Microsoft has linked a destructive Azure intrusion to JADEPUFFER, a threat actor it tracks as Storm-3168. The incident, which unfolded in early June 2026 over roughly 18 hours, relied on two compromised service principals in the same tenant. One principal carried out reconnaissance and resource discovery for close to 16 hours, performing more than 300 read operations; the other handled destructive actions and credential collection.
According to Microsoft's analysis, the second service principal enumerated virtual machines and resource groups across two subscriptions within seconds, then targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, App Services, and recovery protection locks. The destructive phase lasted about seven minutes and involved more than 100 storage account deletion attempts. Most storage accounts were deleted, but Azure resource locks and storage-level deletion protection blocked some deletions. Attempts to delete Azure SQL databases failed because the actor used an unsupported API version.
Microsoft said it is unclear how the service principals were compromised, but it observed that a client ID, client secret, and tenant ID had previously been exposed in plaintext in a public GitHub issue by an employee. Although the secret was removed, it remained accessible through the public edit history. Microsoft also detected repeated probing from Storm-3168-linked infrastructure against Azure App Services for other customers, suggesting the activity may be automated or scripted.
JADEPUFFER was previously documented by Sysdig as the first ransomware operation run end-to-end with an LLM, after exploiting a Langflow flaw (CVE-2025-3248). Microsoft found no ransom note or successful data exfiltration in this Azure case, but assesses the intent as ransomware-aligned because backup and recovery resources were targeted. The company frames the incident as evidence of a broader shift toward AI-orchestrated attacks.