Skip to content

September 29, 2026 · Issue 44 · 4 min read

An agent-linked crew wiped Azure storage in seven minutes, and the controls that held were resource locks

The daily briefing film for this issue, 3:30.

Microsoft published a report on September 25 describing how an actor it tracks as Storm-3168 used two compromised service principals against one organization's Azure tenant in June. The first identity spent about 15 and a half hours on more than 300 read operations. The second enumerated two subscriptions in five seconds. The destructive stage lasted about seven minutes and included more than 100 storage account deletion attempts, per Microsoft(opens in a new tab). Microsoft links the actor to JADEPUFFER, which Sysdig documented in July as the first ransomware operation driven end to end by a language model, per The Register(opens in a new tab).

The likely entry point is ordinary. An employee of the same organization had posted client IDs, client secrets, and tenant IDs in plaintext in a public GitHub issue. Microsoft could not confirm that was the way in. It does note the secrets stayed readable in the issue's edit history after deletion, and that removing an exposed secret does not invalidate it.

What held was not detection. Attempts to remove Azure Backup and Site Recovery protection locks failed, and resource locks blocked some storage deletions. Most of the targeted storage accounts were still deleted, along with a Key Vault and a Function App. Seven minutes is shorter than many paging chains. Two tokens deleting different resource types inside the same 70 seconds is not a pace an analyst matches by reading alerts.

For a CAIO, this moves agentic attack cost from forecast to line item. Service principals and API keys are exactly the identities your own agent programs multiply. Each one with delete rights on production is an outage waiting for a leaked secret. The cheap controls are a lock and a narrower role. The expensive one is a rebuild from backups the attacker also went after.

Nvidia's answer this week is monitoring on separate hardware that can quarantine a misbehaving agent. That governs agents you run. It does nothing about a stolen secret in someone else's hands.

Action items

An attacker with a leaked service principal secret can now move faster than your on call rotation. Plan controls that hold without a human in the loop.

For the CISO. Inventory every service principal and API key with delete rights on production. Remove the rights that no workload needs.

For infrastructure owners. Put resource locks on storage, key vaults, and backup and recovery resources. In this case, locks were what stopped deletions.

For engineering leaders. Treat a secret posted anywhere public as compromised. Rotate it the same day, even if the post is already deleted.

For the CAIO. Count the non-human identities your agent programs create, and make that number part of the business case, not an afterthought.

Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.

Also worth knowing