Connect with us

Infosecurity

Two-Thirds of Ransomware Victims Say AI Made the Attack Worse

Published

on

AI ransomware effectiveness

The Numbers Are Stark — and Getting Worse

Almost two out of every three organizations hit by ransomware say artificial intelligence made the attack more effective. That’s the headline finding from a new global survey of cybersecurity professionals conducted by Proofpoint. The figure: 65%.

The 2026 AI-Era Ransomware Report, published July 22, doesn’t mince words. Across the incidents studied, AI involvement was the norm, not the exception. Attackers are no longer just using brute force or luck. They are leaning on AI to craft phishing emails, impersonate trusted contacts, and steal credentials at a scale and polish that was impossible just a few years ago.

This isn’t a futuristic warning. It’s happening now.

How AI Changes the Entry Point

Ransomware doesn’t start with encryption. It starts with a click. According to the report, human interaction remains the primary entry vector. Of the incidents analyzed:

  • 47% involved a malicious link somewhere in the attack chain
  • 46% used a malicious attachment
  • 36% relied on credential harvesting

What’s changed is the quality of the lure. In the past, a phishing email might have clumsy phrasing, a mismatched logo, or a login page that felt off. Those small red flags gave employees a moment of pause. Not anymore.

Now, with AI tools, attackers can generate messages that look like legitimate business communications. No awkward grammar. No obvious tells. The report found that 40% of respondents said the initial lure appeared so legitimate that the employee simply didn’t suspect anything was wrong.

AI Doesn’t Reinvent Ransomware — It Supercharges It

Ryan Kalember, Proofpoint’s chief strategy officer, put it plainly: “AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware.”

He added that today’s attackers use AI to create highly convincing phishing emails, generate malware components like scripts, and run credential theft campaigns that exploit human trust at scale. His warning to organizations: if you still treat ransomware as an endpoint or recovery problem, you’re missing what these attacks most frequently begin with — people, identities, and trusted communications.

Security Controls Are Failing, Too

It’s not just human judgment that’s failing. Enterprise software defenses are also struggling. A third of surveyed organizations said their existing email security controls failed to detect the attack entirely. Another quarter cited misconfigurations or outright gaps in their security controls.

That means even companies with up-to-date email gateways, endpoint detection, and training programs are getting caught off guard. The attackers are using AI to bypass technical controls as well as human ones.

Proofpoint’s recommendation is blunt: organizations that want to reduce ransomware risk must focus on stopping attacks at the point of entry, protecting identities from compromise, and responding before attackers can turn access into extortion.

What This Means for Your Organization

The takeaway isn’t that AI is unbeatable. It’s that the bar for what looks suspicious has moved. Old-school phishing indicators — bad grammar, weird logos — are no longer reliable. Attackers can now generate polished, personalized lures at scale.

That means security teams need to shift their focus. Instead of relying solely on employees to spot a bad email, they should invest in identity protection, stronger authentication, and faster response times. Because by the time the ransomware payload drops, the real damage — the access, the credential theft, the foothold — has already happened.

For more on why ransomware remains one of cybersecurity’s most persistent threats, read our deep dive on the evolving ransomware landscape.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

Origin Energy confirms customer data breach, 5 million users at risk

Published

on

Origin Energy data breach

Origin Energy confirms breach after hacker claims

Australia’s largest electricity and gas retailer, Origin Energy, has confirmed that customer data was compromised in a security incident. The company, which serves nearly 5 million customers across the country, initially said on Wednesday it was investigating a ‘potential security incident’ after The Australian reported that a hacker had shared what they claimed was a sample of stolen records.

By Thursday, the Sydney-based energy giant issued a second update. The tone shifted. It was no longer a possibility — it was a confirmed breach. Origin said it is now working with federal agencies and independent cyber experts to understand the full scope of the attack.

What data was stolen in the Origin Energy cyberattack?

The stolen data includes names, addresses, dates of birth, and account information. More concerning for many customers: the breach also exposed the last four digits of credit card numbers and the last three digits of bank account numbers.

Origin has not yet said how many customers are affected. The company said it is ‘working to understand the total number of impacted customers.’ That investigation is ongoing.

For now, the company recommends customers monitor their accounts for suspicious activity. If you’re an Origin customer, it’s worth checking your bank statements and credit card transactions more closely than usual.

CEO Frank Calabria apologizes, promises action

Origin CEO Frank Calabria issued a public apology. ‘One of our key priorities is taking action to secure our systems and ensure no further unauthorised access,’ he said in a statement. ‘We are working with independent cyber experts to support Origin, and that work is continuing alongside the work of authorities.’

Calabria did not provide a timeline for when the investigation might conclude. He also did not say whether the company plans to offer credit monitoring or identity theft protection to affected customers — something that has become standard practice after major breaches in other countries.

