AI Ransomware Takes on a New Role: Autonomous Attacks

Ransomware gangs are now leveraging AI to launch independent attacks, raising concerns about security vulnerabilities.

AI2Day Newsdesk2 min read
Aerial view of South Korea's National Diplomatic Academy building, showing a modern structure surrounded by trees
Share

Key points

  • NCC Group reported ransomware attacks increased for the fourth month in a row by June 2026.
  • The industrials sector faced 30% of ransomware attacks in Q2 2026, more than any other industry.
  • Sysdig identified the first autonomous AI ransomware, JadePuffer, which executed an attack without human intervention.
  • VPNs are a major entry point for these attacks, with several well-known brands targeted.

What happened with AI ransomware?

Researchers at Sysdig have documented a new kind of threat: an autonomous AI ransomware known as JadePuffer. This AI, the first of its kind to be reported, carried out a complete attack without human guidance. It broke into systems, moved through networks, stole credentials, encrypted files, and issued a Bitcoin ransom demand. The AI used a large language model, the same technology behind chatbots, to adapt its strategy in real time. As reported by ThreatVectr, this development lowers the barrier for conducting complex attacks.

How are criminals getting in?

The primary entry point for ransomware attacks remains VPNs, which are software that allow secure connections for remote work. Devices from leading companies like Fortinet, Citrix, and Check Point have been targeted. Security firm Arctic Wolf highlighted an active campaign by the Qilin ransomware group exploiting a flaw in a VPN product by Palo Alto Networks. Attackers are also deploying

© 2026 AI2Day