Microsoft Describes Azure DevOps Pipeline Abuse After Identity Compromise
Microsoft analyzed an incident attributed to Storm-3068 activity in which an attacker used an Azure DevOps pipeline to obtain kubeconfig files after taking over an account.

Storm-3068 Azure DevOps is the name of a case Microsoft published on September 29, 2026, in its DART report. According to the investigation, after compromising an identity, the attacker gained access to an Azure DevOps environment, where they created a malicious pipeline intended to collect kubeconfig files for Kubernetes clusters.
This is not an announcement of a new software vulnerability or the release of a product fix. Microsoft describes the case as an example of the risk created when a single user account connects identity in Microsoft Entra, a development environment, CI/CD processes and cloud infrastructure.
Storm-3068 Azure DevOps: The Path Through a Password Reset
According to Microsoft, the attacker gained initial access through a self-service password reset. They then registered their own authentication methods on the compromised account, preserving access even after the original entry.
In the Azure DevOps environment, they then enumerated repositories, projects, pipelines and deployment environments. This overview reportedly allowed them to identify a pipeline with access to sensitive resources and prepare their own pipeline to collect data.
Microsoft states that the created pipeline had permission to access more than 50 resources. According to the report, the attacker added seven stolen kubeconfig files to a repository. Such files commonly contain configuration and access credentials used by clients when communicating with a Kubernetes cluster.
Atera and Chisel Also Appeared in the Incident
Atera and Chisel were also used in the analyzed case. According to Microsoft, Chisel created a reverse tunnel to an external IP address. However, the public material does not confirm that the attacker successfully obtained interactive access to Kubernetes clusters or exfiltrated data from them or other systems.
Microsoft did not disclose the identity of the affected organization, its industry or the scope of the incident’s impact. The technical account is therefore based on Microsoft’s findings from its incident investigation; the materials contain no independent confirmation of the details of this specific case.
Recommendations for Identity and CI/CD
Microsoft recommends monitoring password resets, particularly for accounts with elevated permissions, and paying attention to registrations of new multifactor authentication methods. The recommendations also include phishing-resistant MFA, meaning multifactor authentication that is more resistant to phishing.
For Azure DevOps, the company recommends protecting repository branches, restricting pipeline permissions and applying the principle of least privilege. The practical goal is to ensure that a compromised account or modified pipeline does not automatically have broad access to production resources and credentials.
Storm-3068 is a designation used by Microsoft. In its taxonomy, names such as Storm are used for unknown, emerging or developing activity, so the published information does not confirm the actor’s origin or broader identity.
Further information may come from any new technical or attribution findings by Microsoft and other security companies. For now, this is a specific case study, not a confirmed mass campaign.
Sources
- Microsoft Security Blog – Microsoft’s summary of the incident, a description of the attacker’s methods and recommended defensive measures.
- Microsoft Incident Response – Cyberattack Series Part 3 – Technical details about the password reset, Azure DevOps pipelines, kubeconfig files, Atera, Chisel and the scope of the pipeline’s permissions.
- How Microsoft names threat actors – Explains that Storm designations are used for unknown, emerging or developing activity.
Verified and updated: 09/30/2026 06:27



