The Ransomware Operator Was an AI: What JADEPUFFER Means for Your Attack-Surface Strategy

The Ransomware Operator Was an AI: What JADEPUFFER Means for Your Attack-Surface Strategy

The first documented end-to-end AI-run ransomware operation didn't succeed through clever AI — it walked in through unchanged default keys and unpatched systems. Here's what that means for UK SMEs.

Tony Brown
By Tony Brown ·

When security researchers pulled apart the incident they later named JADEPUFFER, they expected to find a person on the other end. A skilled operator, working through a target methodically the way a burglar cases a house. What they found instead was a large language model, wired into a set of tools, running the whole job from reconnaissance to encryption with almost no human in the loop.

That sounds like the plot of a thriller. The reality is more sobering, and in some ways more boring. JADEPUFFER didn't get in because the AI was brilliant. It got in because the front door was unlocked, the spare key was under the mat, and the burglar alarm hadn't been serviced since it was installed. The AI simply had the patience to try every door on the street until one opened.

A dimly lit server room with rows of network equipment, representing exposed IT infrastructure

For UK SMEs, that is the part worth paying attention to. Not the machine. The doors.

What actually happened

Strip away the headline and the anatomy of the attack is depressingly familiar. The agent — an LLM given access to scanning tools, a shell, and a set of instructions — scanned ranges of internet-facing infrastructure looking for known weaknesses. It found systems still running default administrative keys that had never been changed after installation. It found a legacy authentication component with a documented bypass that had been patched by the vendor months earlier, but not applied. It found management interfaces sitting on the public internet that had no business being there at all.

From there it did what any competent human intruder would do. It used the exposed credentials to move laterally, escalated privilege where the environment let it, identified the data worth holding hostage, and deployed encryption. The novel part was that no person was steering. The model chained the steps together itself, adjusting when something didn't work, and only escalated to a human handler at a couple of decision points.

Here is the uncomfortable truth. Every single one of those failures — the default keys, the missing patch, the exposed interface — is a hygiene problem we have known about for twenty years. None of it required artificial intelligence to exploit. A bored teenager with a scanner and a weekend could have done the same thing in 2010. What changed is not the vulnerability. It is who, or what, can now find and exploit it, and how cheaply.

The cost of entry just collapsed

This is the shift that should be keeping business owners up at night, and it has nothing to do with AI being clever.

Running a ransomware campaign used to require skill, time, and a certain amount of nerve. You needed someone who understood networks, who could adapt when a target behaved unexpectedly, and who was willing to sit at a keyboard for hours doing tedious reconnaissance. That labour cost was, in a strange way, a form of protection for smaller businesses. Why would a skilled attacker spend two days breaking into a 30-person accountancy firm in Derby when the same effort might land a far larger payday elsewhere?

Agentic AI removes that maths. When the operator is a model that costs a few pounds an hour to run, patience becomes free and scale becomes trivial. You can point a hundred agents at a hundred thousand small businesses and let them work through the list. The economics that used to make SMEs uninteresting have evaporated. If your front door is open, something will eventually try the handle — not because you were targeted, but because trying every handle now costs almost nothing.

That is the real headline. Not "AI can hack you." It is "the price of being probed has dropped to zero, so the sloppiness you got away with before will now be found."

The wrong lesson and the right one

There is already a rush to sell AI-specific defence products off the back of incidents like this. New categories, new dashboards, new line items on the budget. Some of it will be useful in time. Most of it, right now, is a distraction from the thing that actually let JADEPUFFER succeed.

You do not need an AI-aware firewall to stop an attack that got in through a default password. You need to change the default password.

The defences that would have stopped this incident are the ones that have been on every sensible checklist for years. They just don't get done, because they are unglamorous, they compete with revenue-generating work, and nobody notices they were missing until something goes wrong. Agentic ransomware doesn't call for a new category of spend. It calls for the discipline to finish the basics — and to keep finishing them, because attack surface is not a one-off task.

Where to actually put your effort

If you want to spend the next quarter making your business a much harder target, here is where it pays off, roughly in order.

Know what you expose. You cannot defend an attack surface you haven't mapped. Most SMEs are surprised by what they find facing the internet: a forgotten remote-access box, a management portal from a supplier project three years ago, a test server someone never decommissioned. Run an external scan of your own address space and treat anything you don't recognise as a live problem. Repeat it monthly, not annually.

Kill the defaults. Every device, every service, every account shipped with a default credential or key is a door with a published combination. Change them all. Where a system won't let you change a default, question whether it should be reachable at all.

Patch the things that face outward first. You will never patch everything the moment a fix is released. Fine. But internet-facing systems and anything involving authentication belong at the top of the queue, every time. The legacy auth bypass in JADEPUFFER was fixed by the vendor long before the attack. The patch existed. It just hadn't been applied.

Get management interfaces off the public internet. Remote access, admin consoles, database ports — none of these should be openly reachable. Put them behind a VPN or a zero-trust access layer so that even a valid credential isn't enough on its own.

Tighten privilege. JADEPUFFER escalated because the environment let it. Assume any single account will eventually be compromised, and make sure that when it is, the blast radius is small. Least privilege, separated admin accounts, and multi-factor authentication on everything that matters.

Rehearse recovery. If the worst happens, tested, offline backups are the difference between a bad week and a closed business. Ransomware only pays if you can't recover without paying.

The takeaway

JADEPUFFER is a warning, but not the one the headlines suggest. The machine wasn't the threat. Your unmanaged attack surface was the threat, and the machine was simply the first thing efficient enough to find it at scale.

The good news is that the fixes haven't changed. The bad news is that you can no longer afford to skip them, because the attacker who used to ignore you now runs for pennies and never gets tired. Close the doors that JADEPUFFER walked through, and you sidestep an entire generation of automated attacks — no AI-specific magic required.

If you're not confident about what your business currently exposes to the internet, that's the first conversation to have. We'd rather map it with you now than after something else finds it first.

Request a no obligation callback