An AI-Run Ransomware Group Comes Back With a New Weapon
JadePuffer, the threat actor previously documented as running the first ransomware campaign carried out end-to-end by a large language model, is back with a new tool. According to Infosecurity Magazine, the group's follow-up campaign has deployed a locker called ENCFORGE, purpose-built to destroy AI model artifacts rather than just encrypt ordinary files and databases.
This matters because it marks a shift in target selection. Earlier ransomware operations, including JadePuffer's original campaign, focused on encrypting production databases and demanding payment for their return. Sysdig's original documentation of the JadePuffer attack described an agentic operator that exploited the Langflow platform and ran the intrusion with minimal human oversight. ENCFORGE appears to extend that same automated approach, but with a new objective: wiping out the trained models, weights, and configuration files that organizations rely on to run AI systems.
Why Targeting AI Models Changes the Calculus
Traditional ransomware holds data hostage. Destroying AI model artifacts is a different kind of extortion. Trained models often represent months of compute time, curated training data, and fine-tuning work that cannot simply be restored from a routine backup if that backup wasn't specifically designed with model recovery in mind. For companies that have built customer-facing AI tools, internal automation, or data processing pipelines around these models, losing them outright can be more disruptive than losing a single database, because rebuilding a model from scratch takes time that a live business often doesn't have.
There's also a privacy dimension worth flagging. Many AI models used by businesses are trained or fine-tuned on datasets that include customer information, whether that's support transcripts, behavioral data, or personal records used to personalize a service. When ransomware operators target the infrastructure around these models, whether by encrypting the surrounding databases or now destroying the models themselves, the personal data flowing through that infrastructure is put at risk of both exposure and loss. Consumers rarely have visibility into which vendors are running AI systems on their information, which makes this kind of attack harder to detect from the outside and harder to prepare for as an individual.
Part of a Broader Pattern in Autonomous Attacks
JadePuffer's return with ENCFORGE fits into a trend that security researchers have been tracking closely this year. Independent findings around the first fully autonomous AI ransomware attack showed that an AI agent could scan for vulnerabilities, gain access, and execute an extortion attempt without a human operator directing each step in real time. That precedent matters here because it suggests JadePuffer isn't a one-off experiment. It's an operator that has iterated on its own tooling, moving from database encryption to a locker specifically engineered against AI infrastructure. As more organizations adopt AI platforms like Langflow and similar orchestration tools, the attack surface for this kind of campaign only grows, a theme covered in recent security recaps tracking ransomware and AI-driven attacks alongside other emerging threats.
What This Means For You
Most readers won't be running an AI model deployment themselves, but the ripple effects reach further than IT departments. If a business you interact with, whether a retailer, a healthcare provider, or a financial service, uses AI systems that get hit by an attack like this, the fallout could include service outages, delayed support, or in worse cases, exposure of the data those models were trained or operated on. Ransomware aimed at AI infrastructure is still a business-to-business problem right now, but the consumer data sitting inside that infrastructure is what gives these attacks their leverage.
For organizations building or operating AI systems, this is a clear signal that model artifacts need the same backup discipline, access controls, and monitoring as any other critical asset. Treating a trained model as disposable or easily replaceable is no longer a safe assumption.
Actionable Takeaways
- If you manage AI infrastructure, ensure model weights and training artifacts are backed up separately from production systems, with offline or immutable copies.
- Review access controls on AI orchestration platforms; agentic ransomware campaigns have exploited exposed or misconfigured tools to gain a foothold.
- As a consumer, ask service providers how they protect the AI systems processing your data, particularly for services handling sensitive personal or financial information.
- Stay alert to service disruptions or breach notifications from companies you use; ransomware targeting AI backends can delay recovery longer than a typical outage.
JadePuffer's evolution from database extortion to AI model destruction is a reminder that ransomware operators adapt quickly to wherever value, and leverage, is concentrated. As AI systems become core infrastructure for more businesses, protecting them will need to become a core part of everyone's security posture, not an afterthought.




