
What was reported
Microsoft published an investigation into Storm-3168, associated with JADEPUFFER, describing destructive Azure activity involving compromised service principals. The report connects resource deletion and cloud credential collection with weaknesses in workload-identity protection. The observed incident predates the publication; this is newly published research, not a claim that the activity began this week.
Defensive perspective
Review workload permissions, exposed secrets and recovery safeguards. Removing an exposed credential from a repository does not invalidate it: revocation or rotation is still required. Microsoft reports that deletion protection and resource locks prevented some destructive operations.
Forensic focus
For an authorized investigation, preserve identity sign-in records, resource activity logs and configuration-change history. Record the collection window and missing retention periods. Correlate the identity, resource and timestamp before describing a sequence as one actor's activity. These are investigation priorities, not proof that a particular environment was affected.
Source published 25 September 2026. Briefing prepared 26 September 2026.