Two stolen Azure identities gave one attacker control over an entire cloud tenant in June 2026. According to new research from Microsoft Security, the JADEPUFFER Azure attack wiped most of the storage accounts it targeted in about seven minutes. Microsoft tracks the agentic ransomware actor behind it as Storm-3168.
At a Glance
| Actor | JADEPUFFER, tracked by Microsoft as Storm-3168 |
| Activity | Destructive cloud attack and credential collection via compromised service principals |
| Targets | One Azure tenant (organization not named) |
| Scale | 100+ storage deletion attempts, 150+ destructive or credential operations in 35 minutes, 30+ storage keys collected |
| Status | No arrests or charges announced; no ransom note observed |
| Sources | Microsoft Security Research; Sysdig Threat Research Team |
TL;DR
Microsoft says a suspected AI-driven actor used compromised service principals to delete Azure resources. The same identity also collected storage keys that could enable later data theft. The activity fits ransomware tactics, but Microsoft saw no ransom note.
What Happened
Discovery Before Destruction
In early June 2026, the first service principal began mapping the victim’s Azure environment. It ran for about 15 and a half hours and logged more than 300 successful read operations. Roughly 90 minutes into that scan, a second service principal checked virtual machines across two subscriptions in five seconds. Both identities shared the same network fingerprint and the user agent python-requests/2.34.2.
A Seven-Minute Wipe
Next, the second identity turned destructive. It attempted more than 150 destructive or credential-related operations in 35 minutes. The deletion burst itself lasted about seven minutes. Most targeted storage accounts disappeared, along with a Key Vault, a Function App, and an App Service plan.
Some defenses held, though. Resource locks and deletion protection saved several storage accounts. Microsoft said this shows “the value of independent safeguards” when an identity holds broad admin rights. Attempts to delete Azure SQL databases also failed because the tool called an unsupported API version.
Credential Collection
About 30 minutes after the wipe, the same identity sent over 30 successful ListKeys requests. These calls returned access keys for storage accounts, including Azure Site Recovery storage.
Who Is Behind It
Sysdig first documented JADEPUFFER in July 2026. The firm described it as the first known agentic ransomware operation. In that earlier case, an AI agent reportedly exploited the Langflow flaw CVE-2025-3248. It then allegedly encrypted 1,342 Nacos configuration items and left an extortion note.
Microsoft ties the JADEPUFFER Azure attack to the same actor through shared infrastructure. The timing and token use “strongly indicates automated or scripted execution,” the report states. For example, researchers saw five tokens for one identity, and two deleted resources within the same 70-second window.
Possible Entry Point
One lead stands out. An employee had posted the service principal’s client ID, secret, and tenant ID in a public GitHub issue. The employee later edited the post. However, the secret stayed visible in the issue’s edit history. Microsoft stressed that it “could not confirm whether this secret was used.” The victim remains unnamed, and no law enforcement action has been announced.
Impact and Scale
The attacker went after backup-themed storage and recovery locks. As a result, Microsoft believes the goal may have been to block recovery. Taken together, these steps are “consistent with tactics that can support ransomware and extortion operations,” Microsoft wrote. Still, the company did not see a ransom note or confirm data theft.
How to Stay Protected
Microsoft recommends several steps for teams that want to avoid a similar cloud wipe:
- Revoke or rotate any secret that has appeared online. Deleting the post does not fix the leak.
- Apply least privilege to service principals and other workload identities.
- Protect recovery resources with resource locks and deletion protection.
- Enable relevant Microsoft Defender for Cloud protections.
Beyond that, defenders should watch for bulk ListKeys calls and sudden bursts of delete operations. Microsoft also argues that security teams will need AI tools of their own to keep pace with machine-speed intruders.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!