Rogue Agent Watch › Records › jadepuffer-agentic-database-extortion

JADEPUFFER: agent-driven database extortion operation against an exposed AI-orchestration deployment

Disclosed · added to the index · last updated

Grades

Verification status
Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Significant — AI materially enabled or accelerated the operation, but was one of several important components.
Severity
High — Significant confirmed harm to one or more organizations.

Summary

On 2026-07-01 Sysdig described an operator it designates JADEPUFFER as the first documented case of agentic ransomware: "an operator whose attack capability is delivered by an AI agent rather than a human-driven toolkit", running what Sysdig calls a complete extortion operation driven end-to-end by a large language model. Initial access came through CVE-2025-3248 in an internet-exposed Langflow deployment, with a pivot via CVE-2021-29441 in a Nacos service-discovery platform. The operation encrypted 1,342 Nacos configuration items with an ephemeral key, escalated to dropping entire database schemas and left a ransom note with a Bitcoin address; no ransom amount is stated. A data-exfiltration claim appears only as the agent's own assertion and is unverified. Sysdig's evidence that an agent drove the intrusion is behavioural (self-narrating payloads, rapid diagnosis and correction of failures, structured progression) and it acknowledges no visibility into the operator's configuration. No model, attribution, victim sector or country is stated.

Impact as stated

Per Sysdig: 1,342 Nacos service configuration items encrypted with an ephemeral key that was never stored or sent, so likely unrecoverable even with payment; entire database schemas dropped; ransom demanded via a Bitcoin address with no amount stated; exfiltration claimed by the agent but unverified.

Facts as stated by sources

Actor
Unknown (Unknown)
Category
Autonomous attack
Models named
not named by sources
Model families
Other / unspecified
Agentic autonomy level
Unknown
Guardrail bypass
Unknown
Attack lifecycle phases
Initial access, Execution, Credential access, Privilege escalation, Impact
Target sectors
not stated
Target countries
not stated
Organisations affected
not stated
Records exfiltrated
not stated

Framework mappings

CVE
CVE-2025-3248, CVE-2021-29441

Mitigations as stated

  • Sysdig recommends patching and not internet-exposing AI-orchestration tools' code-execution endpoints, keeping provider API keys and cloud credentials out of AI-orchestration environments, hardening configuration and service-discovery platforms including default signing keys, never exposing database administrative accounts to the internet, applying egress controls, and using runtime threat detection.

Map

No cited source states a location; this record is listed beside the map, never plotted.

Related records

Sources (1)

  1. JADEPUFFER: Agentic ransomware for automated database extortion
    Sysdig · Vendor report · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "jadepuffer-agentic-database-extortion". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/jadepuffer-agentic-database-extortion.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction