Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up

Incident 1578: LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

Description: Sysdig reported that a ransomware operator it dubbed JADEPUFFER used an LLM-driven agent to turn access through a vulnerable internet-facing Langflow deployment into a database-extortion operation. The report said the activity reached a production database server and produced concrete disruption, with the victim environment allegedly left in a damaged and unrecoverable state alongside a ransom demand.

Tools

New ReportNew ResponseDiscoverView History
The OECD AI Incidents and Hazards Monitor (AIM) automatically collects and classifies AI-related incidents and hazards in real time from reputable news sources worldwide.
 

Entities

View all entities
Alleged: Large language model developers and AI agent system developers developed an AI system deployed by Ransomware operators , JADEPUFFER , Cybercriminals and Agentic threat actors, which harmed Operators of Langflow deployments and Database operators.
Alleged implicated AI systems: Ransomware , Production database servers , Nacos configuration service , MySQL databases , Large language models , Langflow , AI agent systems and Agentic ransomware

Incident Stats

Incident ID
1578
Report Count
4
Incident Date
2026-07-01
Editors
Daniel Atherton

Incident Reports

Reports Timeline

+1
JADEPUFFER: Agentic ransomware for automated database extortion
+1
JadePuffer: The First Complete LLM-Driven Ransomware Attack
JADEPUFFER: 6 Things to Know About the First AI-Driven Ransomware Operation
Loading...
JADEPUFFER: Agentic ransomware for automated database extortion

JADEPUFFER: Agentic ransomware for automated database extortion

sysdig.com

Loading...
JadePuffer: The First Complete LLM-Driven Ransomware Attack

JadePuffer: The First Complete LLM-Driven Ransomware Attack

darkreading.com

Loading...
Researchers Claim First Fully Agentic Ransomware: JadePuffer

Researchers Claim First Fully Agentic Ransomware: JadePuffer

infosecurity-magazine.com

Loading...
JADEPUFFER: 6 Things to Know About the First AI-Driven Ransomware Operation

JADEPUFFER: 6 Things to Know About the First AI-Driven Ransomware Operation

cybelangel.com

Loading...
JADEPUFFER: Agentic ransomware for automated database extortion
sysdig.com · 2026

Ransomware has had a human at the keyboard, or at least a human writing its script, since it was first established as a category of threat. The Sysdig Threat Research Team (TRT) has captured what we assess to be the first documented case of…

Loading...
JadePuffer: The First Complete LLM-Driven Ransomware Attack
darkreading.com · 2026

The first documented case of an end-to-end ransomware operation executed autonomously by a large language model (LLM) has successfully performed extortion without a human operator, ushering in a new era in cyberattacks that has long been ex…

Loading...
Researchers Claim First Fully Agentic Ransomware: JadePuffer
infosecurity-magazine.com · 2026

Cloud security firm Sysdig has released details on what it claims to be the world's first ransomware campaign completely driven by a large language model (LLM).

Dubbed JadePuffer, the campaign targeted an internet-facing Langflow instance b…

Loading...
JADEPUFFER: 6 Things to Know About the First AI-Driven Ransomware Operation
cybelangel.com · 2026

On July 1, 2026, researchers at Sysdig's Threat Research Team published evidence of what they assess to be the first ransomware operation conducted end-to-end by a large language model. The operator, which Sysdig named JADEPUFFER, breached …

Variants

A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?

Similar Incidents

Selected by our editors

Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Jul 2026 · 1 report
By textual similarity

Did our AI mess up? Flag the unrelated incidents

Loading...
All Image Captions Produced are Violent

All Image Captions Produced are Violent

Apr 2018 · 26 reports
Loading...
The DAO Hack

The DAO Hack

Jun 2016 · 24 reports
Loading...
Game AI System Produces Imbalanced Game

Game AI System Produces Imbalanced Game

Jun 2016 · 11 reports
Previous IncidentNext Incident

Similar Incidents

Selected by our editors

Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Jul 2026 · 1 report
By textual similarity

Did our AI mess up? Flag the unrelated incidents

Loading...
All Image Captions Produced are Violent

All Image Captions Produced are Violent

Apr 2018 · 26 reports
Loading...
The DAO Hack

The DAO Hack

Jun 2016 · 24 reports
Loading...
Game AI System Produces Imbalanced Game

Game AI System Produces Imbalanced Game

Jun 2016 · 11 reports

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • 3e68a9f