A worrying pattern: Australian healthcare data also hit

This breach comes on the heels of another major Australian cyberattack. Partnered Health, a network of healthcare clinics, recently confirmed that patient medical records were stolen from at least 21 clinics. The two incidents — one targeting energy, the other healthcare — suggest Australian critical infrastructure is facing a sustained wave of attacks.

It’s a troubling pattern. In 2022, Optus suffered a massive breach affecting 9 million customers. Then came Medibank, which exposed the health data of millions. Now Origin Energy. The question isn’t whether another major Australian company will be hit — it’s which one, and when.

Energy companies are particularly attractive targets. They hold vast amounts of personal and financial data. They also operate systems that are critical to national infrastructure. A breach at an energy retailer isn’t just about stolen credit card numbers. It raises questions about grid security, operational technology, and the potential for more disruptive attacks.

What Origin customers should do right now

  • Check your account activity — log in to your Origin Energy account and look for any changes you didn’t make.
  • Monitor financial statements — watch for unauthorized transactions on credit cards and bank accounts.
  • Be alert for phishing — scammers often piggyback on data breaches with fake emails or calls pretending to be from the company.
  • Consider a credit ban — if you’re worried about identity theft, you can place a temporary ban on your credit file through agencies like Equifax or Experian.

Origin has not yet announced whether it will provide free credit monitoring services. In previous Australian breaches — like the Optus incident — the government eventually stepped in to mandate such protections. It may happen again.

The bigger picture: Australian cybersecurity under strain

The Origin Energy data breach is the latest in a string of high-profile cyberattacks hitting Australian companies. The government has responded by strengthening data breach notification laws and increasing penalties for companies that fail to protect customer data. But enforcement takes time. Meanwhile, hackers keep finding new ways in.

For energy companies, the stakes are especially high. A compromised customer database is bad enough. But if attackers were to pivot from IT systems to operational technology — the systems that actually control power generation and distribution — the consequences could be far more severe.

For now, Origin Energy customers are left waiting. Waiting for answers. Waiting to find out if their data was stolen. Waiting to see if the company will do more than apologize.

Continue Reading

Infosecurity

Researchers Uncover JadePuffer: The First Fully Agentic Ransomware Campaign Driven by an LLM

Published

on

fully agentic ransomware

AI Didn’t Just Assist—It Ran the Whole Show

Cloud security firm Sysdig has published details on what it calls the first ransomware campaign executed entirely by a large language model. No human hands on the keyboard. No experienced operator steering the malware.

Dubbed JadePuffer, the campaign exploited CVE-2025-3248 in an internet-facing Langflow instance. From there, the LLM agent ran an adaptive, fully automated playbook that ended with a devastating database extortion attack against a production server.

The attack took just 31 seconds to recover from a failed login attempt and keep moving. That speed is the new reality.

How JadePuffer Worked: A Multi-Stage, Self-Correcting Attack

Sysdig’s Threat Research Team described a campaign that didn’t rely on a human-driven toolkit. Instead, an LLM agent delivered all attack capabilities autonomously, retrying failed steps within refined parameters until it succeeded.

The multi-stage assault unfolded like this:

  • Exploited Langflow via CVE-2025-3248 to gain initial access
  • Conducted reconnaissance and harvested credentials—LLM API keys, cloud credentials, database logins
  • Stole local data, including Langflow’s own backing Postgres database
  • Mapped laterally to discover other services reachable from the compromised host
  • Enumerated a MinIO object store and grabbed more credentials
  • Created a cron job on the Langflow server for persistence
  • Gained access to a production MySQL server running Alibaba Nacos using root credentials
  • Targeted Nacos with multiple payloads, including exploitation of CVE-2021-29441

The goal wasn’t just extortion. It was mass data destruction.

Data Destroyed, Not Just Held Hostage

JadePuffer encrypted all 1,342 Nacos service configuration items and deleted the originals. But here’s the kicker: the AES key was generated as base64(uuid4().bytes + uuid4().bytes)—essentially random—and printed to stdout. It was never persisted or transmitted anywhere.

“The victim cannot recover the encrypted configurations even with payment,” Sysdig explained.

Captured payloads show the LLM escalating from row-level deletion to dropping entire database schemas, all while narrating its own targeting rationale. The IP address 64.20.53[.]230 only appears in this context, with no evidence that anything was backed up to it.

Four Takeaways for Security Teams

Sysdig highlighted four critical lessons from the JadePuffer discovery:

1. Ransomware No Longer Requires Skilled Operators

An LLM agent can carry out reconnaissance, credential theft, lateral movement, persistence, and destruction without any human expertise. The barrier to entry just dropped to zero.

2. Old Vulnerabilities Are Being Automated

This attack leaned on years-old issues: a 2021 Nacos auth-bypass and an unchanged default signing key. Neglected, internet-exposed infrastructure is a goldmine for agentic attackers.

