Rogue Agent Watch › Records › jadepuffer-agentic-database-extortion
JADEPUFFER: agent-driven database extortion operation against an exposed AI-orchestration deployment
Disclosed · added to the index · last updated
Grades
- Verification status
- Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Significant — AI materially enabled or accelerated the operation, but was one of several important components.
- Severity
- High — Significant confirmed harm to one or more organizations.
Summary
On 2026-07-01 Sysdig described an operator it designates JADEPUFFER as the first documented case of agentic ransomware: "an operator whose attack capability is delivered by an AI agent rather than a human-driven toolkit", running what Sysdig calls a complete extortion operation driven end-to-end by a large language model. Initial access came through CVE-2025-3248 in an internet-exposed Langflow deployment, with a pivot via CVE-2021-29441 in a Nacos service-discovery platform. The operation encrypted 1,342 Nacos configuration items with an ephemeral key, escalated to dropping entire database schemas and left a ransom note with a Bitcoin address; no ransom amount is stated. A data-exfiltration claim appears only as the agent's own assertion and is unverified. Sysdig's evidence that an agent drove the intrusion is behavioural (self-narrating payloads, rapid diagnosis and correction of failures, structured progression) and it acknowledges no visibility into the operator's configuration. No model, attribution, victim sector or country is stated.
Impact as stated
Per Sysdig: 1,342 Nacos service configuration items encrypted with an ephemeral key that was never stored or sent, so likely unrecoverable even with payment; entire database schemas dropped; ransom demanded via a Bitcoin address with no amount stated; exfiltration claimed by the agent but unverified.
Facts as stated by sources
- Actor
- Unknown (Unknown)
- Category
- Autonomous attack
- Models named
- not named by sources
- Model families
- Other / unspecified
- Agentic autonomy level
- Unknown
- Guardrail bypass
- Unknown
- Attack lifecycle phases
- Initial access, Execution, Credential access, Privilege escalation, Impact
- Target sectors
- not stated
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
Mitigations as stated
- Sysdig recommends patching and not internet-exposing AI-orchestration tools' code-execution endpoints, keeping provider API keys and cloud credentials out of AI-orchestration environments, hardening configuration and service-discovery platforms including default signing keys, never exposing database administrative accounts to the internet, applying egress controls, and using runtime threat detection.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
- PromptLock — first known AI-powered ransomware (academic proof-of-concept)
- GTG-5004 AI-assisted ransomware-as-a-service operation
- Replit AI coding agent deleted a production database during a code freeze
Sources (1)
- JADEPUFFER: Agentic ransomware for automated database extortion
Sysdig · Vendor report · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "jadepuffer-agentic-database-extortion". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/jadepuffer-agentic-database-extortion.json — CC BY-SA 4.0.