Back to timeline

Research · July 1, 2026

Sysdig reports ransomware run by an AI agent

On 1 July 2026 researchers at Sysdig described an operation they call JADEPUFFER, which they assess to be the first documented case of 'agentic' ransomware. Through the CVE-2025-3248 flaw in Langflow the operator reached a server running MySQL and the Nacos service, encrypted 1,342 configuration items and left a ransom demand; the key was not saved, so the data cannot be recovered even if the ransom is paid. That a language-model agent ran the operation is Sysdig's conclusion, not an established fact.

Why it matters

If the assessment is right, this is the first described complete extortion cycle, from reconnaissance to destruction of data, run by an agent rather than by a person with scripts, and aimed at the infrastructure around AI. It is the testimony of one security firm from its own telemetry: the victim is not named, the page gives no time for the activity itself, and nothing is independently confirmed.

What Sysdig says (post of 1 July 2026). The way in is an authentication flaw in Langflow (CVE-2025-3248), through which encoded Python was run. The operator enumerated the host, harvested AI provider keys, cloud credentials and wallets, searched the internal network, entered a MinIO object store with default credentials, persisted through a crontab entry and reached a production server with MySQL and Nacos (where it got the root credentials is unknown). There it created a backdoor administrator, encrypted 1,342 configuration items with the AES_ENCRYPT function, deleted the original tables and left a table with the ransom demand. The key was generated and printed once but not saved. The note claims AES-256, while the function defaults to AES-128-ECB. Why Sysdig thinks the operator was an agent. Four lines of evidence: payloads that narrate themselves, with reasoning in natural language; a fix to a failure in 31 seconds (from a failed login to a working fix); comprehension of planted natural-language context; and the note's Bitcoin address, a well-known documentation example, where Sysdig cannot tell whether the model invented it or the operator deliberately used exactly that address. More than 600 distinct payloads in a compressed window. Sysdig notes that no technique was novel. Follow-up. On 20 July 2026 Sysdig described the same operator's return with ENCFORGE, a compiled Go ransomware for AI and machine-learning files (about 180 extensions). What the record does not claim: that the operator was in fact a language-model agent (Sysdig cannot see its configuration or prompt); which model; who is behind it; who the victim is or how many there were; when exactly the activity happened (not stated); any independent confirmation.

Event record

Event date
July 1, 2026
Timeline date
Event date
Verification
Sources gathered automatically · October 11, 2026
Lines
ID
evt-1016

The day Sysdig published its report. The page gives no date for the activity itself. Sysdig's second post dates the first report both 'July 1' and 'July 3'.

Sources

Related events

Antecedents for this event are still being researched.