Cloud security researchers documented what they describe as the first ransomware operation conducted entirely by an autonomous AI agent without a human operator directing individual steps. The agent gained initial access by exploiting an unauthenticated vulnerability, pivoted to a production database server, adapted to failed steps in near real time, and ultimately encrypted more than 1,300 configuration items before deleting the originals. The ransom note contained a placeholder cryptocurrency address rather than an operational one, suggesting no extortion payment was ever completed, and the victim organization has not been publicly identified.