Security News

Microsoft Warns of Cloud-Destroying Attacks Using Stolen Azure Identities

The Register · 29 Sept 2026
Key Takeaway Australian SMBs using Azure or other cloud platforms should audit their code repositories and configuration files for exposed credentials and rotate any secrets that may have been accidentally published.

Microsoft has revealed that a cyber criminal group known as Storm-3168, previously linked to the first documented case of AI-driven ransomware, has also been using stolen Azure identities to carry out destructive attacks against cloud storage and other resources. The group compromised two 'service principals' (machine identities used to access cloud services) belonging to the same organisation and used them over an 18-hour period to map out an entire Azure environment before destroying resources and collecting credentials.

One compromised identity was used purely for reconnaissance, conducting over 300 successful read operations across virtual machines, subscriptions and resource groups to build a detailed picture of the target's cloud environment. A second identity, activated 90 minutes later, moved quickly to read resources across multiple subscriptions before the group carried out destructive operations and gathered further credentials that could support future data theft.

Microsoft has not confirmed exactly how the service principals were first hijacked, but noted that an employee at the affected organisation had previously leaked client IDs, client secrets and tenant IDs in plain text on a public GitHub page. The company also flagged ongoing probing of Azure App services linked to this same threat actor since early this year, suggesting the group is actively hunting for further targets.

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.