"The parallel targeting of Azure SQL databases and storage accounts suggests an effort to broaden the destructive impact across different data services rather than concentrating on a single resource type," Microsoft said.
JadePuffer's agentic AI and the EncForge tool
Researchers at cloud security company Sysdig identified a new ransomware operator called JadePuffer that emerged in July and uses AI-driven agents to automate the full attack chain. According to Sysdig, the malware orchestrates reconnaissance, credential theft, lateral movement, persistence and data encryption with minimal human direction. Sysdig also reported that JadePuffer expanded its focus to attack AI assets — specifically training datasets and vector databases — and does so using a tool the researchers named EncForge.
Microsoft Security Research observed Storm-3168 mapping and wiping resources
Microsoft Security Research attributed the activity to a tracked threat actor it calls Storm-3168 and reported observing two JadePuffer attacks in June. In those incidents the attacker mapped cloud resources, retrieved storage account keys and deleted Azure Storage accounts. Microsoft said the destructive stage of the observed activity lasted seven minutes and targeted more than 100 storage accounts as well as Key Vaults, Function Apps, Virtual Machines, and App Services.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleDestructive operations, and protections that limited damage
Although the attacker succeeded in deleting most of the targeted Azure Storage accounts, Microsoft noted that some accounts remained protected because of Azure resource locks and storage account–level protections. The attacker also removed Azure Site Recovery locks — a deliberate move Microsoft interpreted as an effort to make restoration more difficult. Microsoft did not report financial demands tied to the observed incidents and did not confirm data theft, but it said that the operational pattern could further support ransomware extortion.
Credential use, failed API calls, and a public GitHub exposure
Microsoft reported that the operator used two compromised service principals — security identities that allow applications and automated tools to authenticate in Azure — and both service principals belonged to the same tenant. One principal was used for reconnaissance and resource discovery; the other "performed discovery, destructive operations, and credential collection." Roughly half an hour after the wipe attempts, Storm-3168 returned and issued more than 30 requests for storage account keys, most of which succeeded.
Not every deletion attempt worked. Microsoft said attempts to delete Azure SQL databases failed because the attacker used an unsupported API version, and attempts to remove recovery protection locks failed. Microsoft could not determine exactly how initial access was achieved, but noted that credentials for one of the service principals appeared in a public GitHub issue prior to the attacks.
What this means for cloud teams, regulators, and affected enterprises
- Cloud security teams: The use of AI agents and automated tooling like EncForge means reconnaissance, credential theft and destructive operations can be orchestrated at higher speed and with fewer manual steps. Microsoft and Sysdig's findings emphasize the importance of resource locks and storage-level protections, which in these incidents prevented deletion of some accounts.
- Regulators and procurement leaders: The targeting of AI assets — training datasets and vector databases — expands the asset classes at risk. EncForge and agentic tooling will likely be a factor in future incident reviews where questions of data provenance, retention policies and business continuity intersect with cloud security controls.
- Affected enterprises and operations teams: Microsoft recommended several practical steps: activate cloud workload protections, search public repositories for leaked secrets, and evaluate Azure Role-Based Access Control permissions against least-privilege principles. These measures are aimed at reducing the likelihood that service principals or other credentials can be abused at scale.
Microsoft and Sysdig together describe a fast, targeted campaign that combined automated reconnaissance, credential misuse, destructive deletions and attempts to undermine recovery. Whether Storm-3168 continues to pair deletions with extortion demands remains unreported; what is clear is that automated, agent-driven playbooks are now part of the attacker toolkit and that basic cloud protections — resource locks, storage-level protections, and secrets hygiene — made a measurable difference in these incidents.




