BreachFeed
← All incidents
companyMicrosoft
confirmedlowIncidentFirst reported Sep 28, 2026

Microsoft Azure: attackers used compromised service principals to delete cloud resources

Microsoft said the threat actor it tracks as Storm-3168, also known as JADEPUFFER, carried out destructive actions in an Azure environment by abusing compromised service principals. The attack occurred in early June 2026 over roughly 18 hours and Microsoft described it as an evolution of the actor's tradecraft.

Members only

The full record: the timeline and 4 linked reports

  • Every update as it happened, with the status at each step
  • Every report behind the record, newest first
  • Alerts the moment Microsoft — or anything else you track — is hit again

A free account is all it takes — no card, one minute.

Microsoft Azure: attackers used compromised service principals to delete cloud resources · BreachFeed