What happened
JadePuffer’s AI agents performed reconnaissance, stole service‑principal credentials (one exposed on GitHub), and used those identities to delete over 100 Azure storage accounts, Key Vaults, Function Apps, VMs and App Services within a seven‑minute window. Backup protections were also removed, and attempts to delete Azure SQL databases failed due to an unsupported API version.
Why it matters for trust and compliance
- The incident demonstrates why continuous monitoring of privileged identities and enforceable resource‑lock policies are essential control objectives for audit readiness across frameworks such as NIST CSF 2.0.
- Continuous privileged‑identity monitoring supplies immutable evidence for identity‑access controls during audits.
- Documented resource‑lock configurations prove protective measures were in place before the attack.
Who is affected
Enterprises running workloads on Microsoft Azure SaaS providers that rely on Azure service principals
Recommended actions
- Rotate all service‑principal secrets and adopt short‑lived credentials.
- Enable Azure resource locks (CanNotDelete) on critical assets.
- Implement automated secret‑scanning in code repositories and CI pipelines.
- Activate Azure Defender for Cloud alerts on privileged‑identity usage and mass‑deletion events.
- Integrate privileged‑access logs into a continuous control‑assurance platform for defensible audit trails.