companyMicrosoft
confirmedlowIncidentFirst reported Sep 28, 2026
Microsoft Azure: attackers used compromised service principals to delete cloud resources
Microsoft said the threat actor it tracks as Storm-3168, also known as JADEPUFFER, carried out destructive actions in an Azure environment by abusing compromised service principals. The attack occurred in early June 2026 over roughly 18 hours and Microsoft described it as an evolution of the actor's tradecraft.
Members only
The full record: the timeline and 4 linked reports
- Every update as it happened, with the status at each step
- Every report behind the record, newest first
- Alerts the moment Microsoft — or anything else you track — is hit again
A free account is all it takes — no card, one minute.