Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireSecurity Leadership and ManagementCybersecurity News

Security Experts Discuss the Evolution of JADEPUFFER

By Jordyn Alger, Managing Editor
Green planes reflected
Vishal Bansal via Unsplash
July 22, 2026

Earlier this month, researchers shared what they believed to be the first documented instance of an end-to-end extortion operation driven by an agentic threat actor labelled JADEPUFFER. Now, the researchers have discovered a new development: JADEPUFFER has begun leveraging ransomware to destroy AI models. 

Training a model can cost $500,000 just for engineering and compute, highlighting the gravity of potential losses for organizations. 

“The entry point and the payload in this new operation tell the same story: an agentic operator enters AI infrastructure through an AI framework, and now deploys ransomware designed to destroy what that infrastructure runs on,” the new research states. “Unlike conventional ransomware targets, however, encrypted AI model artifacts cannot be restored after they are wiped. Rebuilding a production-ready, fine-tuned AI model requires re-running weeks or months of training, at a cost of $75,000 to $500,000 per model in compute and engineering time. If the training data sits on the same host, recovery is blocked entirely until that data is reconstructed first.” 

Below, security leaders share their thoughts on JADEPUFFER’s evolution. 

Security Leaders Weigh In

Diana Kelley, Chief Information Security Officer at Noma Security:

The first JADEPUFFER campaign demonstrated a highly autonomous attack capable of compromising AI infrastructure. This evolution goes a step further: it compromises AI infrastructure to target enterprise AI assets, including deployed and fine-tuned models, training and evaluation datasets, vector stores, and model artifacts that organizations depend on to operate AI in production.

That marks an important shift in attacker priorities. Attackers invariably go after what the business values most because that’s what organizations will pay to recover. As enterprise AI becomes a strategic business asset, we should expect attackers to target those assets directly, not just the infrastructure that supports them.

For CISOs, that changes how resilience should be planned. It’s no longer enough to back up servers and applications. Organizations need to identify their AI crown jewels and be prepared to recover the entire AI supply chain: deployed and fine-tuned models, training and evaluation data, vector stores, model registries, and the governance artifacts that establish provenance and trust. Ask yourself: if you can restore the server but not the AI system, have you really recovered?

Agnidipta Sarkar, Chief Evangelist at ColorTokens:

2026 is proving to be a transformational year for breach readiness. The narrative is rapidly changing from stopping attacks at the gate to halting the proliferation of attacks after they have bypassed the initial defenses.

JADEPUFFER demonstrated earlier this month that ransomware is no longer a craft for the highly skilled. All you need is an AI agent.

AI is no longer just a digital business capability. It is now an offensive weapon in the hands of adversaries who can now scan, exploit, and move laterally through your network at machine speed, often completing the entire attack lifecycle from initial access to data exfiltration in under four hours.

Shane Barney, Chief Information Security Officer at Keeper Security: 

JADEPUFFER’s return with purpose-built tooling sends a clear signal: AI infrastructure is not an incidental target. ENCFORGE was designed specifically for the modern AI stack, and the fact that this operator invested in building it between campaigns tells security leaders something important about where this threat category is heading.

An operator returning to the same class of vulnerability across two documented campaigns is not finding sophisticated weaknesses. It is finding ordinary ones that have not been addressed, and that says as much about the state of AI infrastructure governance as it does about the threat actor. Keeper Security research found that 44% of organizations cite lack of governance for AI-driven access and automation as a top identity security gap, and 76% say Non-Human Identities are not consistently governed under privileged access policies. Those are the conditions JADEPUFFER is operating in.

The response starts with recognizing that every AI tool in your environment is a privileged identity with access to sensitive systems, credentials and data. Secrets need to be managed outside the application environment, access boundaries need to be defined and enforced, and what those identities are doing needs to be continuously monitored. Organizations that have extended zero-trust and privileged access management to their AI infrastructure are in a materially stronger position than those that have not, and the gap between those two groups is exactly what this threat was built to exploit.

KEYWORDS: artificial intelligence (AI) Artificial Intelligence (AI) Security ransomware research threat intelligence threat landscape

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Man in suit looking out window at city

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection

Photograph of apartment complex patios

Enhancing Residential Building Security

5 Minutes with Johnson

Can Organizations Trust Their Own AI?

Open filing cabinet

The Inside Job: Corporate Espionage Never Went Away

Person working on laptop

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape

Events

September 10, 2026

So, You Have an Emergency Management Plan… Now What?

LIVE: September 10, 2026 at 2 PM EDT Turning an emergency management plan into an actionable program that prepares staff, students, and partners to respond effectively is a challenge. Learn to move beyond compliance and build a resilient school safety program.
September 22, 2026

How to Detect, Verify, and Respond to AI-Driven Disinformation

LIVE: September 22, 2026 at 2 PM EDT Identify emerging threats, validate information with confidence, and coordinate an effective response across your organization. Learn how to build the people, processes, and technology needed to improve speed-to-truth.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Glowing AI square

    Security Experts Discuss the Hugging Face, OpenAI Incident

    See More
  • Burst of light

    Security Experts Discuss the Claude Fable 5 Launch

    See More
  • Bottles of water

    Security experts discuss the American Water cyberattack

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing