AIPolicyTracker

AI incident ·

LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

4 news reports Snapshot 7 Sep 2026

In brief

An AI system built by Large Language Model Developers and Ai Agent System Developers and deployed by Ransomware Operators, Jadepuffer and 2 others allegedly harmed Operators Of Langflow Deployments and Database Operators.

Risk domain
Not classified
Occurred
Coverage
4 reportsJul 2026

What happened

Sysdig reported that a ransomware operator it dubbed JADEPUFFER used an LLM-driven agent to turn access through a vulnerable internet-facing Langflow deployment into a database-extortion operation. The report said the activity reached a production database server and produced concrete disruption, with the victim environment allegedly left in a damaged and unrecoverable state alongside a ransom demand.

Laws that address this harm

No recorded instrument yet addresses this use case where it happened. See the open queue.

Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).

News reports (4)

Titles link to the original publisher; report text is not reproduced here.

  1. Researchers Claim First Fully Agentic Ransomware: JadePuffer
    infosecurity-magazine.com · Phil Muncaster

Who was involved

Alleged harmed party
Operators Of Langflow Deployments, Database Operators

Classification (MIT AI Risk Repository taxonomy)

Risk domain
—
Risk subdomain
—
Causal entity
—
Intent
—
Timing
—
Harm level
—
Sectors
—
Countries
—

Source record: incident #1578 on the AI Incident Database · all 4 reports