Researchers have uncovered an exposed server that allegedly supported an AI ransomware operation targeting more than 30 companies. The infrastructure contained 3.1TB of stolen data, malware-related tools, AI-generated scripts and records covering attacks from initial access through ransom demands.

Cybernews linked the server to an affiliate of The Gentlemen ransomware group. Researchers say the operation relied heavily on AI automation, reducing the estimated token cost of an attack to between $0.40 and $4 per victim.

Exposed server contained stolen corporate data

Cybernews researchers discovered the exposed infrastructure on July 22. It included a Windows virtual private server and connections to additional servers in other countries.

The system reportedly stored data stolen from organisations across healthcare, marketing, consulting, real estate, software development, telecommunications, manufacturing and transportation.

Researchers found tools for remote access, data uploads and payload delivery, alongside active reverse-shell services. The server also contained 86 AI-generated Python scripts configured with victim endpoints.

The materials suggest attackers used the infrastructure to collect data, maintain access to compromised systems and prepare extortion demands.

AI agent automated attacks against GitLab

The alleged AI ransomware operation focused on vulnerable or misconfigured GitLab instances. GitLab often stores private source code, deployment information and sensitive credentials, making it an attractive target for extortion groups.

Researchers said attackers began with compromised GitLab credentials, likely obtained through information-stealing malware logs or access brokers. They then gave an AI agent the target details and directed it to perform reconnaissance, data theft and other post-compromise actions.

The agent reportedly adapted scripts to each victim environment and generated files for tasks such as collecting data, creating archives and assessing the value of stolen material.

Instead of encrypting systems, the operation appears to have focused on data-theft extortion. The attackers allegedly used AI-generated reports to help calculate ransoms and increase pressure on victims.

Low costs could fuel more cybercrime

Traditional ransomware attacks require technical skill, time and manual oversight. This case suggests AI tools may allow criminals to run many attacks at once with far less effort.

The reported cost of $0.40 to $4 in AI tokens per company does not include infrastructure, stolen credentials or other operational expenses. Even so, the figure shows how automation can make opportunistic attacks cheaper to scale.

Researchers warn that AI-generated scripts may also evade signature-based security tools because the code can change between targets.

The exposed server itself shows that threat actors still make operational mistakes. Misconfigured infrastructure can expose their tools, stolen data and attack workflows.

How companies can reduce risk

Organisations should rotate exposed credentials and monitor GitLab accounts for suspicious activity. They should investigate unusual bulk repository cloning, unfamiliar remote-access tools and unauthorised activity on CI/CD runners.

Teams should also restrict public access to GitLab and other sensitive systems. VPN allowlists and trusted-network access can reduce the exposure of internal developer platforms.

Companies should avoid storing secrets in private repositories and regularly audit their code, CI/CD configurations and access controls. Keeping GitLab and connected software fully patched remains essential.

The AI ransomware operation highlights a growing concern: attackers can now automate more of the intrusion and extortion process. Strong credential hygiene, network controls and continuous monitoring remain the most effective defences.


0 responses to “Exposed Server Reveals AI Ransomware Attacks Costing as Little as $4”