The 'first' AI-run ransomware attack still needed a human 12%

By Connie Loizos24%

7/6/2026, 4:56:14 PM

BS Summary: This article contains 27 faulty reasoning types, including Unattributed Quote, Appeal to Authority, and Recency Bias, with Biased Writer Voice as the most egregious example at 13.1% saturation with 87 hits. Analysis detected 1,031 faulty-reasoning hits from 662 analyzed words, generating a BS Score of 29% and a BS Rank of 12% (19,258 of 21,887 articles). This article is better (less manipulative) than 88.00% of the article peer group.

Last week, researchers at cloud security firm Sysdig said they’d documented the first known case of “agentic ransomware.” 
It was an extortion operation, dubbed JadePuffer, in which an AI agent  not a human  handled the technical execution of a real-world cyberattack from start to finish. 
The agent broke into a vulnerable server, stole credentials, moved through the target’s network, encrypted files, and even wrote its own ransom note, adapting to obstacles along the way like a human hacker would. 
Coverage of the funding described it as run “without any human oversight,” with “no human at the keyboard.” 
That’s not quite the *full* picture. 
In an interview on Monday with CyberScoop, Sysdig’s Michael Clark, the company’s senior director of threat research, clarified that a human was still very much involved  just not in the technical execution. 
“A human still set up and pointed the operation and provisioned the infrastructure behind it, the command-and-control server, the staging server used for the stolen data and chose a victim,” Clark said. 
The credentials used to break into the victim’s database, he added, weren’t harvested by the AI agent itself; someone obtained them separately, through a prior compromise, and handed them to the operation. 
None of this contradicts Sysdig’s original claim, and the technical details of the attack remain notable on their own  wild, even. 
The agent got in through a known bug in Langflow, a popular open source tool for building LLM apps, then moved on to a production MySQL server and exploited another known flaw to gain admin access. 
It encrypted over 1,300 configuration records and not only left behind a ransom note that it wrote itself but it left a Bitcoin address where the ransom could be sent. 
Sysdig hasn’t disclosed who was targeted. 
The techniques were fairly ordinary apparently, what stood out was the speed and transparency involved. 
The agent fixed a failed login in 31 seconds, narrating its own reasoning in natural-language code comments the whole way. 
One detail that initially seemed to muddy the picture has since been clarified. 
Clark had told CyberScoop that Sysdig found “multiple models were used in the attack,” citing harvested keys for OpenAI, Anthropic, DeepSeek, and Gemini  language that left open the question of whether several models actively powered different stages of the intrusion. 
Asked to clarify, Clark told TechCrunch that those keys were simply part of what the agent stole, not evidence of what was driving it. 
“The agent swept the Langflow host for anything valuable  provider API keys, cloud credentials, cryptocurrency wallets, and database configs  and those provider keys were part of the loot,” he said via email. 
“They are indicative of what the attacker considered worth taking, but they do not tell us which model was making the decisions.” 
On the model actually running JadePuffer, Clark said Sysdig “was not able to identify the specific model driving the agent” and has no visibility into its system prompt or configuration. 
Microsoft researcher Geoff McDonald’s theory, offered on LinkedIn several days ago, is worth revisiting in that light. 
McDonald suspected an open-weight model with safety training stripped out, rather than a frontier model, was behind the attack, based on his own red-teaming experience showing frontier labs’ safety layers hold up well. 
Sysdig’s own account doesn’t confirm or rule that out. 
McDonald’s post also warned that ransomware campaigns are now bounded primarily by attacker budget rather than human effort, raising the possibility of “thousands or tens of thousands of simultaneous campaigns.” 
That concern is a little harder to square with what Clark described Monday. 
