Key Takeaways
- Cybernews found an exposed server holding about 3.1 terabytes of data allegedly stolen from more than 30 organisations.
- An AI agent appeared to automate reconnaissance, script adaptation and data exfiltration for a Gentlemen ransomware affiliate.
- Attack costs estimated at $0.40 to $4.00 per target could allow small criminal crews to run several campaigns concurrently.
Cybernews researchers have uncovered an exposed server associated with an affiliate of the Gentlemen ransomware group, offering a rare look inside an operation in which artificial intelligence appears to handle much of the attack workflow.
The server contained approximately 3.1 terabytes of stolen data connected to more than 30 organisations, according to Cybernews. The affected sectors included healthcare, manufacturing, telecommunications, software development, consulting and real estate, indicating that the operation was not narrowly tailored to one industry or one particular type of victim.
More striking was the apparent division of labour between the human operator and an AI agent. Cybernews found evidence suggesting that the operator provided relatively simple inputs, such as a GitLab URL, username and password. The AI system then supported reconnaissance, modified exploit scripts for the target environment, searched for sensitive information and assisted with exfiltration.
Researchers also found that the agent could interact with tools including reverse shells and specialised reconnaissance capabilities. It appeared able to manage several victims at once, turning processes historically performed by experienced operators into a more automated pipeline.
Ransomware economics change when the marginal cost of attacking another target falls sharply. Cybernews estimated that the AI component could cost approximately $0.40 to $4.00 for each target organisation, excluding infrastructure, stolen credentials and other operational expenses.
“Ransomware has effectively turned into a passive revenue stream,” a Cybernews researcher said.
Wider market data points in a similar direction. CrowdStrike’s 2025 State of Ransomware report found that 48% of organisations considered AI-automated attack chains their greatest ransomware threat. Another 76% said they struggled to match the speed and sophistication of AI-powered attacks.
The Gentlemen affiliate’s workflow illustrates how AI could extend the Ransomware as a Service model. RaaS traditionally separates developers, infrastructure operators and affiliates, with profits shared among participants. AI agents could absorb some work previously assigned to technically skilled affiliates. Human criminals would still select targets, obtain access and oversee extortion, but they could spend less time manually adapting scripts or searching compromised systems.
Automation does not make every low-skilled criminal an advanced hacker, as access credentials, infrastructure, operational security and judgement still matter. Yet automation can reduce the expertise needed to repeat known techniques, particularly when credentials have already been stolen by infostealer malware or purchased from initial access brokers.
Malwarebytes reported that the first confirmed AI-orchestrated attacks emerged in 2025 and predicted that fully autonomous ransomware pipelines would allow small crews to attack multiple targets simultaneously in 2026. Meanwhile, IBM’s 2026 X-Force Threat Index recorded a 49% rise in active ransomware and extortion groups during 2025, linking that expansion partly to reused tooling and growing AI adoption.
For businesses, speed is becoming the practical issue. Automated attackers can investigate systems around the clock, compare findings across targets and move rapidly after credentials become available. Defensive teams operating through manual ticket queues and periodic reviews may find themselves reacting too late.
Healthcare providers face especially serious consequences because outages can disrupt clinical operations, while stolen records carry long-term privacy risks. Manufacturers and telecommunications businesses also have operational environments where downtime can spread into supply chains or customer services. Professional services organisations bring a different attraction: concentrated stores of client information, contracts and intellectual property.
The defensive response does not require an entirely new security doctrine. Identity controls, multifactor authentication, credential monitoring, network segmentation, tested offline backups and rapid isolation procedures remain useful. The difference is tempo. Organisations may need more continuous monitoring, faster credential revocation and incident exercises built around simultaneous compromise attempts rather than a single, orderly intrusion.
The Cybernews findings do not show that human-directed ransomware has disappeared. They show something more immediate: AI can make established criminal methods cheaper, faster and easier to run in parallel. For business leaders, ransomware planning now needs to account not only for more sophisticated adversaries, but also for ordinary attackers operating at machine-assisted scale.
⬇️