In the newsletter I told you researchers caught the first ransomware attack run almost entirely by a machine. Here is exactly how it worked, the detail that should get every owner’s attention, and why the boring basics just became the whole ballgame.
See Where Your Business Stands → — a plain A-to-F grade on your Windows PCs. No card needed to see it.
The problem: Ransomware used to need a skilled human at the keyboard, patient, and paid. Researchers just documented AI ransomware that did the whole job on its own: broke in, looked around, stole the passwords it found, worked deeper, and locked up the data. A person pointed it at the target. The machine did the rest.
The straight answer: Do not panic and do not run from robots. This attack did not break down a genius wall. It walked through an unlocked door that had a fix available for over a year. The lesson is the same one it has always been, only the stakes just went up, because the thing checking your forgotten corners never sleeps now. Let me show you how it worked and what actually stops it.
In this article
Hey folks! Every so often a story crosses my desk that marks a before and an after. This is one of them, so let me walk you through it in plain English.
Security researchers at a firm called Sysdig documented the first case they have ever seen of a ransomware attack run, almost from start to finish, by an AI. They named it JadePuffer. And I want to be precise about what “AI ransomware” means here, because the phrase gets thrown around loosely and this is the real thing.
A human did one part: pointed the software at a target and said go. From there the machine ran the playbook a skilled criminal would normally run by hand. It broke in. It looked around the network to learn the layout. It found stored passwords and grabbed them. It used those to work its way deeper into systems it should never have reached. Then it locked up the data and held it for ransom. The whole chain, the part that used to take a trained crook days of careful work, ran on its own.
For years, plenty of us in this field said the day was coming when the attacker would not need much skill, just a tool. Sysdig just put a name and a date on that day. And JadePuffer is not the ceiling. It is the clumsy first version. They always get better.
One detail from the researchers is the thing I cannot stop thinking about, and it is the part that separates this from every piece of automated junk that came before it.
A dumb script quits when it fails. Old automated attacks were brittle. They tried one thing, and if it did not work, they moved on or fell over. That brittleness was quietly protecting you, because most attacks that hit your door were the equivalent of a burglar rattling one handle and wandering off.
JadePuffer adjusted. When one of its login attempts failed, it did not give up. It reasoned about why, changed its approach, and tried again. In one case, the researchers watched it go from a failed login to a working way in inside 31 seconds. That is not a burglar rattling a handle. That is a burglar who tries the door, then the windows, then the back, learning as he goes, without ever getting tired or bored.
Now multiply that by every business at once. A skilled human criminal is one person who has to pick their targets. This does not pick. It works every door, on every address it can reach, at the same time, at machine speed. That is the shift. The patience that used to be rare and expensive is now free and infinite.
Here is the piece that ought to reframe the whole thing for you. That 43 percent jump in ransomware victims over the past year is not a run of bad luck. It is what happens the moment patience stops being the attacker’s bottleneck. When it took skill and time, the crooks aimed at the biggest paydays and left the rest alone. When it takes neither, they hit everyone. Small businesses are not slipping through a smaller net now. There is no small net. There is a machine trying every door.
Here is the twist that changes what you should actually do, and it is the opposite of what the scary headline pushes you toward. This machine did not defeat some brilliant defense. It got in through a flaw in a common piece of software that had a fix available for over a year, sitting on a system nobody had bothered to update. Read that again. The first AI-run ransomware attack succeeded because of a missing patch, the most boring failure in all of security.
So the lesson is not “buy a fancy AI shield to fight the AI attacker.” The lesson is the one I have been saying for years, and it just got teeth. The forgotten, unpatched corner of your business used to be a slow risk, the kind you could get away with ignoring for a good long while because no human was likely to come poke at it. That grace period is over. There is now a tireless machine out there checking every one of those corners, all the time, and it only has to get lucky once.
The opinion I will stake my name on is this: in the age of AI ransomware, the businesses that get hurt will not be the ones without the newest tool. They will be the ones who left the basics undone, the patch nobody applied, the account nobody turned off, the backup nobody tested, because they figured the odds were on their side. The odds just changed sides. The basics you have been putting off are not the boring part anymore. They are the whole ballgame.
