cybersecurity디지털투데이 (DigitalToday)· 7/28/2026, 7:16:25 AM9.0

Ransomware Targeting AI Models Emerges... Concerns Over Surge in Recovery Costs as Learning Weights Are Encrypted

Sysdig reported that the same attacker breached an exposed Langflow server twice, using the specialized ransomware 'ENCFORGE' targeting AI models in the second attack. The first breach occurred on July 1, 2026, and the second on July 20, both exploiting the CVE-2025-3248 vulnerability (CVSS 9.8) to execute arbitrary Python code. The second attack evolved beyond data deletion, encrypting AI assets directly. ENCFORGE, designed specifically for AI environments, encrypts PyTorch/TensorFlow checkpoints, Hugging Face SafeTensors, GGUF models, FAISS indices, Parquet/NumPy data, and more. Sysdig attributed the attack to JADEPUFFER, which focused on disabling corporate AI assets rather than financial gain. The ransomware lacked data exfiltration capabilities and used AES-256-CTR to rapidly damage large models. Recovery costs could reach $75,000-$500,000 for rebuilding a fine-tuned model, with costs escalating if training data is also compromised. Attackers bypassed Docker containment by generating Python scripts via Langflow within five minutes. Security experts noted automation reduced response times, exacerbating damage. The vulnerability was listed in CISA's KEV list since May 2025, but affected servers remained unpatched for over 14 months.

💡 AI analysis: The emergence of AI-specific ransomware like ENCFORGE makes the establishment of specialized integrity verification systems for model weights and core AI assets a critical necessity beyond traditional data protection.
View original (디지털투데이 (DigitalToday)) →