Microsoft’s September 25, 2026 report describes activity in an unnamed Azure tenant in early June: two compromised service principals carried out reconnaissance, resource destruction and credential collection. The destructive sequence lasted about seven minutes and included more than 100 attempted storage-account deletions; most targeted accounts were deleted, while configured protections blocked some attempts. Microsoft says the activity strongly indicated automated or scripted execution.

Two service principals handled different stages

A service principal is an identity that an application or workload can use to access Azure resources. Microsoft reported that one compromised principal spent about 15 hours and 30 minutes enumerating virtual machines, subscriptions, resource groups and other resources, completing more than 300 successful read operations.

About 90 minutes after that reconnaissance began, the second principal enumerated virtual machines and resource groups across two subscriptions in five seconds. It then attempted more than 150 operations related to destruction or credential collection over a 35-minute period. The concentrated destructive sequence took about seven minutes.

The activity also deleted an Azure Key Vault, a Function App and an App Service plan. About 30 minutes after the final destructive activity, the second principal made more than 30 successful ListKeys requests for storage-account keys.

Microsoft’s findings point to automation

Microsoft said the timing, division of work and overlapping token activity strongly indicated automated or scripted execution. Both principals used the user-agent string python-requests/2.34.2, along with a shared network fingerprint and infrastructure associated with Storm-3168. For the principal involved in destruction and key collection, Microsoft observed five unique tokens: four supported deletion, while one handled storage inventory and key retrieval. Two deletion tokens were active at the same time for 70 seconds.

Microsoft tracks the activity as Storm-3168 and associates it with JADEPUFFER. Its account describes automated or scripted activity; it does not attribute the Azure operations to a specific AI model.

Configured protections blocked some storage deletions

Microsoft reported that resource locks and storage-account-level deletion protection blocked attempts against some storage accounts. The targeted accounts were not all protected from deletion: most were successfully deleted.

Attempts to delete Azure SQL databases failed because the activity used an unsupported API version for that resource type. The same activity also made unsuccessful attempts to delete Azure Site Recovery locks and Azure Backup protection locks.

The possible credential exposure

Microsoft reported that a public GitHub issue had contained a service principal’s client ID, client secret and tenant ID. Although the issue was edited, its public edit history retained the secret. Microsoft could not confirm that the exposed credential was used to gain access in this incident and recommends revoking or rotating credentials exposed publicly.

Microsoft described the destructive activity, targeting of recovery controls and credential collection as consistent with tactics that can support ransomware and extortion. It observed no ransom note and did not confirm successful data exfiltration.