JADEPUFFER Attackers Wipe Azure Resources via Compromised Service Principals

In June 2026, the threat group known as JADEPUFFER, tracked by Microsoft under the alias Storm-3168, carried out a destructive cloud attack on Microsoft Azure using compromised service principals.

How the Attack Unfolded

The campaign began with one service principal used for reconnaissance and resource mapping, and a second one used to carry out destructive activity and steal credentials. Over roughly 18 hours, the attackers probed Azure tenants—viewing virtual machines, resource groups, and subscription settings—logging over 300 read operations.

After a period of touring the environment, the attack pivoted to destruction. Within a span of about seven minutes, the threat actor attempted more than 100 deletion operations targeting storage accounts, an Azure Key Vault, Function App, App Service plans, SQL databases, and Azure VM resources. Many storage accounts were successfully deleted; key protective mechanisms—resource locks and deletion protection—blocked others. SQL database deletion largely failed due to using an outdated API version.

Root Cause & Broader Context

Microsoft’s investigation suggests that the service principal credentials (client ID, client secret, tenant ID) were exposed publicly via a GitHub issue by an employee. Though the secret was removed later, its exposure lingered in Git history.

This attack dovetails with JADEPUFFER’s prior activity—including a ransomware operation that used AI to automate every stage, from exploiting a vulnerability in Langflow to encrypting infrastructure, dropping databases, and dropping a ransom note demanding Bitcoin. A related strain called ENCFORGE was later used by the same threat group to target AI infrastructure and files relevant to models, datasets, checkpoints, and common development environments.

What It Means for Cloud Security

This incident marks a shift: attackers are now combining identity compromise, automation, and rapid destructive operations in the cloud. The use of service principals with broad permissions, the exposure of credentials, and the move from reconnaissance to rapid widescale destruction show just how high the stakes have become.

Key vaults, storage accounts, resource locks, and deletion protection matter—defenses that reduce risk even when identities are compromised. Microsoft did not observe data exfiltration or a ransom demand in this attack, but the coordinated deletion of backup-related or recovery infrastructure indicates the objective was to cripple recovery.

For organizations using Azure or any cloud provider: closely audit permissions granted to identities or service principals, monitor sources of credentials, and ensure history or edit logs do not leak secrets. Defensive tools like resource locks and deletion protection are no longer optional—they’re essential buffers.

Analysis:This event signals a rising norm of attackers treating cloud environments as battlefields, not just data stores. The automation of post-compromise activity—with AI-linked groups like JADEPUFFER tying reconnaissance, credential theft, and then fast-moving destruction—raises the urgency for cloud security hygiene. Going forward, organizations must assume that any exposed credential may be used for rapid escalation. We’re entering an age when identity-centric defenses and layered protection (like deletion protection, versioning, and resilient backup architecture) are the difference between a minor breach and total operational loss.