Skip to content
The Cyber Security Place

The ransom note was written by a model, and so was everything before it

Event dated 9 July 2026 · Published 2 September 2026 · 3 sources

Researchers described JadePuffer, a ransomware operation driven by a language model across the full sequence: exploiting a Langflow vulnerability, stealing credentials, reaching a production database, encrypting data and generating the ransom note. Reporting through July also placed AI at more stages of the lifecycle, from reconnaissance to negotiation. No individual step is new — each has appeared in incidents for years. What is new sits at the end: the entity an organisation bargains with may have no person behind each message, which changes what the bargaining can be expected to do.

The instinct on reading this is to ask whether the attack is more dangerous. Mostly it is not, in the sense that matters: the chain used a known vulnerability, took credentials, moved to a database and encrypted it. Every one of those steps is ordinary and every defence against them is unchanged.

The part that is genuinely different is the last one, and it is the part that gets the least attention because it is not technical.

What negotiation assumed

Every piece of advice about ransom negotiation rests on the other side being a person with interests. They want to be paid, they would rather not spend three weeks on a difficult victim, they can be persuaded that a smaller sum now beats a larger one never, and they have a reputation they may want to protect.

Those assumptions are what make delay useful, what make partial offers worth trying, and what make a responder's experience valuable. They describe a counterparty who gets bored, calculates, and occasionally makes mistakes.

What changes when it is automated

Patience becomes free. A system does not tire, does not have other victims competing for its attention this week, and does not accept a lower figure because the conversation has become tedious. Whatever position it was configured to hold, it holds.

It also means the messages can be consistent, fluent, and adapted to the victim's own language and sector without the tells that have historically helped responders judge who they were dealing with. The heuristics built up over a decade — phrasing, timing, negotiating style — were reading a human, and there may be no human to read.

What it does not change

Everything before the note. The Langflow vulnerability was a vulnerability, the stolen credentials were stolen the usual way, and the database was reachable because it was reachable. An operation of this kind still needs a way in, and the ways in are the ones this site has been describing all year.

Which is the practical conclusion, and it is deliberately unexciting. The interesting part of the story is at the end of the chain, and the part that decides whether the chain happens at all is at the beginning — where nothing about it is new.