Home › Intelligence › Brief
BREACH BRIEF 🟠 High ThreatIntel

Storm‑3168: Agentic‑driven Azure attacks exploit compromised service principals to delete resources and harvest credentials

Microsoft disclosed a threat‑actor campaign (Storm‑3168) that hijacks Azure service principals, uses automated scripts for reconnaissance, credential harvesting, and bulk resource deletion. The activity underscores the need for continuous monitoring of privileged identities and robust identity‑governance to satisfy audit‑readiness requirements.

Verisq™ Intelligence · 📅 September 25, 2026 · 📰 microsoft.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
microsoft.com

Storm‑3168: Agentic‑driven Azure attacks exploit compromised service principals

What Happened – Microsoft’s security team observed a campaign (codenamed Storm‑3168) in which threat actors compromised Azure service principals and used automated “agentic” scripts to conduct reconnaissance, harvest additional credentials, and delete cloud resources. The activity was linked to the JADEPUFFER group and demonstrated a high degree of automation across multiple tenant environments.

Why It Matters for Trust & Control Assurance

  • The scenario is a textbook case of privileged identity abuse that a continuous control‑assurance program must detect, log, and remediate.
  • Demonstrates the need for real‑time monitoring of service‑principal activity and enforceable least‑privilege policies to provide defensible audit evidence.
  • Highlights gaps in credential‑rotation and conditional‑access controls that can be addressed through an identity‑governance capability.

Who Is Affected – Organizations that run workloads in Microsoft Azure, especially SaaS providers, large enterprises, and any tenant that creates service principals for automation or third‑party integrations.

Recommended Actions

  • Inventory all service principals and map them to business functions; retire any that are unused.
  • Enforce least‑privilege scopes and require MFA or conditional access for privileged service principals.
  • Deploy continuous monitoring and anomaly detection on Azure AD sign‑in logs to flag atypical service‑principal behavior.
  • Rotate credentials regularly and implement Just‑In‑Time (JIT) access for high‑risk identities.
  • Review Microsoft’s guidance on service‑principal hardening and apply recommended mitigations.

Technical Notes – The attackers leveraged compromised service‑principal credentials (often obtained via phishing or credential‑dumping) to run automated scripts that performed Azure Resource Manager (ARM) enumeration, secret extraction from Key Vault, and bulk deletion of resources. No specific CVE is cited; the technique exploits mis‑managed identity permissions rather than a software flaw. Source: Microsoft Security Blog

📰 Original Source
https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/ ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →