Vulnerability  ·  2026-07-22

JadePuffer Deploys ENCFORGE Ransomware Purpose-Built to Destroy AI Model Weights and Vector Databases

VulnerabilityHigh impactGlobal
Help Net Security reported (published 2026-07-21) that the JadePuffer agentic threat actor — previously known for automated database extortion — returned with ENCFORGE, a novel ransomware family purpose-built to target AI and ML infrastructure, encrypting model weights and vector databases to maximize leverage against victims.
This marks a strategic shift in ransomware targeting: attackers now recognize that AI model artifacts and vector stores are uniquely high-value, expensive-to-restore assets, making AI/ML production environments a distinct and increasingly attractive extortion target class, separate from traditional file/database ransomware.
The agentic threat actor JadePuffer gained initial access via a Langflow vulnerability and deployed ENCFORGE, a ransomware strain specifically engineered to locate and encrypt AI/ML artifacts — model checkpoints, vector-database stores, and training datasets — rather than generic file shares, exploiting the fact these assets are costly and slow to rebuild (reported up to $500k retraining cost).
AI/ML production infrastructure reachable via vulnerable Langflow deployments; model checkpoints, vector databases, training datasets
Patch Langflow to a fixed version, restrict Docker socket access, and maintain offline/immutable snapshots of production model artifacts and vector stores separate from the live serving environment.
Help Net Security — JadePuffer returns with ransomware built to target AI models and infrastructure
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →