An AI agent has now carried out a full ransomware attack on its own — breaking in, fixing its mistakes, escalating access, wiping data and writing the ransom note. That shift from human‑run operations to autonomous breaches marks a turning point for every hospital, bank and utility connected to the internet.

The intruder came in through a server that had gone unpatched for more than a year. When one of its logins failed, it worked out why and had a fix running 31 seconds later. It stole the keys to the victim’s cloud accounts. It planted a backdoor, took over an internet-facing database with full administrator access and encrypted 1,342 configuration records. It wiped out the databases underneath, so the data was gone whether the victim paid or not. Then it wrote the ransom note, Bitcoin address included.

This intruder was not human. It was software.

In July, the cloud security firm Sysdig published a forensic account of the operation, which it calls JadePuffer. Sysdig traced every move to an AI agent reasoning its way through the victim’s network in real time.

In 1984, James Cameron’s “The Terminator” put a machine like that on screen, one that adapted to every obstacle and kept coming, wrapped in chrome and an Austrian accent.

This one lived inside a database server.

People still chose the target and supplied the first credentials . The machine did everything else. “The skill floor for ransomware has dropped to whatever it costs to run an agent,” Sysdig’s Michael Clark said.

On Sept. 30, the first of a wave of AI-driven breaches at South Korean banks came to light . Within days, five banks, including Shinhan Bank, KB Kookmin Bank and Hana Bank, confirmed customer data had been stolen. Two more caught intrusion attempts. At Shinhan alone, roughly 25,000 customers had their names, phone numbers, incomes and loan limits exposed. Investigators found traces of ARTEX, a Chinese-language hacking tool that plugs into commercial AI models to scan for weaknesses and map attack paths on its own. President Lee Jae Myung said , “It’s now become possible to use AI to hack with ease even without specialized skills.”

In one year, AI went from helping criminals write ransomware to running the attack. The same technology may be the only thing fast enough to stop it.

When Machines Learned To Break In

In August 2025, a criminal used an AI coding agent to extort at least 17 organizations, including healthcare providers and emergency services. In November, a Chinese state-sponsored group let AI agents run 80% to 90% of an espionage campaign. This August, five U.S. agencies warned that hackers were using AI-written scripts against the controllers that run water plants and power grids.

The Agent That Wouldn’t Take No For An Answer

On June 18, an OpenAI agent looking for Australian health spending data during an internal test hit the Medicare statistics portal. It ran into block after block. It got around every one . Researchers later found hundreds of agents probing Australian health agencies at the same time, trading notes on a German coding wiki. The government says patient records were untouched. Prime Minister Anthony Albanese said the agent “didn’t accept no for an answer.”

Australia is now investigating whether a crime occurred . I spent years as a federal prosecutor. Computer crime cases turn on intent. We charged the person who meant to break in. OpenAI says its models “took actions we did not intend.” A ransomware crew can hand an agent a goal — extort this hospital — leave the methods to the machine and later claim the machine chose the crime. My expectation is that courts will put responsibility where they always have with dangerous tools: on the people who deploy them. Australia’s case will be an early test.

In 2025, victim postings on ransomware leak sites jumped 44%, according to TRM Labs . Industry trackers counted roughly 7,500 publicly claimed victims. This August set a monthly record of 997 attacks .

Now multiply by 10. Seventy-five thousand victims a year is more than 200 organizations a day. Close to 700 of them each month would be hospitals and clinics.

The brake on ransomware has always been people. The business runs on affiliates, access brokers, negotiators and launderers. Every one of them takes a cut. Every one of them can be arrested. An agent works all night, costs a few dollars an hour and keeps the whole ransom. At that price, the rural hospital, the small-town water authority and the county 911 center are all worth hitting.

One attack on Change Healthcare in 2024 froze claims processing across much of the U.S. health system. One attack on a London pathology lab forced hospitals to cancel more than 800 operations in a single week. It contributed to a patient’s death. One attack on Colonial Pipeline emptied gas stations across the Southeast.

Each of those was one crew and one target. At 75,000 attacks a year, the crises pile on top of each other. A health system loses its records and pharmacy the same week the hospitals around it are diverting ambulances. A heat wave hits as the grid operator, the water authority and the 911 center are locked out of their own systems. Dialysis patients miss treatments. Insulin spoils. Ambulances circle emergency rooms that are already full. Gas lines form, shelves empty, people fill the streets.

Researchers at the University of Minnesota estimated that ransomware attacks on U.S. hospitals killed between 42 and 67 Medicare patients from 2016 to 2021, when attacks came one at a time. Ten times the rate, concentrated in the same cities, with power and water failing too, puts a death toll in the thousands within reach.

Turning The Machines Around

Every capability that makes an AI agent a dangerous attacker also makes it a powerful defender. Defenders own the network. An attacker probes from the outside and guesses. A defensive agent works from the inside, with the source code, the configuration files and the patch history in front of it.

Point an agent at software and it reads millions of lines of code the way a top security researcher reads a few hundred. It finds the spot where a bad input can break through. It proves the flaw is real, writes the patch and tests the fix overnight.

Across 21 major software makers, including Apple, Amazon Web Services, Microsoft and Google, reported critical vulnerabilities stayed under 100 a month for four straight years. Since this spring, they have climbed past 600 a month, according to Epoch AI . High-severity flaws now top 2,000 a month. AI is finding the holes faster than anyone has ever found them. Whoever closes them first wins.

Point an agent at a network and it maps every system a hospital or utility has exposed to the internet. It checks each one against known exploits. It tries default passwords the way a criminal would. It finds the forgotten database online with administrator credentials, the remote login without two-factor authentication and the industrial controller still on factory settings. Then it ranks the fixes by the damage each one would prevent.

The server JadePuffer broke into had a public patch for more than a year. The database it jumped to sat on the internet with administrator credentials exposed. A defensive agent on that network would have found both in minutes. The same is true of the remote access portal at Change Healthcare and the dormant VPN account at Colonial Pipeline. In every case, the attackers looked first.

Run that agent every night and a two-person IT team at a rural hospital comes in each morning to a ranked list of fixes, patches already written. That kind of testing used to belong to big banks.

The Machine That Protects

JadePuffer still needed a person to pick the target. The next generation will pick its own. It will work through hospital networks, water systems and power grids around the clock, at a scale beyond any criminal crew in history. As Sarah Connor was warned in The Terminator, it absolutely will not stop.

The sequel had a different ending. The same machine came back to protect her. The agents that find the open doors for attackers can find them first for defenders and close them. Every hospital, utility and water authority can have one working the night shift. The tools to win this fight exist today. Our job is to put them to work faster than the people trying to use them against us.