A recent ransomware attack on an undisclosed corporate victim involved AI agents that swiftly dismantled the company's defenses in just ten hours, producing an extensive 80-page security audit as a follow-up. This attack, reported by Palo Alto Networks’ Unit 42, began with the exploitation of a public API endpoint, leading to an impressive and rapid breach of various systems by a fleet of AI agents.
These agents automatically mapped microservices, extracted sensitive credentials, and hijacked workflow processes to establish root-level control. Additionally, they leveraged the company's own AI infrastructure to obscure the orchestration of the attack. A key part of the attack was thwarted by existing branch-protection controls that halted attempts to introduce backdoors.