Security Experts Discuss the Evolution of JADEPUFFER

Earlier this month, researchers shared what they believed to be the first documented instance of an end-to-end extortion operation driven by an agentic threat actor labelled JADEPUFFER. Now, the researchers have discovered a new development: JADEPUFFER has begun leveraging ransomware to destroy AI models.
Training a model can cost $500,000 just for engineering and compute, highlighting the gravity of potential losses for organizations.
“The entry point and the payload in this new operation tell the same story: an agentic operator enters AI infrastructure through an AI framework, and now deploys ransomware designed to destroy what that infrastructure runs on,” the new research states. “Unlike conventional ransomware targets, however, encrypted AI model artifacts cannot be restored after they are wiped. Rebuilding a production-ready, fine-tuned AI model requires re-running weeks or months of training, at a cost of $75,000 to $500,000 per model in compute and engineering time. If the training data sits on the same host, recovery is blocked entirely until that data is reconstructed first.”
Below, security leaders share their thoughts on JADEPUFFER’s evolution.
Security Leaders Weigh In
Diana Kelley, Chief Information Security Officer at Noma Security:
The first JADEPUFFER campaign demonstrated a highly autonomous attack capable of compromising AI infrastructure. This evolution goes a step further: it compromises AI infrastructure to target enterprise AI assets, including deployed and fine-tuned models, training and evaluation datasets, vector stores, and model artifacts that organizations depend on to operate AI in production.
That marks an important shift in attacker priorities. Attackers invariably go after what the business values most because that’s what organizations will pay to recover. As enterprise AI becomes a strategic business asset, we should expect attackers to target those assets directly, not just the infrastructure that supports them.
For CISOs, that changes how resilience should be planned. It’s no longer enough to back up servers and applications. Organizations need to identify their AI crown jewels and be prepared to recover the entire AI supply chain: deployed and fine-tuned models, training and evaluation data, vector stores, model registries, and the governance artifacts that establish provenance and trust. Ask yourself: if you can restore the server but not the AI system, have you really recovered?
Agnidipta Sarkar, Chief Evangelist at ColorTokens:
2026 is proving to be a transformational year for breach readiness. The narrative is rapidly changing from stopping attacks at the gate to halting the proliferation of attacks after they have bypassed the initial defenses.
JADEPUFFER demonstrated earlier this month that ransomware is no longer a craft for the highly skilled. All you need is an AI agent.
AI is no longer just a digital business capability. It is now an offensive weapon in the hands of adversaries who can now scan, exploit, and move laterally through your network at machine speed, often completing the entire attack lifecycle from initial access to data exfiltration in under four hours.
Shane Barney, Chief Information Security Officer at Keeper Security:
JADEPUFFER’s return with purpose-built tooling sends a clear signal: AI infrastructure is not an incidental target. ENCFORGE was designed specifically for the modern AI stack, and the fact that this operator invested in building it between campaigns tells security leaders something important about where this threat category is heading.
An operator returning to the same class of vulnerability across two documented campaigns is not finding sophisticated weaknesses. It is finding ordinary ones that have not been addressed, and that says as much about the state of AI infrastructure governance as it does about the threat actor. Keeper Security research found that 44% of organizations cite lack of governance for AI-driven access and automation as a top identity security gap, and 76% say Non-Human Identities are not consistently governed under privileged access policies. Those are the conditions JADEPUFFER is operating in.
The response starts with recognizing that every AI tool in your environment is a privileged identity with access to sensitive systems, credentials and data. Secrets need to be managed outside the application environment, access boundaries need to be defined and enforced, and what those identities are doing needs to be continuously monitored. Organizations that have extended zero-trust and privileged access management to their AI infrastructure are in a materially stronger position than those that have not, and the gap between those two groups is exactly what this threat was built to exploit.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!






