Ransomware gangs are going after VPNs, and an AI just ran its own attack

Ransomware attacks rose for the fourth month in a row in June, with criminals targeting the devices companies use to connect remote workers. A new AI-driven attack completed an entire break-in with no human at the keyboard.

ThreatVectr Newsdesk· 3 min read
Full-frame edge-to-edge photoreal editorial shot of a darkened server room corridor with a single rack door ajar, cool blue emergency lighting spilling across p
Share

Key points

  • Ransomware attacks rose year-over-year for the fourth consecutive month in June 2026, according to NCC Group.
  • The industrials sector absorbed 30% of all ransomware hits in Q2 2026, more than any other industry.
  • Government bodies recorded 89 confirmed ransomware attacks in the first half of 2026, with US agencies accounting for 31% of those, per Comparitech.
  • Researchers at Sysdig documented what they call the first known autonomous AI ransomware agent, dubbed JadePuffer, which carried out a full attack and left a Bitcoin ransom note without any human directing it.
  • Criminals are increasingly breaking in through VPNs, which are the software tunnels companies use to let staff connect securely from home or on the road.

Who got hit, and how badly?

The industrials sector, which covers manufacturing, logistics, and construction, took the most punishment. A single April attack on Signature Healthcare in Massachusetts shows what the numbers mean in practice: ambulance services were disrupted, cancer treatment appointments were cancelled, and Brockton Hospital had to fall back on paper-based procedures for several weeks.

Healthcare was the fourth most targeted industry, absorbing 10% of attacks in Q2 2026. Transportation, healthcare, retail, and technology all saw attack volumes climb over the past six months, by 52%, 35%, 28%, and 23% respectively, according to Comparitech.

Industry Q2 2026 share of attacks 6-month growth
Industrials 30% not reported
Consumer discretionary 24% not reported
Information technology 11% +23%
Healthcare 10% +35%
Transportation not reported +52%
Retail not reported +28%

How are the criminals getting in?

VPNs are the front door attackers keep kicking. Devices from Fortinet, Citrix, and Check Point have all been targeted. Security firm Arctic Wolf flagged an active campaign by the Qilin ransomware group exploiting a vulnerability in Palo Alto Networks' GlobalProtect VPN product.

Two groups sit at the top of the activity charts in 2026: Qilin and a newer outfit called The Gentlemen, which is reportedly a splinter of Qilin. Both have started deploying "EDR killer" tools, software designed to switch off the security agents, called endpoint detection and response tools, that businesses run on their computers and servers. Building those tools is technically demanding, which suggests these groups are growing more capable.

Another group to watch is KryBit, first seen in March 2026, which operates as a franchise model where criminals rent out its ransomware and attack tools to other criminals. It targets Windows machines, Linux servers, and the virtualisation software VMware ESXi.

What is AI ransomware and should people be worried?

Researchers at Sysdig documented an autonomous AI agent called JadePuffer that broke into a system, moved through the network, stole credentials, encrypted files, deleted the originals, and dropped a Bitcoin ransom demand, all without a human directing each step. It used a large language model, the same type of AI technology that powers chatbots, to adapt its approach in real time and fired off more than 600 separate attack actions. Sysdig called it "the first documented case of agentic ransomware."

This does not mean every ransomware attack tomorrow will be AI-driven. It does mean the barrier to running a complex, adaptive attack just got lower.

What should ordinary people do?

If your employer uses a VPN to let you work remotely, make sure any updates your IT team pushes are applied quickly. Stolen login credentials are the other main way attackers get in, so using a unique password for work systems and enabling two-step verification, where the system texts or emails a code to confirm it is really you, limits the damage if a password is ever stolen.

© 2026 Threat Vectr