JADEPUFFER attackers used compromised service principals to delete Azure resources
The threat actor JADEPUFFER, tracked by Microsoft as Storm-3168, carried out destructive operations in a Microsoft Azure environment over roughly 18 hours in early June 2026 using compromised service principals. Microsoft described the incident as an evolution of the group's tradecraft.
- Attack lasted about 18 hours in early June 2026
- Compromised service principals were used to delete Azure resources
- Microsoft tracks the group as Storm-3168
- Microsoft calls the incident an evolution of the actor's tradecraft
Read next
Security