“Unlike conventional ransomware targets, however, encrypted AI model artifacts cannot be restored after they are wiped.” — researchers
JADEPUFFER now deploys ransomware designed to destroy AI models
Researchers who documented an early end-to-end extortion operation by an agentic threat actor labeled JADEPUFFER now report a new development: the actor has begun leveraging ransomware specifically to destroy AI models. The research states that the “entry point and the payload in this new operation tell the same story: an agentic operator enters AI infrastructure through an AI framework, and now deploys ransomware designed to destroy what that infrastructure runs on.”
The consequences are not academic. Training a model can cost $500,000 just for engineering and compute, the reporting notes, and rebuilding a production-ready, fine-tuned model requires re-running weeks or months of training at a cost of $75,000 to $500,000 per model. If the training data sits on the same host, the research warns, recovery is blocked entirely until that data is reconstructed first.
ENCFORGE and a direction in tooling: attackers investing in the AI stack
Security leaders say the return of JADEPUFFER with purpose-built tooling signals a deliberate shift. Shane Barney, Chief Information Security Officer at Keeper Security, said ENCFORGE “was designed specifically for the modern AI stack,” and that the operator’s investment in building it between campaigns “tells security leaders something important about where this threat category is heading.”
Diana Kelley, Chief Information Security Officer at Noma Security, framed the change as an attacker priority shift: “Attackers invariably go after what the business values most because that’s what organizations will pay to recover. As enterprise AI becomes a strategic business asset, we should expect attackers to target those assets directly, not just the infrastructure that supports them.”
Agentic operators, AI-enabled attacks, and the move from prevention to containment
Agnidipta Sarkar, Chief Evangelist at ColorTokens, described 2026 as “proving to be a transformational year for breach readiness,” arguing the narrative is moving “from stopping attacks at the gate to halting the proliferation of attacks after they have bypassed the initial defenses.” In JADEPUFFER’s case, Sarkar emphasized that “ransomware is no longer a craft for the highly skilled. All you need is an AI agent.”
The reporting quotes a stark operational tempo: adversaries can “scan, exploit, and move laterally through your network at machine speed, often completing the entire attack lifecycle from initial access to data exfiltration in under four hours.” That speed, security leaders say, undercuts traditional incident containment assumptions.
What this means for CISOs, procurement leaders, and security teams
- CISOs: Diana Kelley argues that resiliency planning must move beyond server and application backups to identify and protect “AI crown jewels” — deployed and fine-tuned models, training and evaluation data, vector stores, model registries, and governance artifacts that establish provenance and trust. Kelley asks bluntly: “if you can restore the server but not the AI system, have you really recovered?”
- Security teams: Shane Barney advises treating every AI tool as a privileged identity. Keeper Security’s research cited in the reporting found that 44% of organizations cite lack of governance for AI-driven access and automation as a top identity security gap, and 76% say Non-Human Identities are not consistently governed under privileged access policies. Barney recommends managing secrets outside the application environment, defining and enforcing access boundaries, and continuously monitoring what those identities do.
- Procurement and engineering leaders: The cost and time to rebuild models — $75,000 to $500,000 per model and weeks or months of training — create a new calculus for what must be insured, backed up, or isolated. If training datasets and artifacts are co-located with production hosts, recovery may be impossible without reconstructing raw data and retraining.
Conclusion: a narrow vulnerability with broad implications
The central, concrete risk the reporting establishes is narrow and specific: when an adversary wipes encrypted AI model artifacts, those artifacts cannot simply be restored. That fact reframes upset and recovery from an IT exercise into an AI-asset reconstruction problem measured in months and hundreds of thousands of dollars per model. Security leaders quoted in the reporting converge on a single practical question that organizations must answer now: can you recover the AI system — models, data, registries, governance — or only the servers that once hosted them?