(If a human still has to choose each victim, provision infrastructure, and obtain database credentials for every operation, that’s a bit of a bottleneck, at least.) 
Either way, Clark told CyberScoop, while Sysdig hasn’t seen the same operation hit other victims yet, given how cheap it is to run an agent, he expects that to change. 
Article reasoning-pattern comparisonThis article: 3.3%Connie Loizos: 1.7%TechCrunch: 3.0%Confirmation Bias3.3%This article: 6.2%Connie Loizos: 1.7%TechCrunch: 1.4%Anchoring Bias6.2%This article: 7.3%Connie Loizos: 3.0%TechCrunch: 3.5%Availability Heuristic7.3%This article: 5.1%Connie Loizos: 0.5%TechCrunch: 1.1%Representativeness Heuristic5.1%This article: 0.0%Connie Loizos: 0.3%TechCrunch: 0.6%Hindsight Bias0.0%This article: 8.2%Connie Loizos: 2.4%TechCrunch: 2.5%Overconfidence Bias8.2%This article: 7.1%Connie Loizos: 3.3%TechCrunch: 4.8%Framing Effect7.1%This article: 0.0%Connie Loizos: 0.2%TechCrunch: 0.6%Loss Aversion0.0%This article: 2.0%Connie Loizos: 0.5%TechCrunch: 0.6%Status Quo Bias2.0%This article: 0.0%Connie Loizos: 0.1%TechCrunch: 0.2%Sunk Cost Effect0.0%This article: 9.1%Connie Loizos: 4.7%TechCrunch: 4.9%Optimism Bias9.1%This article: 4.5%Connie Loizos: 0.8%TechCrunch: 1.3%Pessimism Bias4.5%This article: 5.3%Connie Loizos: 2.4%TechCrunch: 5.0%Negativity Bias5.3%This article: 5.0%Connie Loizos: 2.3%TechCrunch: 2.1%Self-Serving Bias5.0%This article: 0.0%Connie Loizos: 0.4%TechCrunch: 0.5%Fundamental Attribution Error0.0%This article: 0.0%Connie Loizos: 0.1%TechCrunch: 0.1%Actor-Observer Bias0.0%This article: 0.0%Connie Loizos: 0.3%TechCrunch: 0.6%In-Group Bias0.0%This article: 0.0%Connie Loizos: 0.1%TechCrunch: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Connie Loizos: 2.5%TechCrunch: 3.5%Halo Effect0.0%This article: 0.0%Connie Loizos: 0.0%TechCrunch: 0.1%Horn Effect0.0%This article: 0.0%Connie Loizos: 0.1%TechCrunch: 0.0%Dunning-Kruger Effect0.0%This article: 9.8%Connie Loizos: 2.2%TechCrunch: 2.3%Recency Bias9.8%This article: 0.9%Connie Loizos: 0.6%TechCrunch: 0.3%Primacy Effect0.9%This article: 0.0%Connie Loizos: 0.1%TechCrunch: 0.1%Blind-Spot Bias0.0%This article: 0.0%Connie Loizos: 0.3%TechCrunch: 0.3%Ad Hominem0.0%This article: 0.0%Connie Loizos: 0.1%TechCrunch: 0.6%Straw Man0.0%This article: 11.2%Connie Loizos: 2.1%TechCrunch: 4.4%Appeal to Authority11.2%This article: 4.4%Connie Loizos: 1.6%TechCrunch: 1.7%False Dilemma4.4%This article: 3.9%Connie Loizos: 0.4%TechCrunch: 0.7%Slippery Slope3.9%This article: 0.0%Connie Loizos: 0.1%TechCrunch: 0.2%Circular Reasoning0.0%This article: 6.8%Connie Loizos: 4.2%TechCrunch: 6.0%Hasty Generalization6.8%This article: 0.0%Connie Loizos: 0.0%TechCrunch: 0.2%Red Herring0.0%This article: 0.0%Connie Loizos: 0.2%TechCrunch: 1.1%Bandwagon0.0%This article: 3.3%Connie Loizos: 1.2%TechCrunch: 2.2%Appeal to Emotion3.3%This article: 6.2%Connie Loizos: 0.6%TechCrunch: 0.6%Begging the Question6.2%This article: 4.5%Connie Loizos: 1.6%TechCrunch: 2.9%Post Hoc (False Cause)4.5%This article: 0.0%Connie Loizos: 0.1%TechCrunch: 0.1%Tu Quoque0.0%This article: 0.0%Connie Loizos: 0.1%TechCrunch: 0.5%Burden of Proof0.0%This article: 0.0%Connie Loizos: 0.1%TechCrunch: 0.2%Appeal to Nature0.0%This article: 0.0%Connie Loizos: 0.3%TechCrunch: 0.3%Composition/Division0.0%This article: 5.0%Connie Loizos: 1.7%TechCrunch: 2.4%Anecdotal5.0%This article: 0.0%Connie Loizos: 0.0%TechCrunch: 0.1%No True Scotsman0.0%This article: 6.2%Connie Loizos: 1.4%TechCrunch: 2.0%Ambiguity (Equivocation)6.2%This article: 0.0%Connie Loizos: 0.0%TechCrunch: 0.0%Gambler’s Fallacy0.0%This article: 1.4%Connie Loizos: 0.2%TechCrunch: 0.2%Middle Ground1.4%This article: 2.0%Connie Loizos: 0.0%TechCrunch: 0.0%Personal Incredulity2.0%This article: 0.0%Connie Loizos: 0.2%TechCrunch: 0.1%Special Pleading0.0%This article: 0.0%Connie Loizos: 0.2%TechCrunch: 0.1%Genetic Fallacy0.0%This article: 11.3%Connie Loizos: 0.5%TechCrunch: 2.0%Unattributed Quote11.3%This article: 2.7%Connie Loizos: 0.5%TechCrunch: 0.7%Quote-first Misdirection2.7%This article: 13.1%Connie Loizos: 3.4%TechCrunch: 4.6%Biased Writer Voice13.1%This article: 0.0%Connie Loizos: 0.2%TechCrunch: 0.8%Indoctrination0.0%This article: 0.0%Connie Loizos: 0.1%TechCrunch: 0.1%Politically Left Leaning Bias0.0%This article: 0.0%Connie Loizos: 0.0%TechCrunch: 0.1%Politically Right Leaning Bias0.0%This article: 0.0%Connie Loizos: 3.5%TechCrunch: 4.9%Attempt to Sell a Product or S…0.0%

