AI Ran Its First Solo Ransomware Attack in 30 Minutes Flat | UnHacked Ep. 102

Hosts:
Justin Shelley - https://www.phoenixitadvisors.com/
Mario Zaki - https://www.mazteck.com/
Joshua Holloway - https://7thdi.com/

AI didn't go rogue and hack a company on its own. Someone pointed a jailbroken AI at an unpatched server, and it finished a full ransomware attack in about 30 minutes.

Security researchers at Sysdig just documented the first fully autonomous, AI-driven ransomware attack, nicknamed "Jade Puffer." No human touched a keyboard once it started. It broke in, mapped the network, rewrote its own code to dodge detection, and deployed ransomware, start to finish, faster than most security teams could even get an alert out. Experts are now saying the response window for an attack like this has shrunk from hours to as little as 15 minutes.

Justin Shelley, Mario Zaki, and Joshua Holloway break down what actually happened, and why the scary headline ("AI attacks company, no humans involved") is only half the story. The real vulnerability wasn't AI. It was a production MySQL server exposed to the internet, running unpatched software with a known critical flaw, and a default signing key that hadn't been changed since 2020. The AI didn't discover some brand-new weakness. It exploited the same lazy, preventable gaps that have caused breaches for a decade, just a lot faster.

Josh also shares a live horror story about an MSP that disabled a client's VPN and locked them out of their own data over a single unpaid invoice, in the middle of an unrelated legal dispute, then demanded tens of thousands of dollars before restoring access. It's a hard look at what happens when a business has no idea what their IT provider is actually doing for them, and no leverage when things go sideways.

What you'll learn:
  • How the first fully autonomous AI ransomware attack worked, from breach to payload in under 30 minutes
  • Why the vulnerability that let it happen was public knowledge for over a year, and completely preventable with basic patching
  • Why publishing CVEs (known vulnerabilities) helps defenders more than it helps attackers
  • Why the AI-generated ransomware couldn't have paid off even if the victim tried, because the encryption key was never stored anywhere
  • Red flags that your MSP isn't doing what you're paying them for, and what to do if one tries to hold your data hostage
New episodes of UnHacked drop every week with real talk on cybersecurity, AI, and the tech risks actually hitting small business owners. Subscribe so the next one doesn't catch you off guard.

Not sure if your IT company is actually protecting you or just collecting a check? Phoenix IT Advisors helps small and mid-sized businesses find out, patch what's exposed, and build security that doesn't rely on luck. Visit PhoenixITAdvisors.com to schedule a consult.

Links:

Full episode: https://unhackmybusiness.com/episode/102
Phoenix IT Advisors: https://phoenixitadvisors.com
More UnHacked: @UnHackedPodcast

Creators and Guests

Bryan Lachapelle
Host
Bryan Lachapelle
Hi, I’m Bryan, and I’m the President of B4 Networks. I started working with technology since early childhood, and routinely took apart computers as early as age 13. I received my education in Computer Engineering Technology from Niagara College. Starting B4 Networks was always a dream for me, and this dream became true in 2004. I originally started B4 Networks to service the residential market but found that my true passion was in the commercial and industrial sectors where I could truly utilize my experience as a Network Administrator for a large Toronto based Marine Shipping company. My passion today is to ensure that each and every client receives top of the line services. My first love is for my wonderful family. I also enjoy the outdoors, camping, and helping others. I’m an active Canadian Forces Officer working with the 613 Fonthill Army Cadets as a member of their training staff.
Mario Zaki
Host
Mario Zaki
During my career, I have advised clients on effective – and cost-effective – approaches to developing infrastructure that fosters productivity and profitability. My work has provided me with a broad-based knowledge of business from the inside, with an expertise in areas that go beyond IT alone, ranging from strategic planning to cloud computing to workflow automation solutions.
AI Ran Its First Solo Ransomware Attack in 30 Minutes Flat | UnHacked Ep. 102
Broadcast by