Back to News
Cybersecurity

New Ransomware ENCFORGE Targets AI Infrastructure in Langflow Attacks

Researchers reveal ENCFORGE ransomware's specific targeting of AI model files in recent Langflow server attacks.

Recent findings from Sysdig highlight the emergence of ENCFORGE, a new ransomware variant deployed by the JADEPUFFER operator, which specifically targets AI model files and related infrastructure. This ransomware is designed to encrypt critical assets such as model weights, vector indexes, and training datasets, posing significant risks to organizations relying on AI technologies. This marks a worrying trend in cyber threats, as the focus shifts towards compromising AI systems that are central to many businesses' operations.

The implications for businesses are profound, as the encryption of AI-related files could halt operations, lead to data loss, and result in significant financial and reputational damage. Organizations must prioritize the security of their AI infrastructures, implementing robust cybersecurity measures to protect against such targeted attacks. This situation underscores the urgent need for enhanced vigilance and proactive threat mitigation strategies in the evolving landscape of cybersecurity, particularly as adversaries increasingly recognize the value of AI resources as high-value targets.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html)*