AI Models Under Siege: JADEPUFFER Ransomware Targets Critical AI Infrastructure

3

AI Models Under Siege: How JADEPUFFER's Ransomware Evolution Is Rewriting Cybersecurity Priorities

A threat actor known as JADEPUFFER has escalated its attacks on artificial intelligence infrastructure by deploying ransomware purpose-built to permanently destroy AI models — assets that can cost organizations up to $500,000 to rebuild.

The development marks a dangerous turning point in enterprise cybersecurity. JADEPUFFER was already notable for orchestrating what researchers believe is the first documented end-to-end extortion operation driven by an agentic threat actor. Now its latest campaign reveals something more alarming: adversaries are no longer treating AI infrastructure as a path to an organization's data. They are treating the AI itself as the prize — and the target.


What Makes This Ransomware Different

Traditional ransomware disrupts operations. JADEPUFFER's new tooling — identified in research as ENCFORGE — is designed specifically to destroy them permanently.

"Unlike conventional ransomware targets, encrypted AI model artifacts cannot be restored after they are wiped," the research states. "Rebuilding a production-ready, fine-tuned AI model requires re-running weeks or months of training, at a cost of $75,000 to $500,000 per model in compute and engineering time."

The attack enters through AI frameworks — the same infrastructure organizations rely on to develop and run their models. Once inside, ENCFORGE targets:

  • Deployed models and fine-tuned model artifacts
  • Training and evaluation datasets
  • Vector stores and model registries

If training data sits on the same host as the model, recovery becomes impossible until that data is reconstructed first. This is not a temporary setback — it is the potential erasure of months of institutional investment.

Diana Kelley, Chief Information Security Officer at Noma Security, described the shift in stark terms. "That marks an important shift in attacker priorities," she said. "Attackers invariably go after what the business values most because that's what organizations will pay to recover. As enterprise AI becomes a strategic business asset, we should expect attackers to target those assets directly — not just the infrastructure that supports them."

Her warning lands with particular force given how deeply enterprises have embedded AI into their core operations. Losing a production-ready model is not a server problem. It is a business continuity crisis.

Understanding how threat actors like JADEPUFFER identify, prioritize, and execute against high-value targets is increasingly critical — and it's why building a mature cyber threat intelligence capability has moved from a nice-to-have to a foundational security requirement for enterprises running AI at scale.


The Governance Gap JADEPUFFER Is Exploiting

Ordinary Vulnerabilities, Extraordinary Consequences

Security leaders are drawing attention to a troubling reality beneath the technical details: JADEPUFFER is not finding sophisticated vulnerabilities. It is finding neglected ones.

Shane Barney, Chief Information Security Officer at Keeper Security, pointed to research showing that 44% of organizations cite a lack of governance for AI-driven access and automation as a top identity security gap. Furthermore, 76% of organizations report that Non-Human Identities are not consistently governed under privileged access policies.

"An operator returning to the same class of vulnerability across two documented campaigns is not finding sophisticated weaknesses," Barney said. "It is finding ordinary ones that have not been addressed — and that says as much about the state of AI infrastructure governance as it does about the threat actor."

Barney's prescription is direct. Every AI tool operating in an organization's environment should be treated as a privileged identity with access to sensitive systems, credentials, and data. Secrets must be managed outside the application environment. Access boundaries must be defined and enforced. And the behavior of those identities must be monitored continuously.

"Organizations that have extended zero-trust and privileged access management to their AI infrastructure are in a materially stronger position than those that have not," he said. "The gap between those two groups is exactly what this threat was built to exploit."

The Machine-Speed Threat Landscape

Agnidipta Sarkar, Chief Evangelist at ColorTokens, framed the broader moment with urgency. "2026 is proving to be a transformational year for breach readiness," he said. "The narrative is rapidly changing from stopping attacks at the gate to halting the proliferation of attacks after they have bypassed the initial defenses."

Sarkar noted that AI has fundamentally lowered the barrier for conducting sophisticated attacks. "AI is no longer just a digital business capability," he said. "It is now an offensive weapon in the hands of adversaries who can scan, exploit, and move laterally through your network at machine speed — often completing the entire attack lifecycle from initial access to data exfiltration in under four hours."

Four hours. That window leaves almost no margin for detection-first security strategies. Organizations must assume breach and architect their defenses accordingly. JADEPUFFER's operational pattern — persistent, targeted, and adaptive — bears the hallmarks of a threat actor with long-term objectives rather than opportunistic gain. For security teams seeking to understand this type of adversary in depth, a closer examination of how advanced persistent threats operate and evolve provides essential context for building proportionate defenses.


Rethinking Resilience for the AI Era

The AI Crown Jewels Problem

The emergence of JADEPUFFER's evolved capabilities forces a fundamental rethink of what organizational resilience actually means in an era where AI systems carry significant strategic and financial weight.

Kelley issued a direct challenge to CISOs navigating this new reality. "It's no longer enough to back up servers and applications," she said. "Organizations need to identify their AI crown jewels and be prepared to recover the entire AI supply chain: deployed and fine-tuned models, training and evaluation data, vector stores, model registries, and the governance artifacts that establish provenance and trust."

The question she posed cuts to the heart of the problem: "If you can restore the server but not the AI system, have you really recovered?"

Much like the fictional Skynet in the Terminator franchise once made AI the threat, JADEPUFFER is making AI the victim — and the lesson is that what an organization builds with intelligence can be dismantled by it just as efficiently.

The stakes are not abstract. At $500,000 per model in compute and engineering costs alone, a single successful JADEPUFFER attack could deliver a financial blow that rivals a full operational shutdown.

What Security Teams Should Do Now

Effective defense against this class of threat requires more than patching known vulnerabilities. It demands a proactive, intelligence-led posture — one that accounts for the unique characteristics of AI infrastructure as both an operational dependency and a high-value target. Understanding the full threat intelligence lifecycle is particularly relevant here, as it provides the structured framework security teams need to move from reactive incident response to anticipatory defense.

Security leaders and organizations working to strengthen their posture against this class of threat can draw three practical conclusions from this research:

  1. Audit every AI tool in your environment as a privileged identity and apply access controls accordingly. Non-Human Identities operating without governance are the entry point JADEPUFFER is designed to exploit.
  2. Store training data and model artifacts on separate, isolated systems to prevent total recovery failure. Co-locating these assets eliminates your fallback position the moment an attacker gains access.
  3. Develop an AI-specific incident response plan that accounts for the unique rebuilding timelines and costs associated with destroyed model infrastructure — because a standard disaster recovery playbook will not be sufficient.

The MITRE ATLAS framework, which maps adversarial tactics and techniques specifically against machine learning systems, offers a structured starting point for organizations building or stress-testing their AI-focused threat models.

JADEPUFFER's evolution is a signal, not an anomaly. As AI becomes load-bearing infrastructure for enterprise operations, it will attract precisely the attention that load-bearing infrastructure always has. The organizations that recognize this now — and govern their AI environments accordingly — will be the ones with a viable recovery path when the next campaign lands.

You might also like