JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
Overview
In June 2026, the hacking group JADEPUFFER, tracked by Microsoft as Storm-3168, executed a significant attack on Azure environments using compromised service principals. Over approximately 18 hours, the attackers managed to delete various Azure resources, showcasing an advanced level of sophistication in their methods. This incident raises alarms for organizations relying on Azure, as it highlights vulnerabilities in how service principals can be exploited. Companies must reassess their security measures to protect against such intrusions, especially those tied to critical cloud infrastructure. The incident serves as a reminder of the ongoing risks associated with cloud services and the importance of robust access controls.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Microsoft Azure resources
- Action Required: Organizations should implement stricter access controls for service principals, regularly audit permissions, and monitor for unusual activity within Azure environments.
- Timeline: Ongoing since June 2026
Original Article Summary
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations
Impact
Microsoft Azure resources
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since June 2026
Remediation
Organizations should implement stricter access controls for service principals, regularly audit permissions, and monitor for unusual activity within Azure environments.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Microsoft, Critical.