# Microsoft describes JadePuffer attacks in which Storm-3168 targeted over 100 Azure storage accounts in seven minutes > Microsoft Security Research reports that Storm-3168 used two compromised Azure service principals and AI-driven tooling to destroy cloud resources and remove backup protections. FireAI Security & Research Team (HisnLabs) ยท Published 2026-09-30 Canonical: https://hisnlabs.com/en/news/jadepuffer-storm-3168-agentic-ai-azure-destroy-storage-accounts Microsoft Security Research has described two attacks in which a threat actor it tracks as Storm-3168 used compromised Azure service principals to delete cloud resources, [BleepingComputer reported](https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/) on 28 September 2026. The tooling is called JadePuffer, and the cloud security firm Sysdig had earlier documented its AI-driven capabilities. Microsoft observed the two attacks in June 2026 [[1]](https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/). ## Background An Azure service principal is a non-human identity that applications and scripts use to act in a cloud account. It carries permissions and a secret, and anyone holding the secret can use the permissions. An agentic attack tool is one in which software chooses its next action based on what it finds, so that one operator can run a whole sequence quickly. ## What the report describes Microsoft reported that the actor used two service principals from the same tenant. One performed reconnaissance and resource discovery, and a second carried out destructive operations and credential collection. The destructive phase lasted seven minutes and targeted more than 100 storage accounts, along with Key Vaults, Function Apps, Virtual Machines and App Services [[1]](https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/). The actor made more than 30 requests for storage account keys, most of which succeeded, and removed backup recovery protections to hinder restoration. About 30 minutes passed before follow-up attempts to steal credentials [[1]](https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/). Most storage account deletions succeeded. Some resources survived because of Azure resource locks and account-level protections, and attempts to delete SQL databases failed because of unsupported API versions [[1]](https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/). Microsoft's advice, as reported, is to turn on cloud workload protections, to scan public repositories for exposed secrets and to check role-based access permissions against least privilege [[1]](https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/). The material reviewed does not state how the service principals were compromised. > FireAI, the on-device firewall for macOS developed by HisnLabs, shows which command-line tools and apps on a Mac connect to cloud services. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Implications for Mac users The attacks took place inside Azure tenants, so an ordinary Mac user is not the target [[1]](https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/). The audience for whom the report is relevant is people who administer cloud accounts from a Mac, where a service principal's secret may sit in a configuration file, a shell history or an AI coding agent's context. FireAI News has reported on [stealers that take AI agent tokens and chat histories](https://hisnlabs.com/en/news/infostealers-target-ai-coding-agents-tokens-prompt-histories); the JadePuffer sources do not link the two. ## Recommendations 1. Keep cloud secrets out of repositories, shell history and agent-readable folders, and scan public repositories for leaks. 2. Give each service principal only the permissions its job needs, and separate discovery from destructive rights. 3. Apply resource locks to storage accounts and vaults that must not be deleted. 4. Keep backups protected against deletion by the same identities that manage the data. ## Relevance to FireAI FireAI cannot see or stop actions that take place inside a cloud account, and it does not manage cloud permissions. On the Mac it shows when a tool such as a cloud command-line client connects, through [Activity](https://hisnlabs.com/en/docs/activity-and-connection-history) and the [world map](https://hisnlabs.com/en/docs/world-map), and a [per-app rule](https://hisnlabs.com/en/docs/per-app-rules) can allow only the tools that should reach cloud endpoints. That reduces the chance of a stolen secret being used unnoticed from the same machine, and no more than that. > Credentials used from a Mac leave connections behind. FireAI lists each app and destination, so an unfamiliar cloud client stands out. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Limitations The account rests on one press report of Microsoft's findings. It gives two observed incidents, not the campaign's full extent, and it does not say how the credentials were obtained, how many customers were affected or which country the actor operates from. Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days. ## Sources - [BleepingComputer, 28 September 2026: JadePuffer agentic AI attacks target Azure, destroy cloud resources](https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/)