SecurityUnverified

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations

What happened

The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations

Why it matters

The development may change operating conditions or market expectations around Microsoft. Further confirmation and measurable outcomes matter.

Affected entities

Microsoft · MSFTNeutral

View evidence

1 reports · 1 original report · 1 independent

  1. The Hacker NewsPrimary source · Supports · EN · 100%
    JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources ↗

Claims

  • JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources Observed

Conflicts

No material conflict detected in the available evidence.

Timeline

  1. First reported

Market move following event

Market reaction is not yet available for this asset and time window.

Score explanation

Confidence · formula confidence-2.1.0
Source trust80
Independent corroboration51
Primary evidence35
Claim consistency82
Extraction confidence82
Attribution quality90
Impact · formula impact-2.1.0
Event magnitude45
Market relevance74
Entity significance94
Market breadth54
Novelty68
Urgency55
Ranking · formula rank-1.0.0
Confidence factor0.8425
Freshness factor0.9868
Breaking bonus0
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources | IntelCap