Microsoft Identified Cloud Sabotage Campaign
The campaign targeted Azure cloud environments to delete critical resources and harvest credentials.
Updated on Sept. 26, 2026 in Cybersecurity

Live Poll
Do you trust that major cloud providers adequately secure your business data from cyberattacks?
Microsoft confirmed that a threat actor group known as Storm-3168, also identified as JADEPUFFER, executed a cloud sabotage campaign. The attackers systematically deleted Azure cloud resources after gaining unauthorized access.
Why it matters
The campaign underscores significant vulnerabilities in cloud infrastructure when service principals are compromised. By targeting recovery safeguards, attackers can inflict permanent data loss before administrators can intervene.
The attackers utilized compromised service principals—workload identities granted elevated permissions—to execute automated commands across Azure environments. These credentials allowed the threat actor to bypass standard safeguards and successfully delete critical storage and compute resources.
The players
Microsoft
A global technology leader providing the Azure cloud computing platform and enterprise software solutions.
Storm-3168
A threat actor group, also known as JADEPUFFER, identified as responsible for the cloud sabotage campaign.
The details
Storm-3168 leveraged exposed workload identities, which are managed credentials used by automated applications to access cloud resources. By utilizing these elevated permissions, the actors mapped complex cloud environments to identify and destroy high-value assets. Furthermore, the group deliberately targeted recovery safeguards, which are protocols designed to restore data or revert system changes, effectively preventing standard cloud restoration procedures.
Timeline
September 26, 2026: Microsoft published findings regarding the Storm-3168 campaign.
The Tech Race
This activity marks a shift in threat actor strategy from passive data theft to active sabotage of cloud infrastructure through Azure service principals. It signals an urgent need for security teams to re-evaluate the lifecycle management of automated identities within complex cloud environments.
Cloud administrators should immediately audit all active service principals to ensure only necessary permissions are provisioned. Users and enterprises must review Azure recovery safeguard logs to ensure critical data backups remain untampered and isolated from standard workload identities.
The takeaway
The campaign highlights the fragility of automated cloud workflows when service principal credentials are leaked. Security teams should monitor for unusual automated commands and verify that recovery safeguard policies are properly hardened against unauthorized deletion attempts.
Further reading
For more information on securing identity management, visit Cybersecurity.
Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.
Live Poll
Do you trust that major cloud providers adequately secure your business data from cyberattacks?









