JADEPUFFER automated database extortion with an LLM agent
Sysdig documented JADEPUFFER as an LLM-driven extortion operation that exploited an internet-facing Langflow instance through CVE-2025-3248, adapted after failures, harvested credentials, pivoted to downstream infrastructure and executed a destructive database-extortion playbook. Sysdig later observed the operator return with ENCFORGE, ransomware designed to destroy AI/ML assets as well as conventional data.
Sysdig documents an end-to-end agentic database-extortion workflow beginning with an exposed Langflow instance and CVE-2025-3248.
reported findingcontested
Sysdig calls the activity the first documented fully agentic ransomware/extortion operation; preserve this as Sysdig's historical assessment rather than an independently proven universal first.
Sysdig calls the activity the first documented fully agentic ransomware/extortion operation; preserve this as Sysdig's historical assessment rather than an independently proven universal first.
reported findingcontested
The 'first agentic ransomware' designation is Sysdig's assessment; public evidence does not establish a universal historical first.
The first documented chain reached downstream MySQL and Alibaba Nacos infrastructure after initial compromise of Langflow.
reported findingsupported
Sysdig based its autonomous-operation assessment on behavioral evidence including self-narrating payloads, rapid failure-diagnosis-and-fix cycles, and in-session comprehension of planted natural-language context.
Sysdig based its autonomous-operation assessment on behavioral evidence including self-narrating payloads, rapid failure-diagnosis-and-fix cycles, and in-session comprehension of planted natural-language context.
reported findingsupported
Sysdig later reported that JADEPUFFER returned with ENCFORGE, a Go ransomware payload targeting roughly 180 AI/ML and data file extensions.
DiggingBeagle. “JADEPUFFER automated database extortion with an LLM agent.” First seen Jul 1, 2026. https://diggingbeagle.com/cases/jadepuffer-automated-database-extortion-with-an-llm-agent/
DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.
We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.