The agent corrected a failed login in about 31 seconds, then encrypted more than 1,300 configuration records and left a ransom note.
What happened
Researchers documented an operation called JADEPUFFER in July 2026 and described it as the first confirmed case of an AI agent carrying out a complete extortion campaign without direct human operation, Cyberpress reported on September 18, 2026. The agent entered through a flaw in Langflow, a tool used to build applications around AI models, catalogued as CVE-2025-3248 and allowing code to be run on a server without any login. Once inside, the payloads searched for programming interface keys, cloud login details, database files, cryptocurrency wallet phrases, and configuration data. The agent created a backdoor account, encrypted more than 1,300 configuration records, deleted the originals, and left a ransom demand.
Going deeper
Speed of correction is what distinguishes an agent from a script. Conventional automated ransomware follows instructions written in advance and stops when something unexpected happens, while an agent works toward an objective, observes what each action produced, and chooses what to do next. Researchers recorded this one recovering from a failed login attempt in roughly 31 seconds. It identified exposed systems, tested credentials, moved between machines, and issued the demand without a person approving each step. Most criminal use of AI remains a stage behind this, with attackers using language models to write phishing emails, generate scripts, or summarize what they have found while an operator still decides what happens next.
What was said
The most serious change is "not a new encryption technique," researchers wrote in findings covered by Cyberpress, describing it instead as the removal of the human bottleneck. Their assessment is that autonomous agents can test options continuously, fix errors quickly, and run several stages of an intrusion faster than a human-operated affiliate working through the same sequence.
In the know
An intermediate model sits between AI-assisted attacks and fully autonomous ones, and researchers pointed to a campaign called FortiBleed as the example. There, an affiliate ran a framework of 14 separate agents that researched vulnerabilities, verified them, built tools to test stolen credentials, and produced attack playbooks, according to the same research. Human operators still performed the work inside victim networks, handling remote access, movement between systems, privilege escalation, and deployment of the ransomware itself. The activity was linked to the INC and Lynx ransomware groups. Later activity connected to the JADEPUFFER campaign introduced a second tool named ENCFORGE, built specifically to destroy artificial intelligence and machine learning assets, including model checkpoints, the saved states of a trained model, along with the databases holding its reference material and its training data.
The big picture
Healthcare organizations deploying AI hold assets that most backup and inventory processes were never written to cover. A model fine-tuned on an organization's own clinical documentation, a database of reference material assembled from patient records, or a set of training files represents work that cannot be reconstructed quickly and may exist in no formal inventory. The federal Security Risk Assessment Tool was updated this month to widen its scope to every location that creates, receives, maintains, or transmits electronic protected health information, according to HealthIT.gov, which covers a model trained on patient data as squarely as it covers a server. Organizations running AI in clinical or administrative settings should establish where those assets live, whether they are backed up on the same schedule as clinical systems, and whether anyone would notice their deletion before a ransom note arrived.
FAQs
What separates an AI agent from automated malware?
Automated malware executes instructions written in advance and fails when conditions differ from what its author anticipated. An agent is given a goal, evaluates the result of each action, and selects the next one, which lets it adapt to an environment nobody surveyed beforehand.
Does this change what defences an organization needs?
The controls remain the same, covering patching internet-facing software, restricting credentials, segmenting networks, and maintaining tested offline backups. What changes is the time available, since an attacker who recovers from failures in seconds compresses the window in which detection can act.
Why would attackers target AI and machine learning assets specifically?
Those assets often represent substantial investment, cannot be rebuilt quickly, and frequently sit outside the backup arrangements protecting production databases. Destroying them creates pressure to pay in organizations that could otherwise restore their clinical systems.
What is a model checkpoint?
A saved copy of a model's learned state at a point during or after training, used to resume work or deploy the model. Losing checkpoints without a backup can mean repeating training that took considerable time and computing cost.
How should an organization inventory its AI assets?
Start by identifying every model, dataset, and reference database in use, who owns each, where it is stored, and what it was built from. Assets assembled by clinical or research teams outside IT are the ones most often missing from that list.
