Skip to main content
MicrosoftSecurity incident

JadePuffer crims hijacked Azure identities and used them to blow up cloud resources

What happened

Microsoft reported that the cybercriminal group Storm-3168 (also known as JadePuffer) hijacked two Azure service principals within a single customer's cloud tenant to destroy over 100 Azure Storage accounts and other cloud resources in a destructive attack.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

security Smells like more agentic ransomware, Redmond warns The cyber criminal behind JadePuffer, the first known agentic ransomware infection reported over the summer, has also used stolen Azure identities to conduct destructive attacks on cloud storage and other resources, according to Microsoft. In July, Sysdig threat hunters uncovered JadePuffer, the first-ever documented agentic ransomware infection in which an LLM drove the entire extortion operation, from gaining initial access to compromising a production database server and destroying data. Now Redmond says that it has detected the same attacker, which it tracks as Storm-3168, up to new mischief. Over an 18-hour period in early June, Storm-3168 compromised two service principals and used these machine identities for "extensive Azure-focused resource destruction" and "cloud credential collection that could be used to facilitate future exfiltration," researchers Yossi Weizman and Tushar Mudi wrote on Friday. The two compromised service principals belonged to the same cloud tenant. The crims used one of them to conduct reconnaissance and resource discovery, and the other to carry out destructive operations and credential collection. The Redmond researchers don't know how Storm-3168 initially hijacked the service principals, but noted that an employee of the same organization previously exposed client IDs, client...

Keep reading with a free account

The rest of this article, and every signal for Microsoft, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
Cybercriminal group Storm-3168 compromised two service principals and used them for extensive Azure-focused resource destruction, deleting over 100 Azure Storage accounts, an Azure Key Vault, a Function App, and an App service plan.

Extraction

Confidence
90%
Detected
Sep 28, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for Microsoft and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Microsoft this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/d31b0786-d8f1-4bc7-07c6-416bf53cfb43 returns this record as JSON. POST /v1/companies/enrich returns every signal for microsoft.com.

{
  "signal_id": "d31b0786-d8f1-4bc7-07c6-416bf53cfb43",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-09-28T20:30:00+00:00",
  "company": {
    "name": "Microsoft",
    "domain": "microsoft.com"
  },
  "data": {
    "url": "https://www.theregister.com/security/2026/09/28/jadepuffer-crims-hijacked-azure-identities-and-used-them-to-blow-up-cloud-resources/5299591",
    "title": "JadePuffer crims hijacked Azure identities and used them to blow up cloud resources",
    "excerpt": "security Smells like more agentic ransomware, Redmond warns The cyber criminal behind JadePuffer, the first known agentic ransomware infection reported over the summer, has also used stolen Azure identities to conduct destructive attacks on cloud storage and other resources, according to Microsoft. In July, Sysdig threat hunters uncovered JadePuffer , the first-ever documented agentic ransomware infection in which an LLM drove the entire extortion operation, from gaining initial access to compromising a production database server and destroying data. Now Redmond says that it has detected the same attacker, which it tracks as Storm-3168, up to new mischief. Over an 18-hour period in early June, Storm-3168 compromised two service principals and used these machine identities for “extensive Azure-focused resource destruction” and “cloud credential collection that could be used to facilitate future exfiltration,” researchers Yossi Weizman and Tushar Mudi wrote on Friday. The two compromised service principals belonged to the same cloud tenant. The crims used one of them to conduct reconnaissance and resource discovery, and the other to carry out destructive operations and credential collection. The Redmond researchers don’t know how Storm-3168 initially hijacked the service principals, but noted that an employee of the same organization previously exposed client IDs, client...",
    "summary": "Microsoft reported that the cybercriminal group Storm-3168 (also known as JadePuffer) hijacked two Azure service principals within a single customer's cloud tenant to destroy over 100 Azure Storage accounts and other cloud resources in a destructive attack.",
    "planning": false,
    "image_url": "https://image.theregister.com/5299599.jpg?imageId=5299599&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683",
    "confidence": 0.9,
    "published_at": "2026-09-28T20:30:00Z",
    "vulnerability": "Cybercriminal group Storm-3168 compromised two service principals and used them for extensive Azure-focused resource destruction, deleting over 100 Azure Storage accounts, an Azure Key Vault, a Function App, and an App service plan.",
    "article_sentence": "The cyber criminal behind JadePuffer, the first known agentic ransomware infection reported over the summer, has also used stolen Azure identities to conduct destructive attacks on cloud storage and other resources, according to Microsoft."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.