662 words analyzed.

Speakers

3speakers56%attributed speech288writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 9 words • 0.0% coverageSysdig • 18 words • 0.0% coverageWriter's voice • 29 words • 100.0% coverageWriter's voice • 34 words • 100.0% coverageWriter's voice • 18 words • 100.0% coverageWriter's voice • 6 words • 100.0% coverageMichael Clark • 33 words • 0.0% coverageMichael Clark • 32 words • 0.0% coverageMichael Clark • 32 words • 0.0% coverageWriter's voice • 22 words • 100.0% coverageWriter's voice • 36 words • 0.0% coverageWriter's voice • 30 words • 0.0% coverageSysdig • 6 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 13 words • 100.0% coverageMichael Clark • 41 words • 100.0% coverageMichael Clark • 24 words • 0.0% coverageMichael Clark • 34 words • 0.0% coverageMichael Clark • 22 words • 0.0% coverageMichael Clark • 30 words • 0.0% coverageWriter's voice • 17 words • 100.0% coverageGeoff McDonald • 33 words • 0.0% coverageSysdig • 9 words • 0.0% coverageGeoff McDonald • 30 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 26 words • 0.0% coverageMichael Clark • 30 words • 0.0% coverage
Selected voice

Geoff McDonald

100%flagged-word coverage
63 attributed words17% of attributed speech70% writer coverage
0%17.5%35.0%Biased Writer Voice-30.2 ptsWriter: 30.2%Geoff McDonald: 0.0%0.0%Unattributed Quote-11.8 ptsWriter: 11.8%Geoff McDonald: 0.0%0.0%Quote-first Misdirection-6.3 ptsWriter: 6.3%Geoff McDonald: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.