Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireSecurity Leadership and ManagementCybersecurity News

Security Experts Discuss the Evolution of JADEPUFFER

By Jordyn Alger, Managing Editor
Green planes reflected
Vishal Bansal via Unsplash
July 22, 2026

Earlier this month, researchers shared what they believed to be the first documented instance of an end-to-end extortion operation driven by an agentic threat actor labelled JADEPUFFER. Now, the researchers have discovered a new development: JADEPUFFER has begun leveraging ransomware to destroy AI models. 

Training a model can cost $500,000 just for engineering and compute, highlighting the gravity of potential losses for organizations. 

“The entry point and the payload in this new operation tell the same story: an agentic operator enters AI infrastructure through an AI framework, and now deploys ransomware designed to destroy what that infrastructure runs on,” the new research states. “Unlike conventional ransomware targets, however, encrypted AI model artifacts cannot be restored after they are wiped. Rebuilding a production-ready, fine-tuned AI model requires re-running weeks or months of training, at a cost of $75,000 to $500,000 per model in compute and engineering time. If the training data sits on the same host, recovery is blocked entirely until that data is reconstructed first.” 

Below, security leaders share their thoughts on JADEPUFFER’s evolution. 

Security Leaders Weigh In

Diana Kelley, Chief Information Security Officer at Noma Security:

The first JADEPUFFER campaign demonstrated a highly autonomous attack capable of compromising AI infrastructure. This evolution goes a step further: it compromises AI infrastructure to target enterprise AI assets, including deployed and fine-tuned models, training and evaluation datasets, vector stores, and model artifacts that organizations depend on to operate AI in production.

That marks an important shift in attacker priorities. Attackers invariably go after what the business values most because that’s what organizations will pay to recover. As enterprise AI becomes a strategic business asset, we should expect attackers to target those assets directly, not just the infrastructure that supports them.

For CISOs, that changes how resilience should be planned. It’s no longer enough to back up servers and applications. Organizations need to identify their AI crown jewels and be prepared to recover the entire AI supply chain: deployed and fine-tuned models, training and evaluation data, vector stores, model registries, and the governance artifacts that establish provenance and trust. Ask yourself: if you can restore the server but not the AI system, have you really recovered?

Agnidipta Sarkar, Chief Evangelist at ColorTokens:

2026 is proving to be a transformational year for breach readiness. The narrative is rapidly changing from stopping attacks at the gate to halting the proliferation of attacks after they have bypassed the initial defenses.

JADEPUFFER demonstrated earlier this month that ransomware is no longer a craft for the highly skilled. All you need is an AI agent.

AI is no longer just a digital business capability. It is now an offensive weapon in the hands of adversaries who can now scan, exploit, and move laterally through your network at machine speed, often completing the entire attack lifecycle from initial access to data exfiltration in under four hours.

Shane Barney, Chief Information Security Officer at Keeper Security: 

JADEPUFFER’s return with purpose-built tooling sends a clear signal: AI infrastructure is not an incidental target. ENCFORGE was designed specifically for the modern AI stack, and the fact that this operator invested in building it between campaigns tells security leaders something important about where this threat category is heading.

An operator returning to the same class of vulnerability across two documented campaigns is not finding sophisticated weaknesses. It is finding ordinary ones that have not been addressed, and that says as much about the state of AI infrastructure governance as it does about the threat actor. Keeper Security research found that 44% of organizations cite lack of governance for AI-driven access and automation as a top identity security gap, and 76% say Non-Human Identities are not consistently governed under privileged access policies. Those are the conditions JADEPUFFER is operating in.

The response starts with recognizing that every AI tool in your environment is a privileged identity with access to sensitive systems, credentials and data. Secrets need to be managed outside the application environment, access boundaries need to be defined and enforced, and what those identities are doing needs to be continuously monitored. Organizations that have extended zero-trust and privileged access management to their AI infrastructure are in a materially stronger position than those that have not, and the gap between those two groups is exactly what this threat was built to exploit.

KEYWORDS: artificial intelligence (AI) Artificial Intelligence (AI) Security ransomware research threat intelligence threat landscape

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Hand reaching up out of the ocean

What I Learned About Burnout the Hard Way (and How to Actually Fix it)

Broken wet floor sign

Why Response Time Is Becoming the Missing Metric in Workplace Safety and Security

Paparazzi

When Private Events Become Public Infrastructure: What Celebrity OSINT Teaches Security Leaders

Cyber Tactics

AIBOMs: Bringing AI Security Out of the Shadows, A Practical Guide for Security Professionals

Medical professional

Nearly 85% of Nurses Experienced Workplace Violence in the Last Year

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

August 27, 2026

Leveraging AI & Mobility to Advance Your Security Domain

LIVE: August 27, 2026 at 2 PM EDT Explore how AI-driven cloud security solutions can elevate your security domain enhancing threat detection, streamlining operations, and delivering the resilience modern organizations demand.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Burst of light

    Security Experts Discuss the Claude Fable 5 Launch

    See More
  • Bottles of water

    Security experts discuss the American Water cyberattack

    See More
  • American flag

    Trump Signs Executive Order for Oversight of AI Models, Security Experts Discuss

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing