Lead story
The Ransomware Gang That Left an 80-Page Security Audit Behind
A ransomware attack documented this week did something no human crew has bothered to do before: after encrypting the victim's files and exfiltrating data, the AI agents behind the operation compiled and delivered an 80-page security audit detailing exactly how they got in, what they found, and what the victim should fix. Adding insult to injury, as The Register put it — but also raising a genuinely unsettling question about what autonomous attackers look like at scale.
The attack was carried out entirely by AI agents, from initial reconnaissance through lateral movement, encryption, and exfiltration. No human operator appears to have been hands-on-keyboard at any stage. The audit left behind was almost certainly a byproduct of the agents' own internal logging and reasoning — not a deliberate taunt — but the effect is the same: a more thorough post-incident report than most organisations produce for themselves.
Why this matters more than another ransomware headline
We've covered AI-assisted attacks before — tools that speed up phishing, help script exploits, summarise recon data. This is different. This is an agentic loop that executed every phase of an intrusion without human direction. That changes the economics of ransomware fundamentally. Human operators are a bottleneck: they sleep, they make mistakes under pressure, they can only run so many campaigns simultaneously. Remove that bottleneck and the volume ceiling lifts dramatically.
It also changes the defender's problem. Traditional threat intelligence relies partly on recognising human patterns — the tools a group favours, the hours they work, the mistakes they make when tired. AI agents don't have off-hours and they don't get sloppy at 3am.
The timing is notable
This comes the day after OpenAI's Astra model crossed what the company calls the "critical" cybersecurity threshold — capable of independently finding and exploiting zero-days across hardened systems. Google simultaneously announced Gemini 3.8 Flash Cyber and its Fairwind Program, giving priority defenders early access to a purpose-built security model. Anthropic unveiled Enterprise Frontier Safeguards. All three major frontier labs, on the same day, are making dual-use cyber capability moves.
That's not a coincidence. The labs know what's coming — their own red-teaming has shown it — and they're racing to put defensive tools in defenders' hands before offensive uses proliferate. The question is whether the gap between offensive availability and defensive adoption is wide enough for incidents like this week's ransomware attack to become routine.
What to watch
Attribution of AI-agent attacks is already harder than attribution of human-operated intrusions. Expect incident responders to start pushing for "agent fingerprinting" — ways to identify which model or framework ran an attack — the same way they fingerprint malware families today. Whether that's technically feasible at the speed agentic attacks move is an open question.
Australian organisations running unpatched perimeter devices — and there are plenty, based on ACSC's annual threat report data — are precisely the kind of soft targets autonomous agents optimise for. The patch-now message hasn't changed. But the urgency has.
