← Back

Wire · ai

Exposed Server Reveals Automated Extortion Pipeline

Published

11 September 2026

Topic

ai

Sectors

CybersecurityAI Agents

Geography

Russia

Source

Read at idm.net.au

Verified

Fusion42 · 11 September 2026 · Fusion42 review

An exposed server linked to a Russian-speaking ransomware group automated extortion using an AI agent to compromise around 30 companies, exfiltrate 3.1TB of data, and calculate ransom demands at low token costs. The AI-powered campaign targeted vulnerable GitLab instances, leveraging known but unpatched vulnerabilities, and shifted ransomware activity to data theft extortion without file encryption.

This Wire brief sits within Fusion42's coverage of Cybersecurity and AI Agents.

◆ The Wire takeaway

You face a new normal where AI scripts automate ransomware playbooks end-to-end and evade detection by adapting exploits live. Lock down GitLab and similar developer platforms now or risk becoming a low-cost target for extortion built on AI automation.

Coverage

1 source · 11 Sep 2026

Related on Wire

Topics

CybersecurityAI Agentsransomwareai-automationgitlabdata-extortioncybersecurityvulnerabilities