Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

JADEPUFFER Threat Actors Delete Azure Resources Using Compromised Service Principals

Threat actor JADEPUFFER leveraged stolen Azure service principal credentials to delete cloud resources across multiple tenants, demonstrating a failure in privileged access governance. The incident underscores the need for continuous monitoring and strict control over service principal secrets to satisfy audit‑ready identity management.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 thehackernews.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
5 recommended
📰
Source
thehackernews.com

JADEPUFFER Threat Actors Delete Azure Resources Using Compromised Service Principals

What Happened – The group known as JADEPUFFER (tracked by Microsoft as Storm‑3168) leveraged compromised Azure service‑principal credentials to issue delete commands against Azure Resource Manager APIs. Over an 18‑hour window in early June 2026 the attackers removed virtual machines, storage accounts and other cloud assets across multiple tenant subscriptions.

Why It Matters for Trust & Control Assurance

  • The incident is a textbook case of privileged‑access abuse that a continuous control‑assurance program is built to detect, log and remediate.
  • Without immutable audit trails of service‑principal activity, organizations lack defensible evidence for auditors and regulators.
  • Enforcing just‑in‑time, time‑bound permissions for service principals directly addresses the control objective of “Identity and Access Management” in NIST CSF 2.0.

Who Is Affected – Enterprises and MSPs that run production workloads on Microsoft Azure and rely on service‑principal authentication for automation.

Recommended Actions

  • Conduct an inventory of all Azure service principals; retire or disable any that are unused.
  • Enforce MFA, certificate‑based auth, or Azure AD Conditional Access for privileged service principals.
  • Implement Just‑In‑Time (JIT) or time‑bound access for automation accounts.
  • Enable Azure Activity Log alerts for delete operations and retain logs in an immutable store.
  • Rotate secrets regularly and store them in a dedicated secret‑management vault.

Technical Notes – The attackers exploited stolen service‑principal credentials (likely harvested from insecure code repositories or leaked secrets). No public CVE is involved; the vector is credential compromise leading to API‑based resource deletion. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →