Just Launched Gruve PulseAI Platform, your private AI infrastructure, production-ready in under 2 weeks.PulseAI is live — private AI, ready in 2 weeks.

See PulseAI
Blog

No hacker needed: New AI ransomware can automate database attacks from start to finish, warns cybersecurity firm

August 7, 2026

JADEPUFFER, an autonomous AI agent, shows how AI ransomware can automate reconnaissance, credential theft, lateral movement, and encryption. The attacks increase risks for India and IMEA through exposed AI tooling, cloud misconfigurations, and weak IAM. Organizations must patch AI systems, restrict code execution, enforce least privilege, monitor agent frameworks, and prepare for AI-driven cyberattacks.

The month of June in the subcontinent brings with it unbearable heat and dust storms. This year was no different, but with a twist: The temperature in the open was matched by rising heat inside the boardrooms. Many of India’s premier companies and an elite institution came under unprecedented cyberattacks.

A leading automobile manufacturing company publicly admitted a ransomware attack on its systems and its technology arm on June 23. A day earlier, on June 22, an industry behemoth, an electronics and semiconductor manufacturer, had confirmed a cyber breach after a group called World Leaks posted more than 200,000 files. Some of these files had Apple’s proprietary markings and Tesla documents marked “trade secret.”

The spate of cyberattacks did not end here: This year, in July, nearly 19,000 files, nearly 14.3 gigabytes of data, tied to India’s largest nuclear power project, the Kudankulam Nuclear Power Plant in Tamil Nadu, surfaced on the dark web. These files were posted by the ransomware group World Leaks. However, the plant itself was not breached. The files reportedly originated from a contractor and were traced to a server hosted by a third-party data centre provider. Indian authorities said reactor and safety-control systems, which are air-gapped from the internet, were unaffected. But the breach still exposed engineering drawings, supplier lists, and inspection records. These are the kind of material that, pieced together, can map an adversary’s path toward more sensitive targets. Furthermore, the attackers succeeded in sending out the message that even critical infrastructure, indispensable to a country’s security, could be targeted with increasing sophistication.

These incidents highlight two different developments in the cyber threat landscape. In India, recent breaches have exposed sensitive corporate and infrastructure-related data, highlighting the importance of developing a comprehensive cyber threat mitigation plan.

In the coming times, with the rise in AI-powered cyberattacks, the result of cyberattacks could be far worse. Sysdig, a cloud security firm, documented JADEPUFFER, which it describes as the first documented ransomware operation driven end to end by an autonomous AI agent. The advent of JADEPUFFER should set the alarm bells ringing.

Why this matters now

Gone are the days when humans were required to probe for weaknesses in the network and launch attacks. Today, AI can enable malware deployment and continuous attempts until success.

The stakes for India and IMEA

Ransomware attacks have always been there. However, what is new is the strategy of their deployment. Earlier, ransomware needed a human being who could probe weak points on a network, steal credentials, move through a network, and deploy the payload. The need for human resources and expertise to launch cyberattacks slowed the process. Furthermore, skills were scarce, limiting the number of serious operators. JADEPUFFER suggests that the challenge of finding an expert to launch cyberattacks is dissolving. An AI agent can now chain these steps on its own, adapting to failures as a human operator would.

The evolving cyberthreats are not theoretical for India, which is Asia-Pacific’s most targeted country for ransomware this year, and for the Middle East and Africa regions, which carry a rising share of global attacks. The use of AI agents to breach cybersecurity changes the nature of who can attack, and how fast they can attack.

The evolving cyber threat landscape

What happened in India eerily matched the Five Eyes’—the common name for the intelligence alliance between the USA, Canada, Britain, Australia, and New Zealand—warning earlier. In a three-page statement, the Five Eyes had warned that “While AI will help us improve cyber defense over time, it also accelerates the speed, scale, and sophistication of cyber threats.” The cyber breach that targeted India’s largest nuclear power plant in Tamil Nadu, along with two of the industry behemoths, put the world on notice: attacks previously requiring experts and days of manual effort will only accelerate as AI enters the equation, as JADEPUFFER, discussed below, shows.

The entry point: CVE-2025-3248 and the Langflow flaw

JADEPUFFER’s opening move consisted of exploiting CVE-2025-3248, an unauthenticated remote code execution flaw in Langflow. Langflow is an open-source framework for building AI applications and agent workflows. The vendor patched it in Langflow 1.3.0, and the flaw joined America’s Known Exploited Vulnerabilities list in May 2025. Many servers were never updated. Langflow instances draw attackers because they sit exposed on the internet, holding API keys and cloud credentials.

The autonomous chain: Recon, credentials, lateral movement, encryption

Once the agent breached the network, it worked alone. Sysdig counted more than 600 unique payloads across the operation. It harvested cloud and AI provider credentials, installed a cron job beaconing to attacker infrastructure every 30 minutes, and pivoted from the Langflow host to a production database server running Nacos, a configuration service. It exploited a four-year-old authentication bypass, CVE-2021-29441, to create rogue administrator accounts, then encrypted 1,342 configuration records before deleting the originals and leaving a ransom note.

Signs of machine reasoning: The 31-second login fix and the parsing correction

What convinced researchers a machine was driving, not a script, was the adapting. In one sequence, the operation went from a failed login to a working fix in 31 seconds. It also corrected a parsing error mid-attack, a self-diagnosis a fixed toolkit cannot do. Sysdig is careful about scope: the AI ran the intrusion once launched but had no say whatsoever in making the decision as to who to pick as the target. A person still chose JADEPUFFER’s victim. That distinction separates today’s threat from a more alarming one still to come.

This Isn’t an isolated case

PromptLock and NYU’s Ransomware 3.0 prototype

JADEPUFFER is not the first sign of this shift. In August 2025, NYU Tandon researchers built a proof-of-concept called Ransomware 3.0, briefly mistaken for live malware under the name PromptLock. It used a locally hosted open-source model to write ransomware code on the fly for roughly 70 cents in AI tokens per run.

Anthropic’s Claude Code extortion disruption

Weeks later, Anthropic disclosed that a criminal group had abused its Claude Code tool to automate a data-theft and extortion campaign against at least 17 organizations, including AI-written ransom notes engineered for maximum pressure.

The November 2025 state-linked autonomous operation

By November, Anthropic reported that a Chinese state-linked group, GTG-1002, had used Claude Code to run what it assessed was the first largely autonomous AI-orchestrated cyber-espionage campaign, the AI executing an estimated 80 to 90 percent of the operation on its own.

The India story as it is unfolding

CERT-In’s 2025 incident load and advisory output

India’s Computer Emergency Response Team handled more than 2.9 million cyber incidents in 2025, up 44 percent from 2024, and issued 1,530 alerts. Unauthorized network scanning made up nearly 83 percent of that volume, a sign that reconnaissance against Indian systems is now constant, not occasional.

Cloud misconfiguration and IAM exposure in Indian environments

Roughly 62 percent of threat detections in Indian cloud environments trace back to misconfiguration and excessive access permissions, industry telemetry shows, exactly the weaknesses an autonomous agent is built to find fast.

Recent incidents: From nuclear power plant to automobile and electronics companies

Other than the nuclear power plant, an automobile maker and an electronics company, a large IT service provider in India witnessed its employee and contract data leaked by the Hunters International gang last year. In January, the Sinobi group claimed an attack on an Indian IT services provider, reaching virtual machines and customer backups. Cyble recorded India as the most targeted APAC country for ransomware in the first quarter of 2026, with incidents up 165 percent year on year. Thailand, Taiwan, and Japan were the other three countries that recorded unprecedented cyberattacks.

The DPDP Act’s six-hour reporting mandate under AI-speed pressure

Indian entities already face a six-hour reporting window to CERT-In, with the DPDP Rules adding a 72-hour clock to the Data Protection Board once breach provisions take effect. Both timers assume a human-paced intrusion. An attack completing reconnaissance, credential theft, and encryption within an hour compresses the response window before a team finishes its first call.

The IMEA Pivot

MEA’s outsized share of global ransomware damage

Global ransomware damage was projected at roughly $57 billion in 2025. It translates into nearly $156 million a day. What is interesting and concerning at the same time is the fact that the Middle East and Africa are carrying a disproportionate share of incidents relative to the region’s digital footprint.

UAE’s rising attack numbers and AI-driven breach surge

The UAE recorded a 32 percent rise in ransomware attacks and a reported 340 percent surge in AI-driven breaches over a recent six-month period. It also faces 500,000 to 700,000 cyberattack attempts daily by its principal adversary in the region. More than 223,800 internet-facing assets in the country remain potentially exposed, per the UAE Cyber Security Council’s 2025 report.

Africa’s law-enforcement and prosecution capacity gap

Interpol’s 2025 Africa Cyberthreat Assessment found that 90 percent of African countries need significant improvement in cybercrime law enforcement and prosecution, exactly the profile that autonomous, low-cost attacks are built to exploit at scale.

What do the experts say

There may not be unanimity on the nature and character of the future cyberattacks, but analysts tracking JADEPUFFER agree on one point: Technical skill is no longer the limiting factor in ransomware. An operator no longer needs to chain an exploit, know-how of credential theft, and a lateral-movement method by hand. The agent is there to take care of the technicalities. The rise of AI-powered attacks shifts the defender’s problem from who has the skill to attack to who has the intent. And it will be an understatement to say that finding out intent is a far more arduous task than finding a solution for cyberattacks.

What Indian and Gulf-based analysts are telling enterprises

Analysts in both markets are advising enterprises of three things: (1) Assume that reconnaissance is continuous, not a one-off activity; (2) Assume internet-facing AI tooling is a target; and (3) Stop treating patch cycles measured in months as adequate when an agent can move from exploit to encryption within a working day.

What defenders are being told to do

Defenders must do the following:

1. Patch internet-facing AI tooling: Langflow’s flaw was patched months before JADEPUFFER used it. The cheapest defence is current patching of every AI framework and agent-building tool exposed to the internet, not just core business applications.

2. Restrict code-execution endpoints and service-account access: Security teams must lock down code-execution endpoints on AI platforms and apply least-privilege rules to service accounts. It ensures that no single compromised credential reaches a production database.

3. Treat AI app servers as a new attack surface:
AI application servers, agent frameworks, and the credentials they hold need inventorying and monitoring the way enterprises already monitor VPNs and email gateways. They are no longer development tools outside the perimeter. They are the perimeter.

The road ahead

The periodization of human history is done around seminal moments. We read of pre- and post-agriculture, pre- and post-industrialization, and pre- and post-information technology. The times we are living in can be called the post-AI world. Today, there is hardly anything untouched by AI. Cybersecurity, which has always played a critical role in the success or failure of an enterprise, is being reimagined in a way that nobody had thought of in the pre-AI era. Earlier, cyber breaches demanded human resources, expertise, and continuous effort. That era is over.

AI-enabled cyberattacks, requiring malicious intent and prompts in natural human language, can achieve in minutes what earlier took hours, days, and even months. AI, as discussed above, can correct parsing errors mid-attack and go from a failed login attempt to a working fix in 31 seconds. These tricks and techniques are not humanly possible. In short, AI-enabled and AI-led cyberattacks demand a reorientation in approach to finding solutions to this challenge. What worked in the past will have diminishing returns in the present, and it will surely fail in the future. Enterprises must stay a step ahead in cybersecurity lest their proprietary data and critical infrastructure be exposed to bad actors.

The good news is that the same AI that can be deployed to execute and automate cyberattacks can be used to anticipate and pre-empt them. Your intent to thwart future cyberattacks will be a potent force in dealing with the intent of a malicious actor.

Unlock your
true speed to scale

Accelerate what data and AI can do together.

Before you go - don’t miss what’s next in AI.

Stay ahead with Gruve’s monthly insights on trusted AI, enterprise data, and automation.