In a report published Wednesday, Unit 42 described what it believes is the first documented ransomware attack conducted entirely by AI agents under human supervision. The attacker used automated agents to perform reconnaissance, breach a public API endpoint to tunnel into the enterprise network, map internal microservices, scrape code repositories for hard-coded tokens and passwords, and steal master administrative credentials from the victim's secret-management system.
Specialist pivot agents validated access across cloud, identity, CI/CD, container and SaaS environments. The attacker also hijacked CI/CD workflows to steal cloud access keys and turned the victim's own cloud AI services into post-compromise infrastructure, consuming compute resources while hiding orchestration traffic among legitimate activity.
Unit 42 noted that the attack did not rely on novel zero-day vulnerabilities or elite tradecraft. “What made the attack stand out was AI-assisted operational efficiency,” the incident responders wrote. “The attacker left tactical execution to AI agents that monitored, evaluated, acted and re-planned in real time, increasing speed throughout the attack chain.”
The security shop did not immediately disclose which models or frameworks the attacker used. Palo Alto Networks says the only viable defence against machine-speed attacks is to deploy AI agents themselves. The company recommends automated playbooks that simultaneously revoke credentials, terminate OAuth sessions, freeze CI/CD pipelines and isolate cloud accounts across all operational planes. It also urges organisations to treat AI as core infrastructure, inventorying every model endpoint, API key, MCP gateway and AI tool integration, and applying rate limits and least-privilege policies — or risk an unexpectedly large token bill.