New details on a ransomware attack described as the first known case of an AI agent carrying out the technical execution of a real-world attack.

The report says the attack was not fully autonomous: a human still chose the victim, set up infrastructure, and supplied stolen credentials.

The distinction matters for cybersecurity teams because near-term AI risk may come from human-directed automation rather than independent criminal agents.