Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

JadePuffer Azure attacks used compromised cloud identities to delete resources in minutes

Microsoft says an agent-driven operation used compromised service principals to mass-delete cloud storage, and that simple resource locks blunted part of the damage.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Microsoft tracks the JadePuffer-linked actor as Storm-3168 and says it abused compromised Azure service principals in June 2026 attacks.
  • 2In a seven-minute destructive burst it attempted more than 100 storage account deletions and removed a Key Vault and other resources.
  • 3One identity's credentials had been posted in a public GitHub issue, though Microsoft could not confirm they were used; it says exposed secrets stay dangerous even after deletion.

The news

Microsoft (MSFT) on September 25 detailed JadePuffer Azure attacks in which an actor it tracks as Storm-3168 used compromised cloud identities to map, then destroy, customer resources. Microsoft said the timing and division of work strongly indicated automated or scripted execution, with the core destructive phase lasting minutes.

Security firm Sysdig first identified JadePuffer in July 2026, and Microsoft's post credits Sysdig with calling it the first documented agentic ransomware operation, meaning attacks in which AI agents carry out steps with limited human direction. Microsoft said its research gives the first detailed view of the group's activity in Azure, Microsoft's cloud platform. Microsoft said the activity involved two compromised service principals in the same Azure tenant.

The intrusions abused service principals, the non-human identities that applications and automation use to access Azure. Microsoft said it is unclear how one service principal was first compromised, though its client ID, secret and tenant ID had been posted in plain text in a public GitHub issue by an employee; Microsoft could not confirm that secret was used. The issue was later edited, but the secret stayed visible in its public edit history, and Microsoft stressed that deleting or redacting an exposed secret does not invalidate it.

Microsoft described a slow start and a fast finish. In early June, a first service principal performed more than 300 successful read operations over more than 15 hours, listing virtual machines, subscriptions and resource groups. A second service principal then ran discovery across two subscriptions in five seconds. The core destructive sequence lasted about seven minutes and included more than 100 attempts to delete storage accounts, most of which succeeded, along with deletion of a Key Vault, a Function App and an App Service plan.

Roughly 30 minutes later, the attackers issued more than 30 successful requests to list storage account keys, including accounts tied to Azure Site Recovery, Microsoft said. Attempts to delete SQL databases failed because of unsupported API versions. Azure resource locks and storage-level deletion protection blocked deletion of some storage accounts, and locks on Site Recovery and Azure Backup resources resisted repeated attempts.

The Register, citing Microsoft researchers Yossi Weizman and Tushar Mudi, reported that investigators found no ransom note and no confirmed data theft. The researchers concluded that the focus on backup and recovery systems was consistent with tactics that can support ransomware and extortion.

The numbers

Reconnaissance read operations
More than 300
Length of core destructive sequence
About 7 minutes
Storage account deletion attempts
More than 100
Successful storage key listing requests
More than 30
Subscriptions enumerated in five seconds
2

Why CEOs should care

For CISOs and cloud leaders, the risk Microsoft flagged is ordinary, though unconfirmed as the entry point here: a secret pasted where the public could see it. Microsoft's guidance is to treat any credential that has been publicly exposed as compromised, even if the post was later edited or deleted, and to rotate it immediately. Security teams should scan public repositories, issue trackers and forums for company secrets, and move workload identities toward managed identities or certificate-based credentials that are harder to leak.

The attack also exposes the risk of overprivileged non-human identities. A service principal that can delete storage accounts, Key Vaults and app services across subscriptions is a master key. Ask engineering leaders for an inventory of service principals, what each can delete, and when each secret was last rotated. Least-privilege scoping, which Microsoft recommends, limits what a stolen identity can do.

For CFOs and boards, the most useful detail may be what worked. Resource locks and deletion protection, inexpensive settings that require an extra step before anything is removed, saved some data. Ask whether production storage, backups and disaster-recovery resources carry such locks, and whether backup systems can be deleted with the same credentials that run daily operations.

The bigger picture

Storm-3168 shows how automation changes response time. Reconnaissance took hours, but destruction took minutes, leaving little room for human intervention once deletion began. BleepingComputer, citing Sysdig, reported that the group later widened its focus to AI assets, training datasets and vector databases, the stores that feed enterprise AI systems.

Microsoft recommends enabling Defender for Cloud protections for Resource Manager, storage, Key Vault, App Service and databases, and protecting backup and recovery infrastructure, alongside its own agentic defense tools. Rival cloud providers face the same identity problem, since service accounts and API keys are the common currency of automated infrastructure.

What’s next

Watch for further research from Microsoft and Sysdig on Storm-3168 tooling and targets, and for signs that similar agent-driven playbooks appear in AWS or Google Cloud environments. Organizations should run a secrets-exposure review and confirm deletion protection on critical resources before the next incident, not after.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

MicrosoftJadePufferAzureCloud security

Earlier coverage of Microsoft

All Microsoft coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.