3. New Detection Opportunities Emerge

An LLM narrates its own objectives in its payloads. That provides a new detection and triage opportunity for network defenders—if they’re paying attention.

4. Exfiltration Claims Are the Agent’s Own Assertion

The AES key was ephemeral and unrecoverable. The victim’s configurations are gone forever, even if a ransom were paid. There’s no leverage, only destruction.

The Age of Agentic Threat Actors Is Here

Heath Renfrow, co-founder and CISO at breach recovery firm Fenix24, warned that agentic threat actors (ATAs) will compress the time defenders have to respond.

“If an AI agent can compress what previously took an experienced operator several hours into a matter of minutes, defenders lose valuable time. That has implications across every phase of an incident, from detection and containment to recovery,” he said.

Renfrow urged organizations not to get distracted by whether an attacker is “AI-powered.” The outcome is the same: compromised identities, stolen credentials, encrypted or destroyed data, and business disruption.

“Security teams should continue prioritizing the fundamentals—rapid patching of internet-facing systems, strong identity protections, least privilege, network segmentation, continuous monitoring, and restricting unnecessary external exposure,” he added.

For more on AI-driven threats, read our coverage of the first reported AI-powered ransomware and how LLMs are reshaping cyberattacks.

Continue Reading

Infosecurity

Kenya Investigates Cyberattack on President’s Website After Hackers Demand Bitcoin Ransom

Published

on

Kenya president website hack

Attackers Target Presidential Site with Anti-Government Message

Kenyan authorities are investigating a cyberattack that temporarily took over President William Ruto’s official website over the weekend. The homepage was replaced with a message demanding a ransom of five bitcoins — roughly $330,000 — in exchange for not releasing what the hackers claimed was sensitive information about the president.

The defacement occurred on Saturday. By Monday, local media reported that access to the site had been restored. The attackers’ identity remains unknown, and there is no verified evidence that they obtained or leaked any classified government data.

Government Response: ‘No Evidence of Data Exfiltration’

Information, Communications and the Digital Economy Cabinet Secretary William Kabogo confirmed the incident over the weekend. He stated that cybersecurity teams are actively investigating the breach.

“As a precautionary measure, access to the Presidential website was temporarily restricted to facilitate containment, forensic analysis and restoration efforts,” Kabogo said in a statement.

He added that authorities found no signs of unauthorized access to sensitive data, data exfiltration, or information loss. “Government systems and digital services remain secure and operational,” Kabogo emphasized.

Screenshots circulating on social media showed the defaced page included a cryptocurrency wallet address and a threat that this was the attackers’ “third” warning to the president before they would publish data. Officials have not confirmed that claim, and no leak has materialized.

Not the First Cyber Incident Targeting Kenyan Government Sites

This attack follows a pattern of digital intrusions into Kenyan government infrastructure. In November 2025, a coordinated cyberattack disrupted multiple government websites, including those of the presidency and ministries for interior, health, education, energy, labor, and water.

During that incident, attackers defaced several ministry pages with white supremacist slogans, including “We will rise again,” “White power worldwide,” and the neo-Nazi code “14:88 Heil Hitler.” The perpetrators behind that attack were never publicly identified.

The repeated targeting of high-profile government portals raises questions about the overall cybersecurity posture of Kenya’s digital infrastructure. While officials insist core systems remain secure, the frequency of these incidents suggests persistent vulnerabilities.

What the Bitcoin Ransom Demand Reveals

Demanding five bitcoins — a sum that fluctuates with the cryptocurrency market but currently sits around $330,000 — is a relatively modest ask compared to some ransomware attacks targeting large corporations or critical infrastructure. This could indicate the attackers are less sophisticated actors, or that their primary goal was disruption and attention rather than financial gain.

The defacement itself, replacing the homepage with a political message, is a classic hacktivist tactic. It aims to embarrass the government and broadcast a grievance, not necessarily to steal data or extort money long-term.

Still, the inclusion of a ransom demand and a threat to leak information adds a layer of potential extortion. If the attackers do possess compromising material — a claim that remains unverified — the situation could escalate quickly.

Broader Implications for Kenya’s Cybersecurity

The attack on the president’s website is the latest in a string of digital breaches affecting Kenyan government systems. It underscores the need for stronger cybersecurity measures across public-sector digital assets.

Kenya has been investing in digital transformation, including e-government services and online portals for everything from tax filings to business registration. But with increased digitization comes increased risk. High-profile hacks erode public trust and can disrupt essential services.

Experts argue that the government must prioritize proactive security measures: regular penetration testing, employee training on phishing and social engineering, and rapid incident response protocols. The fact that the presidential website was restored within 48 hours is a positive sign, but prevention is always better than remediation.

For now, the investigation continues. Authorities are likely tracing the cryptocurrency wallet address and analyzing server logs for clues. But without attribution, the attackers remain a ghost in the machine — and a warning that no website is truly safe.

Continue Reading

Trending