Cover: AI-generated editorial composition by TMRW. Incident details come from Microsoft Security Research; BleepingComputer first brought the report to our attention.
Two compromised service principals were enough for an attacker Microsoft tracks as Storm-3168 to map an Azure tenant, collect storage keys, and launch a destructive run across more than 100 storage accounts. The wipe stage lasted seven minutes.
Security researchers also call the operation JadePuffer. The AI story is not that a model invented a magical cloud exploit. It is that an agent compressed reconnaissance and destructive administration into machine-speed operations using credentials that already had too much authority.
The identities were the breach path
Service principals are non-human identities used by applications and automation. Microsoft observed two belonging to the same tenant. One mapped resources. The other performed discovery, credential collection, and deletion. Credentials for one appeared in a public GitHub issue before the attacks; Microsoft could not determine the full initial-access path.
The operator retrieved storage account keys, targeted Key Vaults, Function Apps, virtual machines, and App Services, and tried to remove backup and recovery protections. Attempts to delete Azure SQL databases failed because the attacker used an unsupported API version. About half an hour after the wipe, the operator returned and made more than 30 requests for storage keys.
Resource locks bought time
Most targeted storage accounts were deleted, but some survived because resource locks and account-level protections blocked the operation. That is the cleanest lesson in the report. A control enforced by the platform can stop a credentialed identity even when that identity is moving quickly and correctly through the API.
Backups that share the same administrative path are not a recovery plan. Protect vaults and storage with separate identities, immutable policies, and locks that routine automation cannot remove. Alert on attempts to disable those controls, not only on successful deletion.
Defenders need an agent-speed response
Seven minutes is shorter than most human escalation chains. High-risk sequences—enumerate all resources, fetch account keys, remove recovery locks, delete at scale—should trigger automated containment. Disable or isolate the service principal, preserve logs, and block destructive API calls while an operator investigates.
Review service-principal permissions as aggressively as employee accounts. Remove standing owner rights, rotate leaked secrets, prefer managed identities, and scan public repositories for credentials. Inventory which non-human identities can delete data or change recovery settings.
Microsoft did not confirm financial demands or data theft in the observed cases, so calling the incident ransomware would go beyond the evidence. What is established is more operationally useful: an attacker used compromised cloud identities and agentic automation to turn excessive permission into rapid destruction. The defense is not a better warning banner. It is authority that remains narrow even when commands arrive at machine speed.



