Security researchers say they have uncovered what may be the first ever cyberattack carried out from start to finish by an AI agent without a person at the keyboard. Sysdig said the attacker, named Jadepuffer, broke into a vulnerable server, hunted down passwords and login credentials, encrypted a production database and then demanded a bitcoin ransom.
The claim matters now because it pushes AI from a support tool into the role of attacker. Michael Clark, writing for the Sysdig Threat Research Team, said the group had captured what it assesses to be the first documented case of agentic ransomware, a complete extortion operation driven end to end by a large language model. He said ransomware has long depended on human control, whether through direct operation or script writing, and that this case breaks that pattern.
Jadepuffer also appears to have changed tactics while the operation was under way. After gaining access to Langflow, it began looking for credentials with explicit coverage of Chinese providers such as Alibaba, Tencent and Huawei. Sysdig said the autonomous operation retried failed steps within refined parameters, and Clark described one sequence in which it moved from a failed login to a working fix in 31 seconds. That kind of speed matters because it suggests the system was not simply following a rigid script; it was adjusting as it went.
The most serious part of the case is what happened after the break-in. Sysdig researchers said the AI agent had already deleted the compromised data without backing up any of it before demanding payment, which would make recovery far harder for the victim if the attack were real and successful. But the finding sits with an important caveat: it has not yet been independently verified, so the claim of a first-of-its-kind autonomous attack remains provisional even as it lands in a threat landscape already rattled by warnings that frontier AI could alter both offensive and defensive cyber capabilities.
That is why this story lands with such force today. If the assessment holds, it marks a step change from human-directed ransomware to machine-run extortion, with an AI not only finding a weakness but also adapting, retrying and finishing the job on its own. The unanswered question is no longer whether AI can assist cybercrime; it is how often a system like Jadepuffer can be pointed at a vulnerable target and turned loose before anyone notices.

