Microsoft Pins Azure Wipeout on JadePuffer, the First Agentic Ransomware Crew

Storm-3168's AI-driven agents destroyed more than 100 Azure storage accounts in seven minutes, using a service principal whose credentials had been sitting in a public GitHub issue.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
Full-frame 16:9 photoreal editorial image of a dark server room with rows of blue-lit cloud storage racks, several racks showing empty slots where drives have b
Share

Key points

  • Microsoft's investigation found JadePuffer's AI agents wiped more than 100 Azure storage accounts in a single seven-minute burst in June 2026, the first detailed account of how an agentic ransomware crew behaves inside a cloud tenant.
  • The attackers signed in using two legitimate Azure service principals, machine logins that apps use instead of a human account, both belonging to the same victim organisation.
  • Microsoft, which tracks the group as Storm-3168, found credentials for one of those logins had been posted in a public GitHub issue before the attack.
  • Attempts to delete Azure SQL databases failed because the agent called an outdated version of the Azure programming interface, a mistake a human operator would have caught and retried.
  • Threat Vectr's own leak-site tracking has not seen a public victim post from JadePuffer, which fits Microsoft's note that no ransom demand was observed in these cases.

Microsoft has published the first inside account of an attack by JadePuffer, a criminal group that Sysdig flagged in July as the first ransomware operation to hand the steering wheel to AI agents. We first covered this group on 2 July 2026, and this is now our fourth story on the crew.

An AI agent is a program that takes a goal and figures out the steps itself, calling cloud commands the way a human administrator would. In two incidents in June 2026, those agents tore through an Azure tenant, Microsoft's name for a customer's slice of its cloud. The destructive run lasted seven minutes.

How did the attackers get in?

They logged in with valid credentials. Microsoft found that one of the two Azure service principals used in the attack had its secret key sitting in a public GitHub issue before the break-in, the cloud equivalent of taping your office keys to a lamppost.

Service principals are the non-human logins that applications and automation scripts use to talk to Azure. Because they're often over-privileged and rarely rotated, they're a favourite target. This isn't a novel AI attack. It's old-fashioned credential leakage, with a new kind of operator on the other end.

What did the AI agents actually do?

Once inside, the agents mapped the environment, pulled storage account keys, then started deleting things in bulk. Microsoft logged destruction attempts against Azure Storage accounts, SQL databases, Key Vaults (where secrets and encryption keys live), Function Apps, Virtual Machines, App Services, and the recovery locks that normally stop someone wiping backups.

Resource type Outcome
Azure Storage accounts Most of 100+ deleted; some saved by resource locks
Azure SQL databases Deletion failed, wrong API version used
Recovery protection locks Removal attempts failed
Key Vaults, Function Apps, VMs, App Services Targeted in the seven-minute burst
Storage account keys 30+ requests roughly 30 minutes later, mostly successful

The failed SQL deletion is the detail worth dwelling on. An agent called an Azure API version Microsoft no longer supports. A competent human on a keyboard would have retried. This one moved on.

Is this really ransomware?

Not in the usual sense, at least not here. Microsoft saw no ransom note and confirmed no data theft in these two cases, and no victim has appeared on JadePuffer's leak site in our own tracking. What Microsoft did observe was the attacker stripping out recovery locks, the move you make when you want to stop a victim restoring from backup.

Sysdig's earlier reporting, picked up by BleepingComputer, had JadePuffer branching into AI-specific targets: training datasets and vector databases, the storage systems that power modern AI search, using a tool called EncForge. None of that appeared in the Azure incidents Microsoft describes.

Should you worry about the agentic angle?

The agentic framing is the headline. The way in was a credential left in a GitHub issue. Speed and automation are genuinely new, but the root cause is a secret that should never have been public.

What should defenders do on Monday morning?

Treat service principal secrets like passwords that can end a company. Scan public repositories for leaked keys, cut permissions on every non-human login to the minimum it needs, and turn on Azure's resource locks and backup protections. In these cases, those controls were the only thing that saved any data at all.

© 2026 Threat Vectr