Storm-3168 Deletes Azure Resources in 7-Minute Destructive Cloud Attack
Microsoft says Storm-3168 used stolen Azure identities to delete cloud resources within about seven minutes.
Microsoft says Storm-3168 used two compromised service principals in one Azure tenant for reconnaissance and rapid destruction. In early June 2026 one identity completed more than 300 successful reads over about 15 hours 30 minutes; a second identity then spent roughly seven minutes making more than 100 storage-account deletion attempts, most successful, and deleted a Key Vault, Function App, and App Service plan. Azure SQL deletions failed on an unsupported API version, while locks and deletion protection blocked some attempts; about 30 minutes later the actor made more than 30 successful ListKeys calls, including Site Recovery accounts. Researchers link the case to earlier JADEPUFFER agentic ransomware activity but did not confirm a ransom note, successful theft, or direct AI control.