Case · DiggingBeagle record

JADEPUFFER automated database extortion with an LLM agent

Sysdig documented JADEPUFFER as an LLM-driven extortion operation that exploited an internet-facing Langflow instance through CVE-2025-3248, adapted after failures, harvested credentials, pivoted to downstream infrastructure and executed a destructive database-extortion playbook. Sysdig later observed the operator return with ENCFORGE, ransomware designed to destroy AI/ML assets as well as conventional data.

First seen
Jul 1, 2026
Case kind
incident
AI role
BY AI
Claims
6

Reconstruction

Claims & evidence

reported findingsupported

Sysdig documents an end-to-end agentic database-extortion workflow beginning with an exposed Langflow instance and CVE-2025-3248.

  • supports
    Sysdig - JADEPUFFER agentic ransomware

    Locator: SRC-SYSDIG-JADEPUFFER-JUL01

    Sysdig documents an end-to-end agentic database-extortion workflow beginning with an exposed Langflow instance and CVE-2025-3248.
reported findingcontested

Sysdig calls the activity the first documented fully agentic ransomware/extortion operation; preserve this as Sysdig's historical assessment rather than an independently proven universal first.

  • supports
    Sysdig - JADEPUFFER agentic ransomware

    Locator: SRC-SYSDIG-JADEPUFFER-JUL01

    Sysdig calls the activity the first documented fully agentic ransomware/extortion operation; preserve this as Sysdig's historical assessment rather than an independently proven universal first.
reported findingcontested

The 'first agentic ransomware' designation is Sysdig's assessment; public evidence does not establish a universal historical first.

  • supports
    Sysdig - JADEPUFFER agentic ransomware

    Locator: SRC-SYSDIG-JADEPUFFER-JUL01

    The 'first agentic ransomware' designation is Sysdig's assessment; public evidence does not establish a universal historical first.
reported findingsupported

The first documented chain reached downstream MySQL and Alibaba Nacos infrastructure after initial compromise of Langflow.

  • supports
    Sysdig - JADEPUFFER agentic ransomware

    Locator: SRC-SYSDIG-JADEPUFFER-JUL01

    The first documented chain reached downstream MySQL and Alibaba Nacos infrastructure after initial compromise of Langflow.
reported findingsupported

Sysdig based its autonomous-operation assessment on behavioral evidence including self-narrating payloads, rapid failure-diagnosis-and-fix cycles, and in-session comprehension of planted natural-language context.

  • supports
    Sysdig - JADEPUFFER agentic ransomware

    Locator: SRC-SYSDIG-JADEPUFFER-JUL01

    Sysdig based its autonomous-operation assessment on behavioral evidence including self-narrating payloads, rapid failure-diagnosis-and-fix cycles, and in-session comprehension of planted natural-language context.
reported findingsupported

Sysdig later reported that JADEPUFFER returned with ENCFORGE, a Go ransomware payload targeting roughly 180 AI/ML and data file extensions.

Implications

What remains unknown

  • Victim identity and realized financial loss were not publicly established in the primary reporting.
  • The underlying LLM/model identity was not publicly established.

Cite this record

DiggingBeagle. “JADEPUFFER automated database extortion with an LLM agent.” First seen Jul 1, 2026. https://diggingbeagle.com/cases/jadepuffer-automated-database-extortion-with-an-llm-agent/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.