🔐
Security 📅 2026-07-21 · 09:39 AM IST ⏱ 3 min read

Hackers Deploy New Ransomware Targeting AI Systems Through ServiceNow Vulnerability

Attackers exploiting ServiceNow flaw to install AI-focused ransomware that destroys machine learning models and data.

A New Threat Emerges in the AI Security Landscape

Security researchers have uncovered a troubling trend: criminals are actively exploiting weaknesses in ServiceNow, a widely-used business management platform, to break into systems and install specialized ransomware designed specifically to attack artificial intelligence infrastructure. What makes this particularly concerning is that attackers don't need valid login credentials to gain access—they're using an unauthenticated flaw, meaning anyone on the internet can potentially exploit it.

The investigation traced these attacks back to a group called JADEPUFFER, which operates AI-powered tools to automate their hacking operations. Rather than demanding money to unlock traditional business files, this new ransomware variant—dubbed ENCFORGE—focuses on something far more valuable in today's economy: the mathematical models and databases that power machine learning systems. Think of it like stealing the blueprints from a factory rather than just locking the doors.

Understanding the Technical Landscape

ServiceNow functions as a central nervous system for many enterprises, managing everything from IT operations to customer service workflows. When a critical vulnerability exists in such a system, it becomes an attractive entry point for sophisticated attackers. The fact that no authentication is required amplifies the risk exponentially—it's the digital equivalent of leaving a front door not just unlocked, but wide open to the street.

The use of Go programming language for ENCFORGE suggests attackers built this tool to be lightweight and efficient, capable of running across different operating systems. The specific targeting of AI model weights and vector indexes indicates a deliberate strategy: destroy the actual intelligence within AI systems, not just the company's general data.

What This Means for Your Organization

If your company relies on ServiceNow, you're potentially exposed. This isn't a theoretical risk—actual attacks are happening right now. Organizations using AI systems for critical business functions face an especially acute threat. Unlike traditional ransomware that simply locks files, an attack on AI infrastructure could corrupt the sophisticated models companies have spent months or years training, making them useless overnight.

The involvement of JADEPUFFER, an operator known for sophisticated techniques, signals this isn't opportunistic hacking. This represents coordinated, well-resourced attacks targeting high-value systems.

Immediate Steps You Should Take

The Bigger Picture

This situation reflects a broader shift in cybercrime: as AI becomes central to business operations, criminals are adapting their tactics to target these new crown jewels. Organizations that treat AI security as an afterthought are walking into a trap.

The window for action is narrow—patch your systems today and assume attackers are actively scanning for vulnerable instances right now.

📎 This is original ITVedas reporting. This story was inspired by coverage from source. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →