Seven Minutes: What an AI-Driven Azure Attack Teaches Us About Access
ABRI Systems ·
A cyberattack disclosed by Microsoft on September 25 gives us a glimpse of something cybersecurity professionals have been warning about: AI doesn't necessarily need to invent new ways to break into systems. It can make existing attacks happen much faster.
Microsoft reported malicious activity associated with a threat actor it tracks as Storm-3168, also known as JADEPUFFER. The attackers had compromised two service principals inside an Azure cloud environment. Microsoft technical analysis
That term sounds complicated, but the concept isn't.
A service principal is essentially an identity for software. Instead of a human employee logging into Azure with a username and password, an application or automated process gets its own identity and permissions.
And just like a human account, that identity can have far more access than it actually needs.
Then everything happened very quickly.
According to Microsoft's investigation, one compromised service principal spent hours discovering what existed inside the Azure environment.
Another performed discovery across two subscriptions in five seconds.
Eventually the attackers began destructive operations.
Microsoft observed more than 100 attempts to delete storage accounts during a destructive sequence lasting roughly seven minutes. Most of the targeted storage accounts were successfully deleted. The attackers also targeted databases, a Key Vault, applications and recovery protections. The SQL database deletion attempts failed because the attackers used an unsupported API version. Microsoft technical analysis
Seven minutes for the destructive sequence—not the entire intrusion. Microsoft described earlier reconnaissance and later credential collection as well.
That is an uncomfortable number for defenders because many traditional security processes still assume humans will have time to notice something unusual, investigate it and respond.
Automation changes that equation. Microsoft assessed the timing and coordination as strong evidence of automated or scripted execution; speed alone does not prove that an AI model directed every action.
But there is another important part of this story.
Microsoft found that credentials associated with one of the service principals had previously appeared in plaintext in a public GitHub issue.
The issue was later edited to remove the secret.
The credential itself, however, hadn't magically disappeared.
It remained potentially available through the issue's edit history. Microsoft could not confirm that this particular exposed secret caused the compromise, but the discovery illustrates an important security principle: deleting an exposed password, API key or application secret from the place where it leaked does not make the credential safe again. Microsoft technical analysis
If someone has copied it, they can continue using it until the credential is revoked or replaced.
Think of accidentally posting your house key online.
Deleting the photograph doesn't change the lock.
The good news: some protections worked.
Azure resource locks and deletion protections prevented the attackers from deleting some resources even though the compromised identity had significant permissions. Attempts against some recovery protections also failed. Microsoft technical analysis
That is defence in depth in practice.
Security shouldn't depend on one password, one firewall or one administrator noticing something quickly enough. Independent safeguards should remain between an attacker and catastrophic damage even after another control has failed.
And as automated and AI-assisted attacks become faster, those layers become increasingly important.
Security tip: rotate exposed credentials — don't just delete them.
If an API key, password, token or application secret ever appears somewhere it shouldn't:
*1. Revoke or rotate the credential immediately.
2. Replace it anywhere legitimate systems use it.
3. Check logs for activity involving the old credential.*
Removing the secret from GitHub, Slack, email or a document is cleanup.
Changing the credential is security.
Primary technical source: Microsoft Security Research, September 25, 2026. Microsoft technical analysis
Read Microsoft's Storm-3168 technical analysis
Primary source: Microsoft Security Research, September 25, 2026. Source checked October 1, 2026.
Share