Top Highlights
- JADEPUFFER now uses ransomware to destroy AI models, making recovery costly ($75,000-$500,000) and often impossible, as models can’t be restored after deletion.
- Attackers target not just infrastructure but critical AI assets like trained models and datasets, risking significant operational and financial losses.
- The threat exploits governance gaps in AI access management, emphasizing the need for enhanced zero-trust policies and privileged identity controls.
The Threat, Attack Techniques, and Targets
Earlier this month, researchers identified JADEPUFFER as a dangerous threat actor. This group has developed an advanced form of attack called end-to-end extortion. Recently, they started using ransomware to destroy artificial intelligence (AI) models. These models are vital for many organizations because training them can cost up to $500,000.
The attack begins when JADEPUFFER’s operator gains access to AI infrastructure. They use specialized ransomware designed to wipe AI models completely. Since encrypted AI models cannot be restored, organizations face a severe challenge. Rebuilding these models takes weeks or months of training, which costs between $75,000 and $500,000. If the attacker destroys the training data on the host, recovery is impossible until that data is reconstructed.
The targets include AI infrastructure, like deployed AI models, datasets used for training and testing, and other AI assets essential for operation. The attack aims to damage or eliminate these valuable AI components directly.
Impact, Security Implications, and Remediation Guidance
The impact of JADEPUFFER’s new tactics is significant. Destroying AI models leads to considerable financial losses because rebuilding these models is expensive and time-consuming. For many organizations, this attack can cause operational disruptions and loss of competitive advantage.
Security experts note that the evolution of JADEPUFFER reflects a shift in attacker priorities. Instead of only hacking systems, attackers are now targeting the core AI assets organizations depend on for daily operations. This makes traditional backup plans insufficient because they do not cover the entire AI supply chain. Protecting AI assets requires identifying key AI components and ensuring they can be fully recovered after an attack.
Organizations should improve their security by managing access rights carefully. Every AI tool acts as a privileged identity, so strong access controls and continuous monitoring are needed. Implementing zero-trust policies and securing secrets outside of AI tools help reduce vulnerabilities. If organizations suspect they are under attack or want to improve their defenses, they should consult with their security vendors or relevant authorities for specific remediation strategies.
Discover More Technology Insights
Learn how the Internet of Things (IoT) is transforming everyday life.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
