Microsoft has documented a destructive Azure intrusion linked to the threat actor it tracks as Storm-3168, also known as JADEPUFFER. The attackers used two compromised service principals inside one tenant to enumerate resources, collect credentials and attempt to delete cloud services. Microsoft said the activity occurred in early June 2026 and unfolded over roughly 18 hours.
Cloud identities enabled broad destructive actions
One service principal performed prolonged reconnaissance while another carried out more than 150 destructive or credential-related operations in about 35 minutes. Targets included storage accounts, virtual machines, Key Vault, Function Apps, App Services and Azure SQL databases. Most targeted storage accounts were deleted, while resource locks and deletion protection blocked some attempts.
Microsoft found that credentials for one service principal had previously been exposed in a public GitHub issue. Although the secret was later removed, it remained visible in the issue history. The company assessed the operation as ransomware-aligned, but reported no ransom note or confirmed data exfiltration.
Independent recovery controls limited damage
Organizations should rotate exposed application secrets, restrict service-principal privileges and alert on unusual resource enumeration or deletion. Recovery safeguards should be administratively independent from identities that manage production resources. SectechMedia follows related risks in its cybersecurity coverage.

Leave a Reply