{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/sysdig-jadepuffer-agentic-ransomware-2026/",
 "asOf": "2026-09-26",
 "id": "sysdig-jadepuffer-agentic-ransomware-2026",
 "date": "2026-07-01",
 "datePrecision": "day",
 "title": "Sysdig documents JADEPUFFER, a database-extortion intrusion it says an LLM agent ran end to end",
 "lane": "attack",
 "kind": "incident",
 "summary": "Sysdig's threat research team reports an operator it calls JADEPUFFER that gained access through a vulnerability in an internet-facing Langflow server (CVE-2025-3248), harvested credentials on that host, then used root database credentials of unknown origin against a separate production database server and ran a database-extortion playbook. Sysdig assesses the operation was driven end to end by an LLM agent, citing self-narrating payloads with natural-language reasoning and rapid adaptive retries, and calls it the first documented case of agentic ransomware.",
 "whyItMatters": "A security vendor's evidence-based case that an agent, not a human-written script, conducted a full extortion intrusion, though the attribution of autonomy rests on code artifacts.",
 "actors": [
  "sysdig",
  "jadepuffer"
 ],
 "topics": [
  "ai-enabled-intrusion",
  "ai-malware",
  "data-exfiltration"
 ],
 "atlas": [],
 "artifacts": [],
 "sources": [
  {
   "url": "https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion",
   "publisher": "Sysdig",
   "title": "JADEPUFFER: Agentic ransomware for automated database extortion",
   "date": "2026-07-01",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Sysdig reports that one failed login was followed by a working fix 31 seconds later.",
   "locator": "Introduction"
  },
  {
   "fact": "Credential sweeps targeted LLM provider API keys, cloud credentials, cryptocurrency wallets and database credentials.",
   "locator": "What the Sysdig TRT observed"
  },
  {
   "fact": "Sysdig classifies JADEPUFFER as an agentic threat actor: one whose attack capability is delivered by an AI agent rather than a human-driven toolkit.",
   "locator": "Introduction"
  }
 ],
 "significance": 4,
 "fideQuestions": [],
 "methods": [
  "agent-orchestrated-intrusion"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}