
JADEPUFFER Threat Actor Conducts Destructive Attack on Microsoft Azure Using Compromised Service Principals
Cloud SecurityCyber AttacksThreat ActorsAzure
The threat actor JADEPUFFER, tracked by Microsoft as Storm-3168, conducted destructive operations within a Microsoft Azure environment using compromised service principals. The attack occurred in early June 2026 and lasted approximately 18 hours. Microsoft characterized this activity as an evolution of the threat actor's tradecraft, with the attackers using the compromised service principals to delete Azure resources.