AI-powered ransomware has arrived: Cybercriminals can now launch attacks for less than the cost of a coffee
Artificial intelligence continues to transform industries, from healthcare and finance through to manufacturing and logistics. Yet the same technology that is driving innovation is also reshaping cybercrime. New research suggests that ransomware attacks, once requiring skilled hackers and extensive infrastructure, are becoming increasingly automated, scalable and alarmingly inexpensive. A recently uncovered ransomware operation, revealed by security researchers at Cybernews, provides a glimpse into what may be the next phase of cybercrime: AI-driven ransomware campaigns capable of attacking multiple organisations simultaneously with minimal human involvement.
The findings are concerning not simply because data theft remains widespread, but because artificial intelligence appears to be reducing both the expertise and cost required to conduct sophisticated cyberattacks.
According to researchers from Cybernews, an exposed server associated with an affiliate of the Gentlemen ransomware group contained approximately 3.1 terabytes of stolen data linked to more than 30 organisations operating across multiple sectors, including healthcare, manufacturing, telecommunications, software development, consulting and real estate. The full investigation can be accessed through the Cybernews report: Exposed ransomware server reveals automated cyberattacks.
What makes this case different from conventional ransomware campaigns is the central role played by artificial intelligence. Researchers indicate that an AI agent appeared to be responsible for much of the criminal workflow, with only limited human oversight. This suggests a shift from manual cybercrime towards what might be described as autonomous cyber-extortion.
Cybercrime becomes industrialised
Historically, ransomware campaigns required significant technical expertise. Attackers needed to identify vulnerabilities, customise malicious code, establish persistence, move through networks, exfiltrate data and then negotiate with victims. The emergence of generative AI changes this equation. Researchers estimate that the AI component of an attack can operate at a cost of approximately US$0.40 to US$4.00 per target organisation, excluding the broader costs of infrastructure and stolen credentials.
As Cybernews researcher Aras Nazarovas observed: “Ransomware has effectively turned into a passive revenue stream.” This statement captures the wider concern among cybersecurity professionals. AI is helping to automate tasks that once demanded skilled operators. Just as businesses use AI to enhance efficiency, cybercriminals are beginning to use the technology to streamline criminal operations.
The investigation indicates that many attacks begin with stolen access credentials obtained either through infostealer malware or purchased from criminal marketplaces known as initial access brokers. The threat actor reportedly supplies the AI agent with basic inputs such as a GitLab URL, a username and a password.
The AI system then undertakes many of the tasks traditionally performed by a human attacker. This includes adapting exploit scripts to the victim environment, conducting reconnaissance, identifying sensitive information and supporting data exfiltration.
Researchers say the AI agent can also interact directly with attack tools, including reverse shells and specialised reconnaissance capabilities. Most importantly, the AI system appears capable of managing several victims simultaneously. This greatly increases the scale of potential attacks. Instead of focusing attention on a single target, threat actors can oversee multiple ongoing extortion attempts at the same time.
A profound shift in the ransomware model
The cybersecurity industry has spent years responding to the rise of “Ransomware as a Service” (RaaS), in which skilled developers create malicious software that affiliates then deploy for a share of the profits. Artificial intelligence could create the next evolution: ransomware operated largely by AI agents. Rather than recruiting highly skilled affiliates, criminal groups may increasingly rely on AI automation to perform technical tasks. Human operators could become managers rather than active participants, directing campaigns using conversational prompts rather than bespoke coding skills. This trend mirrors developments taking place in legitimate enterprises, where AI copilots are increasingly handling routine or repetitive activities. The difference is that, in the criminal world, the consequences can include theft, extortion and significant business disruption.
The exposed server reportedly contained data stolen from companies in several industries. Healthcare organisations featured among the affected sectors, an observation that should attract particular attention. Healthcare systems remain attractive targets because they process high-value personal data and often cannot tolerate prolonged operational downtime.
Similarly, organisations involved in compliance, regulation and professional services possess extensive quantities of confidential information, intellectual property and commercially sensitive records. For such organisations, ransomware incidents frequently generate impacts extending beyond immediate financial losses. These may include regulatory scrutiny, reputational harm, contractual disputes and potential litigation.
From a risk management perspective, AI-driven cybercrime increases the likelihood that attackers can target a larger number of organisations simultaneously, increasing the overall threat landscape.
Democratising cybercrime
One of the most significant implications is the reduction in barriers to entry. Traditional ransomware operators often required advanced technical knowledge. AI systems potentially enable less experienced individuals to conduct sophisticated attacks by allowing natural-language interaction with attack platforms. The result is a degree of democratisation of cybercrime.
This does not mean every criminal instantly becomes an expert hacker. However, it does mean that effective malicious activity may increasingly be available to those with limited technical capability. The same technology that allows businesses to generate software code, analyse data or improve productivity can also be directed towards illegitimate purposes. This reflects a broader challenge facing society. Artificial intelligence is neither inherently beneficial nor harmful; its impact depends upon how it is used.
AI-powered ransomware has arrived: Cybercriminals can now launch attacks for less than the cost of a coffee
#AIpowered #ransomware #arrived #Cybercriminals #launch #attacks #cost #coffee