What the first AI-run ransomware attack means for small business
Why the first AI-orchestrated ransomware campaign changes the cyber threat picture for SMEs.
By Andrew Lai · First published by KBI Media. Republished with permission.
Security researchers at Sysdig have documented something that people in the industry had been predicting for a while and which has now actually happened. A ransomware campaign, tracked under the name JadePuffer, in which an AI agent carried out the entire attack from beginning to end. A person started it off. Everything after that was the machine.
The agent broke in through an internet-facing system with a known vulnerability, mapped the environment it found itself in, hunted down credentials, moved through internal systems, set up persistence so it could not be easily evicted, encrypted production configuration, deleted database tables and delivered the ransom note. Every one of those steps used to require a person who knew what they were doing.
The Skill Barrier Has Collapsed
That last point is the one that matters. Running a full ransomware campaign has historically needed a crew, or at least an operator with genuine expertise across several very different disciplines. Breaking in, escalating privileges, moving sideways without tripping alarms and staging the extortion are separate crafts. The researchers’ conclusion was that an agent can now chain all of it together without the operator holding deep expertise in any single step. The pool of people capable of running an attack like this has widened enormously.
The Phishing Has Caught up as Well
The same shift is happening at the front door. A longitudinal study by the security firm Hoxhunt, run across 70,000 live simulations, found AI-generated spear phishing was 31 per cent less effective than elite human red teams back in 2023. By March 2025 it was 24 per cent more effective. Separately, academic researchers found AI-written phishing emails achieved click-through rates on par with those written by human experts, at roughly 95 per cent lower cost.
Small Business Used to Be Protected by the Maths
Here is why this lands hardest on smaller firms. For years, SMEs were shielded by something nobody likes to say out loud, which is that they were not worth the effort. A skilled attacker running a tailored campaign had every reason to aim at a large target with a large payout. When the cost of a convincing, tailored attack falls by something like 95 per cent, and the skill needed to follow it through falls with it, that protection quietly disappears. Attacks that were previously uneconomic against a suburban accounting practice become perfectly viable. Small businesses already absorb a disproportionate share of incidents, and a single one costs around $46,000 on average according to the Australian Cyber Security Centre.
The Way in Was Still a Known Vulnerability
The reassuring part of the JadePuffer story is easy to miss. For all the sophistication of what came afterwards, the agent got its initial foothold through an internet-facing system running a vulnerability that already had a published fix available. The clever part was everything that followed entry. Entry itself was ordinary, and preventable.
There is a detail in that worth sitting with. The exposed system the agent walked through was Langflow, a tool businesses use to build AI applications. An AI tool, stood up and left facing the internet with the patch not applied, was the door into the entire thing.
The Basics Still Do the Heavy Lifting
Which is why the advice has not changed, even though the threat has. Patch anything exposed to the internet, and do it quickly. Turn on multi-factor authentication. Keep backups that are genuinely separated from your main systems, and test that they actually restore, because this playbook was destruction rather than simple encryption. Limit who can reach what. Have a short written plan for the day something goes wrong. None of that is exciting and all of it works.
Add one more item to that list. Write down every AI tool your business has stood up, particularly anything with a web interface, and check whether it is exposed and patched. These get spun up quickly and forgotten just as fast.
Defenders Get the Same Tools
It would be a mistake to read this as a story about AI leaving everyone helpless. The same capability that lets an agent chain together an attack lets a defender watch for unusual behaviour, find weaknesses earlier and respond faster than a small team could manage alone. The Five Eyes cyber agencies made exactly this point in their joint warning this year, urging organisations to use AI deliberately to strengthen defence rather than only to save time.
While historically the AI adoption focus has been on automating manual tasks and improving productivity, the focus now needs to shift to automated AI cybersecurity hardening. I expect a wave of automated agent-driven attacks before long, and the businesses that have not prepared are running out of time to start.