Storm-3168 in Azure Used Compromised Application Identities to Delete Resources
Microsoft described an attack in one Azure tenant where compromised service principals were used for reconnaissance, attempts to delete resources, and obtaining access keys.

Storm-3168 in Azure, according to Microsoft, used two compromised service principals in a single compromised tenant. The attackers performed reconnaissance of cloud resources, attempted to delete storage accounts, and obtained access keys for storage. Microsoft did not observe a ransom demand and did not confirm successful data exfiltration.
A service principal is an application identity used by services, automation, or applications to access Azure. Unlike a regular user account, it often does not require interactive sign-in. If such an identity has extensive Azure RBAC permissions and its secret is exposed, it can be used to carry out extensive actions in the environment.
Storm-3168 in Azure: Reconnaissance, Deletion, and Keys
On September 25, Microsoft said it had recorded activity associated with the Storm-3168 actor in a compromised tenant. Two service principals were used. According to the company, the attackers first identified available Azure resources and then made more than 100 attempts to delete storage accounts.
They also deleted a Key Vault, Function App, and App Service plan. Attempts to delete Azure SQL databases failed because the API version used did not support these operations. Resource locks and delete protection stopped some attempts to delete storage accounts.
More than 30 successful ListKeys requests followed the destructive phase. These are used to obtain storage account keys. Such keys can expand access to data stored in the respective accounts if other settings do not restrict that access.
Public Secret Was Not Confirmed in the Incident
Microsoft said it could not confirm a connection between the described incident and a client secret that was publicly exposed in the history of a GitHub issue. Removing the secret from a public location does not by itself resolve the compromise if it has already been copied. It must be revoked or replaced.
The activity is also associated with the designation JADEPUFFER. In its characterization of the activity as “agentic-driven,” Microsoft builds on an earlier analysis by Sysdig. However, it has not been independently confirmed publicly that the specific Azure attack was fully autonomously controlled. The motive has likewise not been confirmed: the activity is compatible with ransomware or extortion, but Microsoft did not record a ransom demand or confirmed data theft in this activity.
This Is Not a Vulnerability with a Patch
The case does not describe a new Azure vulnerability for which a security update is available. The core issue is a compromised application identity and the extent of its permissions. Microsoft recommends immediately revoking or rotating publicly exposed secrets, restricting workload identity permissions to the minimum necessary, and protecting backup and recovery resources.
Administrators should also monitor for possible attempts to delete recovery locks or bypass backup protection, as well as unusual Azure Resource Manager operations from suspicious IP addresses. It is important to review which service principals have permission to delete resources or read storage account access keys.
What to Watch Next
Further developments may bring confirmation of additional victims, possible exfiltration, or ransom demands associated with Storm-3168. Any new indicators of compromise and detection rules usable outside Microsoft security products will also be important.
Sources
- Microsoft Security Blog – Microsoft’s primary announcement about the observed Azure activity, affected resources, unverified initial access, absence of confirmed exfiltration, and recommended mitigations.
- Sysdig Threat Research – An earlier research report that Microsoft references in connection with the JADEPUFFER designation; it documents Sysdig’s assessment that the observed ransomware operation was controlled by an LLM agent.
Verified and updated: September 26, 2026 15:24



