Microsoft Identified Cloud Sabotage Campaign
The threat actor Storm-3168 exploited compromised service principals to delete critical Azure cloud resources.
Updated on Sept. 26, 2026 in Cybersecurity

Live Poll
Do you trust that major cloud providers adequately secure your business data from cyberattacks?
Microsoft recently identified a sophisticated cloud sabotage campaign orchestrated by the threat actor group Storm-3168. The attackers used compromised service principals to map environments and destroy critical Azure cloud resources.
Why it matters
The campaign highlights significant vulnerabilities in cloud environment management, as attackers successfully bypassed recovery safeguards to disrupt infrastructure. Obtaining storage-account credentials allowed the group to compromise data security within targeted environments.
The attackers identified as Storm-3168, also known as JADEPUFFER, leveraged elevated permissions from compromised service principals. They utilized these identities to map cloud environments and target recovery safeguards within Azure.
The players
Microsoft
Microsoft is a global technology corporation that provides cloud computing services through its Azure platform.
Storm-3168
Storm-3168, also referred to as JADEPUFFER, is a threat actor group known for conducting sabotage operations against cloud environments.
The details
Attackers gained unauthorized access by abusing exposed workload identities to execute automated commands against the cloud infrastructure. This malicious activity successfully deleted critical resources while effectively targeting the platform's native recovery safeguards to prevent restoration.
Timeline
September 26, 2026: Microsoft published findings regarding the Storm-3168 campaign.
The Tech Race
This incident demonstrates a shift toward destructive sabotage within cloud ecosystems, moving beyond simple data exfiltration toward resource destruction. It underscores the critical need for robust identity management as service principals become prime targets in modern cyber warfare.
Users and administrators of cloud environments must prioritize the auditing of service principal permissions to prevent unauthorized automated command execution. Implementing stricter identity monitoring is now essential to mitigate the risk of permanent resource deletion by threat actors.
The takeaway
Organizations should treat workload identities with the same security rigor as human administrative accounts to prevent catastrophic resource loss. Regularly auditing permission levels and implementing multi-layered recovery protocols remains the best defense against targeted cloud sabotage.
Further reading
Learn more about securing cloud infrastructure in the Cybersecurity section.
Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.
Live Poll
Do you trust that major cloud providers adequately secure your business data from cyberattacks?










