# JadePuffer used a service principal leaked in a GitHub issue to wipe Azure resources in seven minutes

Source: https://startwithidentity.com/blog/2026-09-28-jadepuffer-used-leaked-service-principal-credentials-to-wipe-azure-tenants/
Last updated: 2026-09-28
License: content by Start with Identity. Cite the source URL.

---

Microsoft and [Sysdig](https://startwithidentity.com/vendors/ciem/sysdig/) have detailed JadePuffer, a ransomware operator Microsoft tracks as Storm-3168, running agent-driven attacks against Azure tenants. In two attacks observed in June, the operation used two compromised service principals in the same tenant: one for reconnaissance and resource discovery, the second for further discovery, credential collection and destruction. It targeted more than 100 storage accounts along with Key Vaults, Function Apps, virtual machines and App Services, made more than 30 requests for storage account keys, most of which succeeded, and removed Azure Site Recovery locks to block recovery. The destructive phase took seven minutes; parallel attempts to delete Azure SQL resources failed on an unsupported API version. Microsoft could not determine the initial access, but credentials for one of the service principals had appeared in a public GitHub issue before the attacks.

## Why it matters

Every step here ran on permissions the service principals already had. Listing storage keys, deleting resource locks and destroying production resources are separate rights, and a principal that holds all three at once is standing destructive privilege waiting for its secret to leak. The review to run is which of your service principals can both read secrets and delete locks, and why; almost none should need both, and lock deletion in particular belongs behind a human approval. See [zero standing privileges](https://startwithidentity.com/glossary/zero-standing-privileges/) and [least privilege](https://startwithidentity.com/glossary/least-privilege/).

The initial access is the older lesson. A client secret is a password for a workload, and it ended up in a GitHub issue the way passwords end up in chat. Workload identity federation and managed identities remove the secret entirely, which removes this whole class of leak. The AI agent matters mainly for speed: seven minutes from start to finish means a response process measured in hours only ever gets to investigate. See [secrets in repositories and CI](https://startwithidentity.com/techniques/secrets-in-repositories-and-ci/) and [client credentials](https://startwithidentity.com/glossary/client-credentials/).

Source: [BleepingComputer](https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/)
