# Ransomware Groups Shift Focus to AI Models: A New Era of Digital Extortion

*Published September 21, 2026*
*Source: [https://cybersecuritynews.com/when-ransomware-targets-ai-models-defending-the-ai-ml-recovery-chain/](https://cybersecuritynews.com/when-ransomware-targets-ai-models-defending-the-ai-ml-recovery-chain/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/ransomware-groups-shift-focus-to-ai-models-a-new-era-of-digital-extortion) or [see plans](https://www.sec-news.ai/pricing).*

## Article

Ransomware attacks have taken a strategic turn as threat actors now target artificial intelligence (AI) and machine learning (ML) assets. The Sysdig Threat Research Team has identified a group called JADEPUFFER that exemplifies this shift. Initially engaging in rudimentary database extortion, JADEPUFFER has evolved to deploy specialized ransomware aimed at destroying AI and ML infrastructure. Their first major attack involved compromising a Langflow instance, exploiting a known vulnerability to access sensitive data and encrypt over a thousand configuration items. Unusually, this attack did not focus on data exfiltration but rather on destruction, as the encryption keys were not stored, rendering recovery impossible. 

The sophistication of JADEPUFFER's operations became evident with the introduction of their second campaign featuring ENCFORGE, a custom ransomware targeting AI-specific file extensions such as model formats, training datasets, and vector indices. ENCFORGE employs hybrid encryption techniques and is designed to disrupt AI development pipelines by encrypting critical components. Despite facing initial setbacks, the threat actor quickly adapted by deploying a container escape mechanism, showcasing the resilience and adaptability of AI-driven attacks. 

The implications of these attacks are substantial, as the cost of rebuilding AI models and datasets can be prohibitive, often reaching hundreds of thousands of dollars. Traditional backup strategies are insufficient as they fail to account for the unique dependencies and large file sizes associated with AI assets. Organizations must monitor process behavior, identity anomalies, and filesystem changes to detect and respond to such threats in real time. Protecting AI infrastructure requires recognizing its critical role and ensuring continuous monitoring and robust recovery processes.
