JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
thehackernews.com Sep 28, 2026

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

AI-summarised brief · reviewed before publication

Microsoft identified an 18‑hour Azure breach in early June 2026, where the JADEPUFFER threat actor leveraged two compromised service principals to enumerate and delete resources. The attackers targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, App Services, and Virtual Machines, executing over 300 read operations and more than 150 destructive actions in a 35‑minute burst. Most storage accounts were deleted, though resource locks and deletion protection halted a few attempts. The compromise stemmed from a public GitHub leak of a service principal’s client secret.

💡 Why It Matters

  • · The incident demonstrates how exposed service principals can grant attackers sweeping administrative control, underscoring the critical need for secure credential handling and layered protection mechanisms in cloud environments.