Attackers Hijack Azure Service Accounts to Wipe Cloud Resources
Microsoft has detailed a destructive attack campaign linked to the threat actor known as JADEPUFFER, tracked internally as Storm-3168. In early June 2026, the group used compromised Azure service principals, which are identities used by applications and services to access cloud resources, to carry out an 18-hour attack that hit Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, Virtual Machines, App Services, and recovery protection locks.
Microsoft found two compromised service principals within the same tenant: one used for reconnaissance and discovering resources, and the other used to perform destructive actions and steal credentials. This group was previously linked by researchers at Sysdig to an AI-driven ransomware operation that exploited a known Langflow vulnerability, harvested credentials, and used an AI agent to plan and execute attack steps automatically. The same target was later hit again with a purpose-built ransomware strain called ENCFORGE, designed to seek out AI infrastructure files such as model checkpoints, training datasets, and vector databases.
This case shows how attackers are increasingly targeting cloud identity systems, not just endpoints, to cause maximum disruption. Compromising a single service account can give attackers broad access across multiple cloud services at once.