Someone Paid the Ransom and Got Nothing Back: What JadePuffer Means for Your Backup Strategy
A new strain of ransomware called JadePuffer never stores the keys needed to decrypt your files, so paying achieves nothing. Here's why immutable, tested backups are now your only real route back.
A manufacturing firm in the East Midlands paid a ransom of just over £40,000 last quarter. They sent the cryptocurrency, waited the promised two hours, and received a decryption tool from the attackers. It ran for a while, then failed. They ran it again. It failed again. When they finally got a security specialist involved, the answer was blunt: the tool was never going to work, because the key it needed had never existed in a form anyone could hand back.
That firm had been hit by a strain that security researchers have started calling JadePuffer. It has picked up a lot of coverage because it uses machine learning to decide which files to encrypt first and how to spread across a network. The headlines have leaned hard into the AI angle, and that's understandable — it makes for a dramatic story. But the AI part is not the thing that should worry you. The thing that should worry you is much simpler, and it changes how you think about recovery entirely.
The detail that actually matters
Most ransomware, historically, has worked on a rough bargain. The attacker encrypts your files with a key, keeps that key on their own infrastructure, and sells it back to you. It's extortion, but it's a transaction. Enough victims got their data back over the years that a grim sort of market grew up around it. Paying was a bad idea, but it was sometimes a working idea.
JadePuffer breaks that bargain. It generates encryption keys on the infected machine, uses them, and then discards them. The keys are never sent home to a server the attackers control. They are never written to disk in any recoverable way. Once the encryption is done, the key is gone — not hidden, not held for ransom, but genuinely destroyed.
So when the ransom note demands payment for a decryption tool, the note is lying. There is no tool that can reverse the damage, because the information needed to reverse it no longer exists anywhere on Earth. The attackers are collecting money for something they cannot deliver, and in many cases they know it.
Why would anyone build ransomware that can't be paid off? A few reasons. It's simpler to write, because you strip out all the key-management infrastructure. It's harder to trace, because there's no command-and-control server quietly storing keys for investigators to find. And for some groups, the goal was never really the money — it's disruption, and the ransom note is just a way to waste more of your time.
What this does to the 'should we pay?' question
For years, the advice around paying has been a moral and legal one. The National Crime Agency and the ICO both discourage it. It funds criminal activity, it marks you as a soft target, and depending on who the attackers are, paying could put you on the wrong side of sanctions law.
Those arguments still stand. But JadePuffer adds a colder, more practical one on top: with this kind of malware, paying does not even work. You are not weighing a bad option against a worse one. You are handing money to someone who cannot help you, and then you are still stuck at square one — except poorer, and with the clock still running.
The East Midlands firm learned this the hard way. Their four days of downtime became eight, because they spent the first stretch waiting on a fix that was never coming. Every hour they lost to that false hope was an hour they weren't spending on the one thing that could actually get them running again.
The only route back is the one you built beforehand
Here is the uncomfortable conclusion. If the key is gone and there's no one to pay, your recovery depends entirely on having a clean copy of your data somewhere the attacker couldn't touch. That's it. There is no clever tool, no negotiation, no specialist who can conjure the files back. Backups are not a nice-to-have safety net any more. They are the whole plan.
And not just any backups. Plenty of the businesses we speak to are quietly confident because they 'have backups', only to discover during an incident that those backups were sitting on the same network the ransomware swept through, or were so old that restoring them means losing a fortnight of work. A backup that gets encrypted alongside everything else is not a backup. It's a second copy of the problem.
Three things separate a backup that saves you from one that doesn't.
Immutability. An immutable backup cannot be altered or deleted for a set period, even by someone with full admin credentials. This matters because modern ransomware actively hunts for backups and tries to wipe them before it triggers the encryption — the attackers know that a good backup is the only thing standing between them and a payday. Immutable storage means that even if the malware reaches your backup system, it can look but it cannot touch. Most reputable cloud backup services now offer this, sometimes called object lock or write-once-read-many storage. If yours doesn't, that's a conversation worth having this week.
Separation. Your backups need to live somewhere that isn't reachable from your day-to-day network using everyday credentials. The old rule still holds well: three copies of your data, on two different types of media, with one kept off-site or offline. That offline or air-gapped copy is your last line of defence when everything else has been compromised.
Testing. This is the one almost everyone skips, and it's the one that catches people out. A backup you have never restored from is a guess, not a guarantee. We regularly run restore tests for clients and find corrupted files, missing databases, or backup jobs that silently stopped working months ago. The middle of a live incident is the worst possible moment to discover your restore process doesn't do what you assumed. Test it on a quiet Tuesday instead, on a schedule, and document how long a full restore actually takes. That number is your real recovery time, and it's usually longer than people expect.
What to do next
You don't need to panic about JadePuffer specifically. Strains come and go, and the AI features that made the news will be old hat within a year. What won't change is the underlying shift: a growing share of attacks make payment pointless by design. Planning around the assumption that you can buy your way out is planning to lose.
So take an hour and answer three questions honestly. Are your backups immutable, so an attacker with admin rights can't destroy them? Are they separated from your main network, so ransomware can't reach them in the first place? And have you actually restored from them recently enough to trust that they work?
If you can't answer all three with a confident yes, that's your priority. The firm that paid £40,000 for nothing would give a great deal to have had that hour back. You still have it. Use it before someone decides to take the decision out of your hands.
If you'd like a second pair of eyes on your current setup, that's exactly the sort of review we do. It's a lot cheaper than finding out the hard way.
