What Happened
Microsoft tracks JADEPUFFER as Storm-3168, an AI-orchestrated group previously tied to LLM-driven ransomware. In early June the group compromised an Azure tenant over about 18 hours. A first service principal spent 16 hours on reconnaissance, running more than 300 read operations. A second began discovery 90 minutes later, then launched more than 150 destructive and credential collection operations in 35 minutes. The core deletion sequence took seven minutes, with over 100 attempts against storage accounts. Attackers deleted storage accounts, SQL databases, Key Vaults, Function Apps, and virtual machines. The service principal credentials came from a public GitHub issue history. Resource locks and deletion protection blocked some attempts. Read the details at The Hacker News.
Why This Matters for Canadian Organizations
Canadian governments and enterprises run large Azure footprints, often with dozens of service principals created by developers and automation teams. Nobody watches most of them the way they watch human accounts. They hold broad permissions, carry long-lived secrets, and skip multi-factor authentication by design. One pasted credential in a public issue was enough here.
The speed is the lesson. Seven minutes leaves no room for a human analyst to react. Organizations bound by OSFI Guideline B-13 or provincial data residency rules need recovery plans for deleted cloud resources, not only for stolen data. Deleting a Key Vault destroys the keys protecting backups, and losing them turns an outage into a permanent loss.
What to Do
Apply resource locks and deletion protection to production storage, databases, and Key Vaults. Enable soft delete and purge protection where available. Scan repositories, issues, and pull requests for exposed secrets, and rotate any credential found. Replace client secrets with managed identities or federated credentials. Trim service principal permissions to the minimum, and alert on bursts of read operations followed by delete calls from a single identity. Test your restore process against a deletion scenario before an attacker does.
Explore more analysis in our Trends section and daily coverage in News.






