What happened
Researchers at Tenet Security have documented a novel attack class they call 'Agentjacking,' in which AI coding agents are manipulated into executing malicious code on developer machines. The method exploits Sentry, a widely used open-source error-tracking platform, by injecting a fabricated error report that the AI agent interprets as legitimate and acts upon. Separately, a ransomware collective called The Gentlemen has surged to become the second most prolific ransomware operation by victim count, drawing skilled threat actors through an unusually generous affiliate model that hands over 90 percent of collected ransoms. Investigative reporting from Krebs on Security suggests researchers have identified behavioral and technical clues that may point to the real-world identity of the group's administrator.
Why it matters for your business
Agentjacking signals a meaningful shift in the attack surface: as development teams integrate AI agents directly into coding workflows, those agents become viable entry points for supply chain and lateral-movement attacks. A poisoned error report requires no phishing email and no direct user interaction — the agent does the attacker's work autonomously. Organizations using AI-assisted development tools should audit which external data sources those agents are permitted to consume and act on, and enforce strict sandboxing around automated code execution. The Gentlemen's 90-percent payout structure makes affiliate recruitment cheap and fast, which typically correlates with a spike in attack volume and a broadening of target industries — meaning mid-market firms, not just large enterprises, are likely in scope.
What to watch next
Expect disclosure of additional Agentjacking vectors beyond Sentry as security teams examine other monitoring and observability platforms that feed data to AI agents. If the administrator identity behind The Gentlemen is confirmed and acted upon by law enforcement, observers should track whether the group fragments into smaller cells — a pattern seen after previous ransomware takedowns that often produces short-term disruption but long-term proliferation.
