September 29, 2026 · Issue 44 · 4 min read
An agent-linked crew wiped Azure storage in seven minutes, and the controls that held were resource locks
Microsoft published a report on September 25 describing how an actor it tracks as Storm-3168 used two compromised service principals against one organization's Azure tenant in June. The first identity spent about 15 and a half hours on more than 300 read operations. The second enumerated two subscriptions in five seconds. The destructive stage lasted about seven minutes and included more than 100 storage account deletion attempts, per Microsoft(opens in a new tab). Microsoft links the actor to JADEPUFFER, which Sysdig documented in July as the first ransomware operation driven end to end by a language model, per The Register(opens in a new tab).
The likely entry point is ordinary. An employee of the same organization had posted client IDs, client secrets, and tenant IDs in plaintext in a public GitHub issue. Microsoft could not confirm that was the way in. It does note the secrets stayed readable in the issue's edit history after deletion, and that removing an exposed secret does not invalidate it.
What held was not detection. Attempts to remove Azure Backup and Site Recovery protection locks failed, and resource locks blocked some storage deletions. Most of the targeted storage accounts were still deleted, along with a Key Vault and a Function App. Seven minutes is shorter than many paging chains. Two tokens deleting different resource types inside the same 70 seconds is not a pace an analyst matches by reading alerts.
For a CAIO, this moves agentic attack cost from forecast to line item. Service principals and API keys are exactly the identities your own agent programs multiply. Each one with delete rights on production is an outage waiting for a leaked secret. The cheap controls are a lock and a narrower role. The expensive one is a rebuild from backups the attacker also went after.
Nvidia's answer this week is monitoring on separate hardware that can quarantine a misbehaving agent. That governs agents you run. It does nothing about a stolen secret in someone else's hands.
Action items
An attacker with a leaked service principal secret can now move faster than your on call rotation. Plan controls that hold without a human in the loop.
For the CISO. Inventory every service principal and API key with delete rights on production. Remove the rights that no workload needs.
For infrastructure owners. Put resource locks on storage, key vaults, and backup and recovery resources. In this case, locks were what stopped deletions.
For engineering leaders. Treat a secret posted anywhere public as compromised. Rotate it the same day, even if the post is already deleted.
For the CAIO. Count the non-human identities your agent programs create, and make that number part of the business case, not an afterthought.
Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.
Also worth knowing
- Storm-3168: Agentic-driven cloud attacks using compromised service principals(opens in a new tab)
Microsoft Security Blog
Two service principals with broad rights were enough to delete most of a tenant's storage accounts. Audit which non-human identities can delete production resources, and lock backup and recovery resources today.
- JadePuffer crims hijacked Azure identities and used them to blow up cloud resources(opens in a new tab)
The Register
The secrets were exposed in a public GitHub issue before the attack. Deleting a leaked secret is not remediation. Rotation is, and it has to happen the day the leak is found.
- Nvidia launches new platform for reining in rogue AI agents(opens in a new tab)
TechCrunch
Nvidia pairs its OpenShell access controls with Sentry, a monitor on a separate BlueField-4 processor. TechCrunch reports no pricing or dates. Ask whether your agent vendors plan to support it, and note OpenAI is not on the partner list.
- Google fights EU attempt to open Android to rival AI(opens in a new tab)
The Irish Times
Google is appealing DMA orders to let users pick AI assistants by voice on Android and to share search data with rivals. The outcome shapes which assistants reach employee phones in Europe, and on what terms.