Microsoft's security research team has documented the Azure activity of Storm-3168, the actor it tracks as JADEPUFFER and which Sysdig described in July 2026 as the first documented agentic ransomware operation. Two compromised service principals in the same tenant were used in sequence: one performed reconnaissance and resource discovery, the other carried out discovery, destructive operations and credential collection. Microsoft observed bulk destruction aimed at Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, virtual machines and App Services, alongside cloud credential collection usable for later exfiltration. The recommended controls are workload identity and secret protection, least privilege, safeguarding recovery resources, and enabling Defender for Cloud coverage — with the explicit caveat that credentials exposed publicly remain usable until revoked or rotated, so removing the original disclosure is not remediation. Microsoft frames the case as evidence of a wider shift to AI-orchestrated post-compromise operations and argues defenders need equivalent automation across large environments.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-26 |
| Source | Microsoft Security |
| Reliability | Tier 1 |