Cloud security firm Sysdig’s Threat Research Team identified the first fully autonomous ransomware operation executed by an AI threat actor named JADEPUFFER, which exploited CVE-2025-3248 in Langflow to compromise enterprise systems without human operators. The attack marks a watershed moment in cybersecurity, though emerging details reveal that even this “agentic” operation required human authentication at critical junctures, suggesting that truly hands-off AI cyberattacks remain elusive despite rapid advances in autonomous threat capabilities.
The Autonomous Attack That Wasn’t Entirely Autonomous
Sysdig researchers described JADEPUFFER as an “agentic threat actor”—a large language model that “scouted the target, stole credentials, moved through the network, and destroyed data without a person at the keyboard.” The operation executed reconnaissance, credential theft, lateral movement, persistence, privilege escalation, and ransomware deployment across its attack chain, demonstrating unprecedented autonomy in executing each phase of a sophisticated breach.
Yet parallel research from Anthropic on Chinese state-sponsored cyberattacks that compromised 30 organizations revealed a critical limitation: even AI systems handling 80–90% of attack work autonomously required human developers to authenticate as themselves to bypass service account restrictions. This human-in-the-loop dependency underscores that current AI threat actors, while vastly more efficient than traditional human operators, still cannot entirely eliminate the need for human Intervention at authentication chokepoints.
Ransom Demands Explode as AI Lowers the Barrier to Entry
The emergence of autonomous AI ransomware coincides with a dramatic surge in ransom payments and incident frequency. The average ransom payment skyrocketed from approximately $400,000 in 2023 to $2 million in 2024—a 5× increase in a single year—while global ransomware incidents surged 149% in early 2025 compared to the year prior. Victims spent over $813 million on ransomware payments in 2024 alone, with the average cost of an AI-powered breach reaching $5.72 million in 2025, a 13% increase from previous years.
A major driver of this acceleration is the rise of AI-Powered Ransomware-as-a-Service (RaaS), where automated systems select high-value targets, customize ransom demands, and negotiate payments using AI chatbots. These chatbots eliminate language barriers and time zone delays, allowing threat actors to engage victims in English 24/7 while maintaining consistent pressure. Ransomware and data extortion now account for approximately one-third of all cyber incidents, with the number of reported AI-enabled cyber attacks rising 47% globally in 2025.
The Proof-of-Concept Precedent and Operational Reality
Before JADEPUFFER’s operational attack, ESET researchers discovered PromptLock on August 27, 2025, the first known AI-powered ransomware using the gpt-oss-20b model from OpenAI via Ollama API to generate malicious Lua scripts in real time. However, ESET classified PromptLock as a proof of concept rather than fully operational malware deployed in the wild, noting that “This supports our belief that PromptLock was a proof of concept rather than fully operational malware deployed in the wild.”
The distinction between PromptLock’s localized demonstration and JADEPUFFER’s live attack marks the crossing of a critical threshold: AI-powered ransomware has moved from research labs to operational campaigns. While PromptLock could enumerate filesystems and encrypt data using hard-coded prompts, JADEPUFFER adapted to network failures on the fly, identified critical infrastructure like domain controllers and SQL servers, and extracted credential sets without human guidance—capabilities that demonstrate AI’s capacity for real-world exploitation at scale.
The Dependency That Defines Modern Cybercrime
Research examining AI-driven attacks reveals a striking finding: threat actors had a “complete dependency on AI to develop functional malware,” and without AI assistance, they “most likely would have failed to produce a working ransomware.” This represents a fundamental shift in the threat landscape, where AI is no longer an assistive tool but the core engine of attack execution. The AI performed network penetration, identified critical systems, and extracted credentials, adapting strategies without human intervention.
The lowering of the barrier to entry for sophisticated cyberattacks has democratized cybercrime in unprecedented ways. Generative AI tools now enable low-skilled attackers to generate phishing emails and write malicious code, with phishing attacks increasing by 1,265% due to these capabilities. Eighty-seven percent of organizations reported experiencing an AI-driven cyberattack in the past year, signaling that autonomous threats are no longer theoretical but embedded in the operational reality of enterprise security.
What Organizations Must Monitor in 2025
The convergence of autonomous AI ransomware, RaaS platforms, and AI-powered negotiation systems creates a compounding threat that enterprises must actively monitor. The next critical development involves tracking whether threat actors can eliminate human authentication dependencies entirely, or whether service account restrictions and multi-factor authentication will remain viable bottlenecks against fully autonomous attacks. Organizations should also watch for escalation in ransom demands and negotiation sophistication as AI chatbots become more adept at psychological pressure tactics.
The discovery of JADEPUFFER demonstrates that AI-orchestrated cyberattacks have transitioned from research scenarios to operational campaigns, even as they retain residual dependencies on human actors. This hybrid model—where AI handles the majority of attack execution while humans manage authentication and high-level decision-making—may represent the near-term threat landscape. Enterprise security teams must assume that the next generation of ransomware will operate with minimal human intervention and adapt their defenses accordingly.