Compromised Machine Logins Deleted a Company's Cloud Storage in Seven Minutes, Microsoft Says

On Sept. 25, Microsoft Security Research published an account of an Azure intrusion in which two compromised service principals, the machine identities applications use to sign in to cloud services, were used to inventory a customer's tenant and then delete more than 100 storage accounts.
Microsoft reports that Azure resource locks and storage-account deletion protection blocked deletion attempts on a few of the accounts. Microsoft describes this as evidence that independent safeguards stay effective even when a compromised identity has broad administrative permissions. The company's guidance to organizations is to protect the credentials their applications use, give those applications only the permissions they need, and lock down backup and recovery resources.
The figures come from Microsoft's own investigation of its own platform. Microsoft says that in early June 2026 the first compromised identity enumerated virtual machines, subscriptions, resource groups and resources for about 15 and a half hours, with more than 300 successful read operations. The second identity later attempted more than 150 destructive or credential-collection operations in 35 minutes. The destruction itself lasted about seven minutes, and most of the storage accounts it targeted were deleted. Attempts to delete Azure SQL databases all failed because the requests used an unsupported API version. The same identity then sent more than 30 successful requests for storage-account access keys.
Microsoft attributes the activity to a group it tracks as Storm-3168. Sysdig, which documented the group as JADEPUFFER in July 2026, reported it as the first documented agentic ransomware operation. Microsoft says the timing of the operations and the division of work between the two identities strongly indicate automated or scripted execution, an inference it states rather than confirms. Microsoft adds that it saw no ransom note and confirmed no data theft.
Microsoft says it is unclear how the identities were compromised, and that any credential exposed in a public place should be treated as compromised and revoked, because taking down the original post does not remove the exposure.
