Wire · ai
Exposed Server Reveals Automated Extortion Pipeline
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 11 September 2026 · Fusion42 review
An exposed server linked to a Russian-speaking ransomware group automated extortion using an AI agent to compromise around 30 companies, exfiltrate 3.1TB of data, and calculate ransom demands at low token costs. The AI-powered campaign targeted vulnerable GitLab instances, leveraging known but unpatched vulnerabilities, and shifted ransomware activity to data theft extortion without file encryption.
This Wire brief sits within Fusion42's coverage of Cybersecurity and AI Agents.
◆ ◆ The Wire takeaway
You face a new normal where AI scripts automate ransomware playbooks end-to-end and evade detection by adapting exploits live. Lock down GitLab and similar developer platforms now or risk becoming a low-cost target for extortion built on AI automation.
◆ Coverage
1 source · 11 Sep 2026
◆ Related on Wire
◆ Topics