New Ransomware Targets AI Model Weights, Fails to Collect Ransom
A sophisticated ransomware variant, dubbed ENCFORGE by Sysdig's Threat Research Team, has been identified targeting trained AI model weights. The same attacker breached an internet-facing Langflow server twice, first on July 1 and again on July 20, 2026, exploiting a critical authentication flaw (CVE-2025-3248). While the initial attack involved encrypting configuration items, the second deployed ENCFORGE, specifically designed to target AI assets like PyTorch, TensorFlow, Hugging Face SafeTensors, GGUF, and FAISS vector indexes. This ransomware is notable for its explicit focus on AI model files, unlike generic ransomware that might incidentally encrypt them. Michael Clark of Sysdig highlighted that the objective is to destroy an organization's unique AI assets, which are difficult to restore. Notably, ENCFORGE lacks network exfiltration capabilities, a payment portal, or a leak site, indicating its primary function is destruction rather than extortion. The ransomware encrypts files using AES-256-CTR with an embedded RSA-2048 key, a method designed for rapid damage to large files. The estimated cost to rebuild a fine-tuned AI model ranges from $75,000 to $500,000, a figure that could resonate with business risk assessments. Official guidance from agencies like the NSA, CISA, and FBI has focused on data supply chain integrity and data trustworthiness, but ENCFORGE's attack vector directly challenges the existence of these models. The attacker demonstrated rapid adaptation, developing an escape mechanism within minutes when the initial ransomware deployment failed. This campaign exploited known vulnerabilities and misconfigurations, including an exposed Docker socket, indicating a reliance on routine security weaknesses. The Langflow server, with approximately 7,000 exposed instances globally, holds sensitive credentials and connections to AI data stores, making it a prime target.
This incident highlights a significant evolution in ransomware tactics, shifting focus from data exfiltration and financial extortion to the direct destruction of valuable, difficult-to-replicate AI model assets. The attacker's ability to rapidly adapt and deploy specialized ransomware, coupled with the exploitation of known, unpatched vulnerabilities, underscores the persistent challenges in securing complex, interconnected cloud environments. The lack of a ransom collection mechanism suggests a potential shift towards disruptive cyber warfare or state-sponsored sabotage, aiming to cripple an organization's AI capabilities rather than profit directly. This necessitates a re-evaluation of cybersecurity strategies to prioritize the integrity and resilience of AI training data and model weights, treating them as critical infrastructure with distinct recovery and protection requirements. The incident also exposes a gap between current threat landscapes and official guidance, emphasizing the need for proactive defense mechanisms that anticipate novel attack vectors targeting emerging technologies.
AI-generated to prompt reflection — not editorial opinion, not advice, not a statement of fact. How this works.