As reported by BleepingComputer, Microsoft Security Research has published details of two JadePuffer (Storm-3168) attacks against Azure tenants in June 2026 that leveraged AI agents to automate the full attack chain — from reconnaissance and credential theft to the wholesale deletion of storage accounts, Key Vaults, Function Apps, VMs, and App Services. The destructive phase unfolded in approximately seven minutes.
The headline is speed, not novelty
The technical components of this campaign — compromised service principals, abuse of Microsoft Graph and Azure Resource Manager APIs, attempts to remove recovery locks — are not new. What changes the calculus is the agentic orchestration layer. Storm-3168 isn't deploying AI to write payloads faster; they're deploying it to execute the entire operational kill chain in minutes, at scale, across hundreds of resources. That compression matters because it shrinks the defender's reaction window from hours to single-digit minutes. Traditional incident response playbooks that assume time-to-detect will be in the tens of minutes no longer hold.
Service principals are the new endpoints
Microsoft could not fully confirm the initial access vector, but observed that one of the two compromised service principals had credentials exposed in a public GitHub issue prior to the attacks. This is a familiar failure mode: long-lived client secrets committed to source control, scoped to Contributor or Owner over broad resource groups, with no conditional access, no managed identity migration, and no alerting on anomalous Graph calls. Service principals are now the highest-leverage identity target in Azure because they authenticate non-interactively, often bypass MFA requirements, and inherit whatever role assignment the owner happened to grant six months ago.
Resource locks earned their keep
Notably, some Azure Storage accounts survived the wipe attempts because of Azure resource locks and storage-account-level protections. This is a small but important data point: defense-in-depth inside the control plane actually worked. The attacker also removed Azure Site Recovery locks on at least some resources, indicating awareness that locks existed and required explicit deletion — which is itself a detection signal worth hunting for. Unrequested lock-removal operations against recovery-critical resources should be a high-priority alert in any Azure SIEM rule set.
EncForge and the AI-asset pivot
Earlier Sysdig research tied JadePuffer to EncForge, a tool designed to target AI training datasets and vector databases. The expansion from generic cloud destruction to ML-asset targeting signals that threat actors now treat model weights, embeddings, and training corpora as first-class exfiltration and extortion targets. Organizations operating RAG pipelines, fine-tuning infrastructure, or vector stores containing proprietary data should treat these stores with the same access controls and telemetry as production databases — not as "research" workloads.
What You Should Do
The 7-minute window is the operational lesson: assume that once an attacker reaches a privileged service principal, you have minutes — not hours — before destructive impact. Pre-positioned locks, granular RBAC, and aggressive secret hygiene are the only controls fast enough to matter.