TL;DR: AI-orchestrated ransomware is moving from concept to proof-of-function, with NYU Tandon researchers showing PromptLock can autonomously run reconnaissance, file selection, encryption, and extortion note generation, according to SecurityScorecard. The shift changes the control problem from blocking a human operator to containing machine-driven speed, polymorphism, and third-party exposure.
NHIMG editorial — based on content published by SecurityScorecard: Ransomware 3.0 runs autonomously on AI
By the numbers:
- 35.5% of breaches involved third parties in SecurityScorecard's 2025 Global Third-Party Breach Report.
- AI-powered attackers can attempt access within an average of 17 minutes when AWS credentials are exposed publicly.
Questions worth separating out
Q: What breaks when ransomware can run autonomously on AI?
A: Traditional detection and response workflows break because they assume the attacker needs time to operate manually.
Q: Why do exposed credentials matter more when attackers use AI-assisted malware?
A: Exposed credentials give adaptive malware a foothold it can use to generate scripts, explore systems, and change tactics faster than manual attackers.
Q: What are the signs that ransomware defence is failing against AI-driven attacks?
A: The clearest signs are delayed detection, broad admin entitlements, recoveries that have never been tested, and vendors with access you cannot revoke quickly.
Practitioner guidance
- Harden privileged access paths Remove standing admin access where possible, require phishing-resistant MFA for high-risk accounts, and restrict cloud admin actions to task-scoped sessions.
- Isolate recovery from production identity Keep immutable backups offline or logically isolated, and ensure backup credentials cannot be used to modify production systems.
- Continuously monitor third-party exposure Track vendor access, exposed services, and new vulnerabilities in near real time rather than relying on periodic questionnaires.
What's in the full article
SecurityScorecard's full article covers the operational detail this post intentionally leaves for the source:
- How TITAN Secure maps Internet Intelligence data to vendor ecosystems for real-time reconnaissance detection
- How TITAN Watch tracks vendor posture across 4.1 billion scanned IP addresses for continuous third-party visibility
- How TITAN Assess automates end-to-end third-party risk workflows for validation and compliance
- How SecurityScorecard frames the control stack around authentication, backups, and threat intelligence in one workflow
👉 Read SecurityScorecard's analysis of ransomware 3.0 and autonomous AI attacks →
Ransomware 3.0 and autonomous attacks: are your controls keeping up?
Explore further
Autonomous ransomware changes the control objective from containment to preemption. When a payload can move through reconnaissance, encryption, and extortion without a human operator in the loop, the defender's margin collapses. That means signature-led response is no longer enough on its own, especially where identity or vendor access is the first point of compromise. Practitioners should treat speed of execution as a primary risk variable.
A question worth separating out:
Q: How should security teams respond when third-party access is part of the ransomware path?
A: They should treat supplier access like privileged access, not like a procurement checkbox. That means continuous review of vendor entitlements, tighter segmentation around shared accounts, and immediate revocation paths for any third-party route that can reach critical systems.
👉 Read our full editorial: Ransomware 3.0 shifts attack speed, deception, and defence priorities