Skip to content
See the World Through ScienceA project of ALLATRA

Compromised Machine Logins Deleted a Company's Cloud Storage in Seven Minutes, Microsoft Says

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Close-up of rows of hot-swap disk drives in an enterprise storage array, with blue activity lights along each row.
Hot-swap disk drives in an enterprise storage array (illustrative). Microsoft says more than 100 storage accounts in a single Azure tenant were deleted in about seven minutes."IMG_1317" by Jemimus, via flickr, CC-BY-2.0

On Sept. 25, Microsoft Security Research published an account of an Azure intrusion in which two compromised service principals, the machine identities applications use to sign in to cloud services, were used to inventory a customer's tenant and then delete more than 100 storage accounts.

Microsoft reports that Azure resource locks and storage-account deletion protection blocked deletion attempts on a few of the accounts. Microsoft describes this as evidence that independent safeguards stay effective even when a compromised identity has broad administrative permissions. The company's guidance to organizations is to protect the credentials their applications use, give those applications only the permissions they need, and lock down backup and recovery resources.

The figures come from Microsoft's own investigation of its own platform. Microsoft says that in early June 2026 the first compromised identity enumerated virtual machines, subscriptions, resource groups and resources for about 15 and a half hours, with more than 300 successful read operations. The second identity later attempted more than 150 destructive or credential-collection operations in 35 minutes. The destruction itself lasted about seven minutes, and most of the storage accounts it targeted were deleted. Attempts to delete Azure SQL databases all failed because the requests used an unsupported API version. The same identity then sent more than 30 successful requests for storage-account access keys.

Microsoft attributes the activity to a group it tracks as Storm-3168. Sysdig, which documented the group as JADEPUFFER in July 2026, reported it as the first documented agentic ransomware operation. Microsoft says the timing of the operations and the division of work between the two identities strongly indicate automated or scripted execution, an inference it states rather than confirms. Microsoft adds that it saw no ransom note and confirmed no data theft.

Microsoft says it is unclear how the identities were compromised, and that any credential exposed in a public place should be treated as compromised and revoked, because taking down the original post does not remove the exposure.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Compromised Machine Logins Deleted a Company's Cloud Storage in Seven Minutes, Microsoft Says

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.