Published : 06 Jul 2026, 01:13 AM
Updated : 08 Sep 2026, 09:21 AM
Security researchers say they have uncovered what they believe to be the first documented case of an artificial intelligence system carrying out a cyberattack from start to finish without human assistance.
The development has fuelled concerns that AI could make it easier for criminals to launch sophisticated attacks, The Independent reported.
The attack involved ransomware, in which victims are locked out of their data and forced to pay a ransom to regain access.
Researchers at cloud security firm Sysdig identified the AI system, naming it Jadepuffer.
It infiltrated a vulnerable server, found passwords and login credentials on its own, then encrypted a live database before demanding a bitcoin ransom.
Michael Clark, Sysdig's director of threat research, said in a blog post that ransomware attacks have always involved a human either at the keyboard or writing the script.
He said his team believes this to be the first recorded case of "agentic ransomware" -- an extortion operation carried out entirely by a large language model, with no human input at any stage.
According to Sysdig, after gaining access through Langflow, an open-source tool for building AI applications, the AI immediately began searching for credentials, with particular focus on Chinese cloud providers including Alibaba, Tencent and Huawei.
The system did not follow a fixed script. It adjusted its approach as it went, correcting course far faster than a human attacker typically could.
Clark said the AI's adaptability stood out most, noting that in one instance, it moved from a failed login attempt to a working fix in just 31 seconds.
Sysdig also found that victims could not recover their files even if they paid the ransom, since the AI had already deleted the original data without keeping a backup.
The findings have not yet been independently verified.
Even so, the case adds to growing concern about how quickly AI systems are gaining the ability to conduct advanced cyberattacks without human oversight.
Last month, the Five Eyes intelligence alliance warned that AI-driven threats to businesses and governments could materialise within months.
The alliance said advanced AI models are expected to reshape both attack and defence capabilities in cyber security, and called for a coordinated response across organisations and society.