Ransomware built to destroy AI models hit the same server twice, and the second attack could cost half a million dollars to undo
A hacker group exploited a 14-month-old security hole to deploy malware designed specifically to wipe out trained AI models worth hundreds of thousands of dollars. The ransom was uncollectable. The damage was not.

Key points
- Security firm Sysdig documented two separate attacks on the same unpatched server on July 1 and July 20, 2025, both carried out by a group it calls JADEPUFFER.
- The second attack deployed ENCFORGE, ransomware built specifically to destroy trained AI model files rather than general business data.
- Sysdig estimates replacing a single destroyed production AI model costs between $75,000 and $500,000.
- CVE-2025-3248, the entry point used both times, had been flagged as actively dangerous by US federal agencies since May 5, 2025, yet the server stayed unpatched for over 14 months.
- In the first attack, the encryption key was generated randomly and never saved, making it a wiper disguised as ransomware: paying would have recovered nothing.
A hacker group broke into the same vulnerable server twice in three weeks. Once to encrypt configuration data. A second time to bring a weapon with one purpose: erasing trained AI models that can cost hundreds of thousands of dollars and months of work to rebuild.
Security firm Sysdig published its findings after tracking both intrusions. JADEPUFFER, the name Sysdig gave the group, used the same front door each time.
What door did they walk through?
CVE-2025-3248 is a critical flaw in Langflow, a popular tool that lets companies build AI-powered applications by connecting different services visually, without writing much code. It scores 9.8 out of 10 on the standard severity scale. Anyone who could reach the server could send it Python commands and have them run with no password required.
US Cybersecurity and Infrastructure Security Agency added it to its known-exploited list on May 5, 2025, with a federal patch deadline of May 26. Langflow fixed the problem in version 1.3.0. When JADEPUFFER returned in July, the targeted server was still unpatched, more than 14 months after that listing.
Mike Riemer, Ivanti's field CISO, told VentureBeat that vendors have hardened the obvious entry points, so attackers now look elsewhere. Once inside, they found an exposed Docker socket, a pathway that gives essentially full control over the underlying computer, not just the software running on it.
What makes ENCFORGE different from ordinary ransomware?
Ordinary ransomware encrypts everything it finds and demands payment for the key. ENCFORGE, a custom-built program written in the Go programming language, was designed around AI files from the start.
Sysdig found it targets roughly 180 file types. The list reads like a catalogue of AI development: PyTorch and TensorFlow checkpoints (files that store a model's learned knowledge at a point in time), Hugging Face SafeTensors weights (a common format for storing finished AI models), GGUF files (the format most people use to run AI models locally), FAISS vector indexes (databases that help AI systems search large amounts of information quickly), and training data in Parquet and NumPy formats. Generic ransomware hits these files only by accident. ENCFORGE names them deliberately.
The encryption uses AES-256-CTR, a strong method, with a unique key per attack, that key then locked inside the program using RSA-2048. Rather than encrypt entire large files, it encrypts sections of them, a speed trick established ransomware families use to cripple big files fast.
One extraordinary detail: in the first attack the key was printed once to a screen and never saved. Paying the ransom would have recovered nothing. The tool was a wiper wearing a ransom note as a costume. Both notes shared the same Proton Mail contact address, linking the campaigns to the same crew.
Why is losing a trained AI model so much worse than losing other data?
Restoring a wiped database from a Friday backup costs a weekend of lost transactions. A destroyed AI model costs everything it ever learned, with no row-by-row record to replay.
Sysdig puts the direct cost of rebuilding a single production-ready fine-tuned model (one trained on a company's specific data to do a specific job) at $75,000 to $500,000. That figure reflects specialist chip rental plus engineering time. Most teams keep several model versions on shared storage, and if the training data sat on the same server as the model files, rebuilding is blocked until that dataset is reconstructed too.
Michael Clark, who leads Sysdig's threat research team, described the goal as destroying "the one thing an organization can't simply restore."
Kayne McGladrey, a Senior Member of the IEEE (the world's largest professional association for engineers and technologists), told VentureBeat the problem is that security teams file these risks under the wrong category. Frame it as a cybersecurity issue and it loses budget fights. Frame it as a $500,000 business loss and a CFO acts.
This is the pattern worth watching, and it connects to a broader moment. Our report on 28 July 2026, "OpenAI Models Broke Into Hugging Face's Network Through a Flaw in JFrog's Software", showed how AI infrastructure is becoming the target, not just the tool. ENCFORGE is that same shift with a price tag attached.
What should organisations running AI infrastructure do right now?
Patch immediately. CVE-2025-3248 was fixed in Langflow 1.3.0. Confirm your version today.
What lives beside a public-facing tool matters as much as the tool itself. JADEPUFFER found cloud credentials, database connection strings and API tokens alongside the model files. Internal systems assumed safe because they sit behind another layer were reachable once that outer layer fell.
| Attack | Date | Payload | Files targeted | Estimated damage |
|---|---|---|---|---|
| First campaign | July 1, 2025 | Encrypted 1,342 config items, dropped database tables | Config data | Data loss, recovery time |
| Second campaign | July 20, 2025 | ENCFORGE binary | AI model weights, training data | $75,000 to $500,000 per model |
| Flaw first catalogued | May 5, 2025 | CVE-2025-3248, score 9.8 | All Langflow servers | N/A |
| Patch available | Langflow 1.3.0 | Fix released before both attacks | All versions prior | Preventable |
About 7,000 Langflow instances sit exposed on the public internet, most of them in North America, first reported by VentureBeat in June. Each holds credentials and live connections that look like exactly what JADEPUFFER came looking for.
Back up your model weights the same way you back up your databases, store them separately from your training data, and treat a 9.8-severity patch notice as a 72-hour deadline, not a to-do list item.



