamic debate.
Select debater for this side:
No debate personas available right now.
Select debater for this side:
No debate personas available right now.
Who's Got This Round?
Make your prediction before the referee scores
The referee scores both sides on
Round Results
Set the Crossfire
Pick the question both personas must answer in the final round
Debate Oracle! You called every round!
Sharp Instincts! You know your debaters!
The Coin Flip Strategist! Perfectly balanced!
The Contrarian! Bold predictions!
Inverse Genius! Try betting the opposite next time!
XP Breakdown
Prediction History
Organizations Involved
A San Francisco cloud-security company whose threat researchers documented the JadePuffer operation.
An open-source tool for building AI workflows; the agent used a flaw in it to gain its first foothold.
The AI firm that, months earlier, disclosed a state-linked espionage campaign it says was largely run by its own model.
Timeline
March 2021 July 2026
-
Case reported as first fully autonomous AI ransomware attack
Latest CoverageSecurity outlets frame JadePuffer as the first ransomware attack carried out start to finish by an autonomous AI agent.
-
TechCrunch questions the no-human framing
AnalysisTechCrunch reported that Sysdig's Michael Clark clarified a human was still involved — setting goals and collecting payment. The technical execution was fully automated, but the operator still had to initiate and direct the campaign at the strategic level.
-
Sysdig publishes JadePuffer report
DisclosureSysdig details an attack it says an AI agent ran end to end, encrypting 1,342 config items on a production database.
-
CISA and Five Eyes partners publish agentic-AI security guidance
PolicyCISA, NSA, and the cybersecurity agencies of Australia, Canada, New Zealand, and the UK jointly released "Careful Adoption of Agentic AI Services," the first Five Eyes guidance specifically addressing autonomous AI agents. It flags privilege escalation, behavioral misalignment, and accountability gaps as core risks.
-
Anthropic reports AI-run espionage campaign
DisclosureAnthropic says a state-linked group used its Claude model to automate most of an espionage campaign against about 30 targets.
-
Langflow RCE flaw disclosed
VulnerabilityCVE-2025-3248 lets an unauthenticated attacker run code on exposed Langflow servers. This becomes JadePuffer's way in.
-
Nacos auth-bypass flaw disclosed
VulnerabilityCVE-2021-29441, an authentication-bypass bug in Alibaba's Nacos config service, is made public. The agent later abuses it.
Historical Context
3 moments from history that rhyme with this story — and how they unfolded.
The Morris Worm (1988)
A Cornell graduate student, Robert Morris, released a self-replicating program onto the early internet. It spread on its own, infecting thousands of machines and slowing much of the network. No human guided its movement once it was loose.
Cleanup took days and cost an estimated hundreds of thousands to millions of dollars. The scare led to the first Computer Emergency Response Team.
Morris became the first person convicted under the US Computer Fraud and Abuse Act. Self-spreading code became a permanent security concern.
It was the first time code, not a person, drove an attack step by step. JadePuffer extends that idea from blind replication to an agent that reasons and adapts.
WannaCry ransomware (2017)
Ransomware paired with a self-spreading exploit tore through networks in a single weekend. It hit more than 200,000 computers across 150 countries and forced parts of the UK's National Health Service to turn away patients.
Hospitals canceled appointments and surgeries. A researcher stumbled on a kill switch that slowed the spread.
It showed how fast automated ransomware could scale without human hands guiding each infection.
WannaCry automated the spread. JadePuffer automates the thinking too, choosing targets and fixing its own errors as it goes.
NotPetya (2017)
Malware disguised as ransomware swept through companies worldwide, starting in Ukraine. It demanded payment, but its encryption was built so that files could not be recovered even if victims paid. Damage ran into the billions.
Shipping giant Maersk and others halted operations for days. Recovery meant rebuilding systems from scratch.
It proved a ransom note can be a cover for pure destruction.
JadePuffer never stored its encryption key, so paying would not restore the data. Like NotPetya, the demand may mask an attack that cannot be undone.
