AI-Powered Ransomware Attacks Just Got a Lot Cheaper
Security researchers have exposed a ransomware server that reveals just how far automation has crept into cybercrime. According to reporting from Cybernews, a ransomware affiliate has been running an AI agent called Hermes that can compromise and extort multiple victims at the same time, and the entire operation costs roughly $4 in AI tokens per attack. The discovery offers a rare, direct look inside how AI-powered ransomware attacks are reshaping the economics of extortion, and it should serve as a wake-up call for any organization that assumes cybercriminals still need deep technical skill or significant budgets to cause damage.
What makes this case notable isn't just the low cost. It's the scope of what the Hermes agent was apparently doing on its own. Researchers found that the tool was used across every stage of an attack, from initial compromise through to calculating and setting ransom demands. In other words, tasks that once required a skilled human operator, or a small team of them, are now being delegated to an automated system that can run the same playbook against several targets in parallel.
From Encryption to Pure Data-Theft Extortion
Perhaps the most significant shift documented in this case is strategic, not technical. The affiliate behind Hermes has reportedly abandoned traditional ransomware encryption altogether. Instead of locking up a victim's files and demanding payment for a decryption key, the group now focuses exclusively on stealing data and threatening to leak or sell it unless a ransom is paid.
This matters because it changes the calculus for victims and defenders alike. Encryption-based ransomware can often be countered, at least partially, by restoring from clean backups. Data-theft extortion sidesteps that defense entirely. Even if a company recovers its systems without paying a cent, the attackers still hold sensitive files, and the threat of exposure alone can be enough to pressure a payout. For companies handling customer data, financial records, or health information, that means backups alone are no longer a sufficient safety net.
This isn't the first time AI tooling has surfaced in connection with the broader ransomware ecosystem. vpn.social previously reported on a case involving Claude Code used in Gentlemen ransomware VPN attacks, where an AI coding assistant was reportedly leveraged to carry out stages of an intrusion. Taken together, these reports point to a pattern: ransomware operators are increasingly experimenting with AI tools to handle work that used to require dedicated human expertise, lowering the barrier to entry and speeding up attack timelines.
What This Means For You
If you run a business, manage IT infrastructure, or simply store sensitive data online, this case is a reminder that the threshold for launching a serious cyberattack keeps dropping. When a ransomware campaign can be automated and scaled for a few dollars, attackers no longer need to be selective. Smaller organizations that previously assumed they were "too small to be a target" are now well within reach, since the marginal cost of adding one more victim to an AI-driven campaign is negligible.
The shift toward data-theft-only extortion also means that prevention has to happen earlier in the attack chain. Once data has left your network, there is no restoring your way out of the problem. That puts extra weight on things like network segmentation, strict access controls, and monitoring for unusual outbound data transfers, since these are the controls that can stop exfiltration before it happens rather than after the fact.
Key Takeaways
Given how cheap and automated these attacks have become, a few practical steps stand out for reducing risk:
- Assume your organization is a viable target regardless of size, since AI-driven attacks scale cheaply across many victims at once.
- Prioritize preventing data exfiltration, not just system recovery, since backups don't protect against leak-based extortion.
- Segment networks and limit access privileges so a single compromised account can't expose your entire dataset.
- Monitor for unusual outbound traffic patterns, which is often the clearest early sign of data theft in progress.
- Review incident response plans to specifically address extortion threats based on stolen data, not just ransomware encryption.
AI-powered ransomware attacks are no longer a future concern; they're already running in the wild for the cost of a cup of coffee. Staying ahead of that trend means treating data protection, not just recovery, as the top priority, and revisiting your organization's defenses before an automated attacker finds the gap first.




