Security firm Sysdig documented JadePuffer, described as the first fully autonomous ransomware attack carried out almost entirely by an AI agent, in July 2026. After a human operator selected the target, the AI agent independently exploited a Langflow vulnerability, stole credentials, moved laterally through systems, and deployed roughly 600 payloads to encrypt 1,342 configuration items, including autonomously correcting a failed login attempt within 31 seconds. The attack’s ransom note referenced a decryption key that was never saved, making recovery impossible even if a ransom were paid.
