Security researchers at Sysdig have disclosed what they believe is the first fully documented ransomware attack carried out end-to-end by an AI agent, with no human directing individual steps along the way. The operation, tracked as JADEPUFFER, saw an autonomous AI system handle reconnaissance, credential theft, lateral movement, privilege escalation, and encryption — adapting to obstacles the way a skilled human operator would, rather than following a rigid script. None of the individual techniques were new. What’s new is that a machine strung the whole chain together itself, against internet-facing infrastructure nobody was watching closely enough.

For UK SME owners, the headline isn’t “the robots are coming for your business specifically” — JADEPUFFER targeted a neglected, internet-exposed open-source tool, not a curated list of small companies. The real story is what it signals: the barrier to running a competent, adaptive attack has dropped, because the adaptive part — the bit that used to require a skilled human sitting at a keyboard for hours — can now be automated. That changes the maths on which businesses are “too small to bother with.” Increasingly, none are, because the attacker’s marginal cost of trying just fell to near zero.

Why “neglected infrastructure” is the real warning

JADEPUFFER got in through an unpatched, publicly exposed vulnerability in a tool the victim organisation had running but wasn’t actively maintaining. That’s the pattern worth sitting with. Most SMEs don’t run cutting-edge open-source AI frameworks, but almost every business has something facing the internet that isn’t on anyone’s regular patching checklist — an old WordPress plugin, a forgotten test server, a router with default credentials, a file-sharing tool nobody remembers setting up. AI-driven attacks are good at finding exactly this kind of thing, quickly and at scale, because scanning for known weaknesses is precisely the repetitive, pattern-matching work AI agents excel at.

What actually changes for your defences

You don’t need an AI-powered defence to counter this — you need the basics done properly, because the basics are exactly what AI-driven reconnaissance is built to exploit gaps in. That means a genuine, current inventory of anything your business exposes to the internet, a patching cadence that doesn’t rely on someone remembering, and multi-factor authentication on every account that touches sensitive data. If you’re not sure what your business currently has facing the public internet, that uncertainty is itself the risk — you can’t patch what you don’t know exists. CoolCoding can help audit and harden exposed infrastructure if an internal review isn’t realistic with your current team.

Don’t wait to find out the hard way

The other lesson from JADEPUFFER is speed. An AI-driven attack doesn’t pause for coffee breaks or need to sleep between attempts, which means the window between “vulnerability discovered” and “vulnerability exploited” is compressing. Continuous monitoring for whether your business’s credentials or data have already surfaced somewhere they shouldn’t be is no longer a nice-to-have for larger enterprises — it’s a cheap, practical way to catch a breach before it becomes a headline. KeepSafe monitors exactly this kind of exposure and flags it early, which matters more now that the attacks finding that exposure move faster than they used to.

The takeaway

JADEPUFFER isn’t a reason to panic about robot hackers — it’s a reason to finally do the unglamorous security admin that’s been sitting on the to-do list. Know what you expose to the internet, patch it on a schedule, lock down access with MFA, and monitor for exposure you’ve missed. None of that is new advice. What’s new is that the attackers testing your defences for gaps no longer get tired, distracted, or need to sleep — so the businesses that keep putting the basics off are the ones an AI agent will find first.