AI Ran Its Own Hack, Fairlife Milk Halted, 79% of Ransomware Starts With a Login


AI Ran Its Own Hack, Fairlife Milk Halted, 79% of Ransomware Starts With a Login


An AI just ran an entire hacking campaign on its own. No human at the keyboard, 17,000 actions in a single weekend, against Hugging Face, the platform nearly every company on earth downloads its AI from. If the tool your business relies on can be attacked by software that never sleeps, the math on cybersecurity just changed for everyone. *The cost of attacking just dropped. The value of defending just went up.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. First, the one that should make every owner sit up. Hugging Face, the "GitHub of AI," disclosed that an autonomous AI agent broke in through a poisoned dataset, stole credentials, and moved through its systems, logging more than 17,000 actions before it was caught. That is the workload of a full hacking crew, run by software, at a speed no human team can match. Here is the part that should reframe how you think about your own company: for years the limit on an attacker was people, and people cost money and don't scale, but an agent erases that limit. The new economy runs on agents plus employees, and the criminals are already staffing up with agents. Then it gets physical. A ransomware attack hit Coca-Cola's Fairlife, the premium milk brand doing over $3 billion a year, and shut down every one of its U.S. production plants. This wasn't stolen emails, it reached the operational systems that physically make the product, so a breach turned into a full shutdown. Because Coca-Cola is publicly traded, the attack landed in an SEC filing within days, a reminder that a cyberattack is now a material business event you may legally have to report. One detail worth noting: the Canadian plants kept running because they were separated from the U.S. network, which is exactly what good segmentation buys you. Finally, the numbers behind all of it. The new Sophos State of Ransomware 2026 report surveyed 2,158 companies that actually got hit, and the headline flips a common assumption: 79% of attacks now start with a stolen login, not some exotic exploit. Even more sobering, 97% of the victims whose attack began with stolen credentials already had multi-factor authentication turned on, which means regular MFA is being bypassed. The good news you can act on: two-thirds of encrypted victims recovered from backups instead of paying, and while ransom demands fell to around $700,000, the average cleanup still runs $1.7 million, so prevention is almost always the cheaper line item. Three stories, one thread. The cost of launching an attack keeps falling, which makes every dollar you spend defending worth more than it was a year ago. In this episode, we discuss: • How an autonomous AI agent hacked Hugging Face with no human at the keyboard • Why the Coca-Cola Fairlife ransomware attack shut down U.S. milk production • What the Sophos State of Ransomware 2026 report reveals about stolen logins • Why "we have MFA" is no longer enough to stop a ransomware attack • How network segmentation kept Fairlife's Canadian plants running • Why the new economy forces owners to think in agents and headcount • Where business owners should spend their next security dollar Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #HuggingFace #AI #CocaCola #Fairlife #Ransomware #Sophos #DataBreach #MFA #BusinessRisk #MSP

Contact Me