An autonomous AI-driven attacker destroyed more than 100 Azure storage accounts in just seven minutes after compromising machine identities used by cloud applications, according to a Microsoft blog post published this month. The threat actor, tracked as Storm-3168 or Jadepuffer and first identified in July, has expanded from database attacks into Azure environments, where it can now enumerate cloud resources, erase assets, and harvest additional credentials. Microsoft says the campaign represents what it calls "extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could be used to facilitate future exfiltration."

Microsoft observed two compromised service principals—unique machine identities assigned to applications running in Azure—operating within the same tenant, with each identity playing a distinct role. One service principal spent over 15 hours cataloging virtual machines, subscriptions, resource groups, and other assets, completing more than 300 successful read operations during its reconnaissance phase. The second identity enumerated resources across multiple subscriptions within seconds before conducting further discovery work. After both agents finished their mapping activity, they launched more than 150 destructive or credential-harvesting operations over roughly 35 minutes. The core destructive sequence lasted approximately seven minutes and targeted storage accounts, with most deletion attempts succeeding. The attackers also erased an Azure Key Vault, a Function App, and an App Service plan tied to the same resource group, and attempted to remove Azure SQL databases along with backup-related safeguards including Azure Site Recovery locks and backup protection locks.

The report notes that the timing and division of activity "strongly indicates automated or scripted execution," pointing to coordination between the two compromised identities. About 30 minutes after the destructive operations concluded, the same service principal requested storage account access keys, making more than 30 successful ListKeys requests that included storage accounts tied to recovery services. Microsoft said the combination of resource deletion, interference with recovery systems, and credential collection is "consistent with tactics that can support ransomware and extortion operations," though the company didn't observe a ransom note or confirm data theft in this case. Microsoft couldn't confirm how the attackers initially gained access, but discovered that credentials linked to one compromised service principal had previously appeared in plaintext within a public GitHub issue; although the secret was later removed, it stayed accessible in the edit history.

The speed of the attack—seven minutes from first deletion to final erasure—challenges conventional incident response workflows, particularly when automated systems can coordinate reconnaissance and destruction across cloud subscriptions faster than human teams can assemble. Because the compromised identities were service principals rather than user accounts, their activity resembled routine cloud administration, making detection more difficult without strong monitoring of identity behavior and resource changes. Microsoft said the activity reflects "a broader shift toward AI-orchestrated attacks," where adversaries can coordinate operations across cloud environments with "greater speed and scale." The company recommended that organizations protect workload identities, enforce least-privilege access for service principals, and secure backup and recovery resources to reduce exposure to similar campaigns. Nick Tausek, lead security automation architect at Swimlane, noted that "publicly exposed credentials remain usable until revoked or rotated; removing the original disclosure alone does not remediate the exposure," underscoring the persistence risk when secrets leak into version-controlled platforms. Ross Filipek, CISO at Corsica Technologies, said response planning across development, cloud operations, and incident response teams is critical: "If those teams wait until an outage to work out who owns the credentials, they'll lose valuable time." The case suggests that cloud defenders may need to rethink how quickly they can revoke compromised identities and verify the integrity of backup systems before trusting restored infrastructure. Organizations relying on traditional playbooks built for slower, human-paced intrusions may find themselves structurally disadvantaged against adversaries capable of coordinating multi-stage operations in minutes rather than hours.