And that is precisely why watching cannot be a once-in-a-while thing. A machine that never sleeps is not answered by a person who checks in quarterly. It is answered by someone who is actually watching the doors around the clock and closes them the moment one drifts open.
None of this is exotic. It is the boring stuff, which is exactly the point, because the boring stuff is what the machine is counting on you to skip.
1. Find your oldest, most-ignored system and update it.
Every business has one. The server in the closet, the app the office cannot work without, the remote-access setup someone configured years ago. That is where the machine gets in. Name it, find out when it was last patched, and get it current this week. If you are not sure what you even have exposed, that is answer enough on its own.
2. Turn on two-step login and test a real backup.
JadePuffer stole stored passwords and used them to move deeper. Two-step login on email, banking, and remote access blunts exactly that. And a backup you have actually restored from, kept disconnected so ransomware cannot reach it, is the difference between a bad week and a closed business. A backup you have never tested is a hope, not a plan.
3. See the open doors before the machine does.
Run a Reveal scan on your Windows computers. It grades each one A to F and lists the open doors in plain English, the same forgotten corners a tool like JadePuffer goes hunting for. It is the first step most of the businesses I now manage took before they signed on.
My father fell for a phishing email. I have spent my whole career in this, and it still reached him. Scammers got remote access to his computer and went hunting for his financial papers. My step-mother noticed something was off, called me, and I stopped them before they reached the spreadsheet with all his bank credentials. We were lucky. We caught it in time. If the only thing standing guard had been a tireless machine on the other side and nobody on ours, he would have been cleaned out.
That is why I built Forward to Safety around people who actually watch, backed by good technology. More than 35 years at this, since 1991. FBI InfraGard trainer. Not one client I manage has ever been hit by ransomware, because when an automated attacker comes knocking at 3 a.m., someone real is awake and watching the door.
You need the basics done right first, and this attack is the proof. JadePuffer, the scariest thing in the field this month, got in through a year-old missing patch, not through some defense that only another AI could have stopped. No amount of fancy tooling saves a business that leaves the front door unlocked.
Good technology helps, and we use it. But the thing that actually stopped every ransomware attack aimed at the clients I manage was not a smarter box. It was a real person watching the doors and closing them fast. The machine never sleeps. Your answer to it cannot be a tool nobody is minding.
Answer these honestly, just to yourself. There is a system in your business you have been meaning to get to, isn’t there? You already know the boring basics matter more than any shiny tool, because you just read how the scariest attack of the month walked through a missing patch. And “we will get to it” felt safe back when nothing was out there hunting around the clock. It is not that safe now, and part of you knows it.
That flicker of discomfort is not me trying to scare you, and it is not a character flaw. It is the honest distance between how seriously you take your business and one corner of it nobody has checked. You get to decide how that tension ends. Bury it, and it comes back every time one of these stories crosses your desk. Or spend fifteen minutes with us, close the corner, and set it down for good. Doing something about it is the only version that actually lets you stop carrying it.
Here is the honest version of what we do. There is a tireless machine out there trying every door on every business it can reach. Our answer is simple and it works: real people watching your doors around the clock, closing the forgotten corners before anything can walk through.
We find the open doors, we patch and harden them, and then we keep watch and step in the moment something moves. You hand off the worry and get back to running your business.
Not one client we manage has ever been hit by ransomware. In the age of a machine that works every door at once, that track record is the whole point.
Let’s grab fifteen minutes and find the one open door most likely to hurt you, and exactly how to close it. No pitch, no obligation.
Book My 15-Minute Game Plan → — fifteen minutes with a real person, straight talk on where your business stands.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
#AIRansomware #JadePuffer #SmallBusinessSecurity #Patching #ForwardToSafety
Join thousands of security professionals who receive Craig Peterson's Insider Show Notes and cybersecurity updates.
Join 10,000+ cybersecurity professionals