READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Microsoft Report: Hackers Deleted Over 100 Azure Accounts in About Seven Minutes, Only Pre-Set Locks Survived

Microsoft Report: Hackers Deleted Over 100 Azure Accounts in About Seven Minutes, Only Pre-Set Locks Survived
Microsoft's September 25 threat report on Storm-3168, tied to the JADEPUFFER group Sysdig first flagged in July 2026, shows attackers using stolen Azure service principals wiped more than 100 storage accounts plus a Key Vault, Function App and App Service plan in roughly seven minutes. The only things left standing were resources locked down before the attack started. A Sysdig researcher is pushing back on the "AI did it alone" framing, and that pushback deserves attention.

Microsoft published a detailed technical report on September 25, 2026, showing how fast an attacker can move once it holds valid cloud credentials. The number that matters: about seven minutes to destroy over 100 Azure storage accounts, a Key Vault, a Function App, and an App Service plan.

Microsoft tracks the actor as Storm-3168 and formally links it to JADEPUFFER, the group Sysdig first documented in July 2026. Researchers Yossi Weizman and Tushar Mudi, part of Microsoft Defender for Cloud, authored the report. This is the first detailed public look at how this crew operates inside Azure specifically.

The Timeline

The full campaign against the unnamed victim ran roughly 18 hours in early June 2026, according to The Hacker News. Two compromised service principals from the same tenant did the work. Service principals are non-human identities that applications use to talk to Azure, and they're a common target because nobody watches them the way they watch a human login.

The first service principal spent about 15 hours and 30 minutes quietly mapping the environment, running over 300 successful read operations across virtual machines, subscriptions, and resource groups, according to Microsoft's own report. Ninety minutes after that started, a second service principal did the same recon across two subscriptions in five seconds flat. Both used the same infrastructure, the same network fingerprint, and the identical user agent string python-requests/2.34.2.

Sixteen hours later, the second identity checked Azure App Service configuration stores, likely hunting exposed credentials, and unsuccessfully searched for OpenSearch resources. Seventy seconds after that, it requested keys for a storage account that didn't exist. Less than a second after that failed request, deletion began. Over the next 35 minutes the identity attempted more than 150 destructive or credential-related operations. The actual destruction of resources took about seven minutes.

What Survived, And Why

Only assets protected in advance made it through. Microsoft's report credits Azure resource locks and storage-level deletion protection, both of which have to be configured before an attack, not during one. Microsoft's own conclusion, stated plainly in its report: the defensive window "opens long before an attack, not during it."

SQL databases also survived, but according to the report, an important catch emerged. They weren't protected by permissions. Microsoft says the compromised identity had direct SQL DB Contributor access, which would have authorized every deletion attempt. The databases only survived because the attacker's requests hit an API version bug. A correctly formed request likely would have taken them down too.

One more detail nobody has fully explained: in the resource group where the Key Vault, Function App, and App Service plan got wiped out, a similarly named storage account was left untouched, according to Microsoft's report. Microsoft's writeup doesn't say why.

Where JADEPUFFER Came From

Sysdig first named JADEPUFFER on July 1, 2026, calling it the first documented ransomware operation run end-to-end by a large language model with no human at the keyboard during the active attack. That campaign exploited CVE-2025-3248, an unauthenticated remote code execution flaw in Langflow, an open-source LLM app framework. The vendor patched it in April 2025. CISA added it to its Known Exploited Vulnerabilities catalog the following month. The victim was still running an unpatched, internet-facing instance more than a year later.

In that first incident, the LLM agent encrypted 1,342 Alibaba Nacos configuration records using MySQL's built-in AES_ENCRYPT function, printed the encryption key once, and never stored it, according to The Hacker News. That means paying the ransom wouldn't have recovered anything. Three weeks later, Sysdig documented a second strain, ENCFORGE, a Go-based ransomware built specifically to hit AI infrastructure, scanning for nearly 180 file extensions covering model checkpoints, vector databases, training data, and embedding indices, plus macOS Keychain files and Apple Pages and Numbers documents.

Not Everyone Buys the Full "AI Did It" Story

Michael Clark, Sysdig's senior director of threat research, told CyberScoop that a human still set up and pointed the original operation, provisioned the infrastructure, and chose the victim. CyberScoop also reported the actor's origins are unknown and don't overlap with any established ransomware group or nation-state.

That distinction matters for how to read Microsoft's Azure report specifically. Sysdig's "agentic" label described what it saw in its own Langflow case, where the malware's self-narrating logs showed the LLM reasoning through its own steps in real time. Microsoft's Azure evidence shows extreme speed and automation, a sub-second gap between a failed key request and a flood of deletions. The report Microsoft published does not show that an AI model was making live decisions inside the Azure attack itself. Whether the Azure operation was autonomously agentic or just fast, pre-scripted automation pointed by a human remains an open question the public record doesn't settle.

A Separate Case, Same Pattern

Microsoft disclosed a different AI-linked operation this cycle: a subscription-based fraud platform called EvilTokens, introduced on a Telegram channel in February 2026 for a $1,500 setup fee plus $500 a month, according to Ars Technica. Its AI chatbot analyzed victims' inboxes to find trusted contacts and payment authorizations, then drafted impersonation emails to trick employees into wiring money. Microsoft said EvilTokens users compromised 12,000 accounts across 10,000 organizations worldwide, with the US hit hardest. Microsoft, working with security firm SpyCloud, seized 50 websites and 150 domains tied to the operation. The UK's Metropolitan Police arrested two men on suspicion of related offenses. This is a distinct case from Storm-3168, run through OAuth device-code abuse rather than cloud service principals, but it shows Microsoft is now fighting AI-assisted crime on multiple fronts simultaneously.

What Microsoft Is Telling Customers To Do

Microsoft's advisory is specific: protect workload identities and secrets, enforce least privilege, safeguard recovery resources, and turn on Defender for Cloud protections. The company also warned that publicly exposed credentials remain usable until they're actually revoked or rotated, removing the original leak from view does nothing.

Microsoft says it's building AI-assisted defense tools of its own, Project Perception and MDASH, aimed at letting defenders investigate and respond across large cloud environments without manually chasing every logged action. Whether those tools can close a seven-minute destruction window before it opens is the question Microsoft's own report leaves unanswered.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
Ars TechnicaMicrosoft disrupts AI-assisted platform that compromised 12,000 accounts
unknown
The Hacker NewsJADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
unknown
InfoSec TodayStorm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities
unknown
Tech TimesAI Ransomware Wiped 100 Azure Accounts in 7 Minutes: Only Pre-Configured Locks Survived - Tech Times
unknown
Security AffairsStorm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities
unknown
windowsforumStorm-3168 Azure Attack: Compromised Service Principals Delete Storage Accounts
unknown
microsoftStorm-3168: Agentic-driven cloud attacks using compromised service principals | Microsoft Security Blog