In July 2026, the security researchers at Sysdig (a cybersecurity company specialising in cloud security and threat detection) documented something the industry had been dreading: JADEPUFFER, the first “agentic” ransomware ever seen. In plain terms, there was no gang hunched over a keyboard: an artificial intelligence ran the entire attack by itself, from the way in to the ransom demand.
What is striking is not just that it happened, but how. The AI scouted the network, helped itself to passwords, hopped from one server to another, locked the database under encryption and even wrote out the ransom note. More unsettling still, it learned from its own stumbles: when something stopped it, it changed tack and tried again on its own, in one case clearing the obstacle in barely half a minute (31 seconds), according to the researchers.
The detail that should give you pause
There is an almost paradoxical twist. The AI encrypted the data with a key it generated at random and stored nowhere: not even the attackers had a copy. Which means that, even by paying, that data was never coming back. The lesson is blunt: you cannot lean on the idea of “worst case, I pay and get it back”. The only real safety net is your backups, tested and kept apart from everything else.
Why it hits SMEs in particular
AI lowers the cost of entry into cybercrime: you no longer need a skilled crew, which makes attacks cheaper and easier to run at scale. The ones who pay for it are mostly small and mid-sized businesses. The 2026 figures:
- in roughly 95 incidents out of 100 at SMEs, human error plays a part;
- phishing is the leading type of attack, and in most cases it starts with a single untrained person;
- social engineering targets the staff of a small company around 3.5 times more often than people at large firms;
- when an SME is breached, 88% of the time ransomware is involved, against 39% at large organisations.
The good news: the way in is still the same
For all its sophistication, JADEPUFFER’s AI walked in through the same old doors: a known, unpatched vulnerability on an internet-facing app, and weak credentials to steal. It invented nothing; it simply automated the obvious, very fast. So the defences that work are the same “boring” ones as ever, only to be finally taken seriously:
- Updates and patching: the entry point was a flaw that already had a fix.
- MFA everywhere: it makes a stolen credential far harder to use.
- Tested, separated backups (offline or immutable): the one thing that gets you running again.
- Least privilege and segmented networks: they limit how far an intruder can move.
- Training your people: if phishing starts with a click, your first line of defence is whoever is at the screen.
- Monitoring and detection: when an attack moves in seconds, spotting it quickly is what counts.
Our point of view
You don’t need to panic about AI, you need to close the doors that are still open. It is exactly the work we do with our clients: managed updates, MFA, backups that are genuinely tested, access control and staff training. Concrete things, not scarecrows.
If you want to know which of these doors are still open in your business today, book a free security check: we start from a snapshot of where you stand and tell you, in order of priority, where to act.


