As reported by BleepingComputer, Microsoft Security Research has published details of two JadePuffer (Storm-3168) attacks against Azure tenants in June 2026 that leveraged AI agents to automate the full attack chain — from reconnaissance and credential theft to the wholesale deletion of storage accounts, Key Vaults, Function Apps, VMs, and App Services. The destructive phase unfolded in approximately seven minutes.

Cloud Security Alert: The technical components of this campaign — compromised service principals, abuse of Microsoft Graph and Azure Resource Manager APIs, attempts to remove recovery locks — are not new.

The headline is speed, not novelty

The technical components of this campaign — compromised service principals, abuse of Microsoft Graph and Azure Resource Manager APIs, attempts to remove recovery locks — are not new. What changes the calculus is the agentic orchestration layer. Storm-3168 isn't deploying AI to write payloads faster; they're deploying it to execute the entire operational kill chain in minutes, at scale, across hundreds of resources. That compression matters because it shrinks the defender's reaction window from hours to single-digit minutes. Traditional incident response playbooks that assume time-to-detect will be in the tens of minutes no longer hold.

Service principals are the new endpoints

Microsoft could not fully confirm the initial access vector, but observed that one of the two compromised service principals had credentials exposed in a public GitHub issue prior to the attacks. This is a familiar failure mode: long-lived client secrets committed to source control, scoped to Contributor or Owner over broad resource groups, with no conditional access, no managed identity migration, and no alerting on anomalous Graph calls. Service principals are now the highest-leverage identity target in Azure because they authenticate non-interactively, often bypass MFA requirements, and inherit whatever role assignment the owner happened to grant six months ago.

Resource locks earned their keep

Notably, some Azure Storage accounts survived the wipe attempts because of Azure resource locks and storage-account-level protections. This is a small but important data point: defense-in-depth inside the control plane actually worked. The attacker also removed Azure Site Recovery locks on at least some resources, indicating awareness that locks existed and required explicit deletion — which is itself a detection signal worth hunting for. Unrequested lock-removal operations against recovery-critical resources should be a high-priority alert in any Azure SIEM rule set.

EncForge and the AI-asset pivot

Earlier Sysdig research tied JadePuffer to EncForge, a tool designed to target AI training datasets and vector databases. The expansion from generic cloud destruction to ML-asset targeting signals that threat actors now treat model weights, embeddings, and training corpora as first-class exfiltration and extortion targets. Organizations operating RAG pipelines, fine-tuning infrastructure, or vector stores containing proprietary data should treat these stores with the same access controls and telemetry as production databases — not as "research" workloads.

What You Should Do

EncForge and the AI-asset pivot
Audit service principals immediately. Inventory every SPN in every tenant, flag any with Client Secret expiration beyond 90 days, and migrate to managed identities or workload identity federation where possible.
Enforce least-privilege RBAC. Replace broad Contributor/Owner role assignments with custom roles scoped to specific resource groups. Apply deny-assignment policies at the subscription level for sensitive resource types.
Lock recovery-critical resources. Apply Delete locks at the resource-group level for Key Vaults, backup vaults, and tier-0 storage accounts. Monitor lock-removal operations as high-severity alerts.
Hunt for leaked secrets in GitHub. Run a GitHub secret-scanning pass against all repos — including archived and forked — and rotate any client secrets older than 60 days regardless of suspected exposure.
Deploy Microsoft Defender for Cloud and enable workload protections. Confirm that Microsoft Defender for Storage and Defender for Key Vault are on, and that alerting is routed to a monitored channel.
Inventory AI assets. Catalog vector databases, training datasets, and model registries. Apply IAM controls consistent with production data tiering.
The 7-minute window is the operational lesson: assume that once an attacker reaches a privileged service principal, you have minutes — not hours — before destructive impact. Pre-positioned locks, granular RBAC, and aggressive secret hygiene are the only controls fast enough to matter.