Storm-3168 deletes Azure resources in seven minutes using two compromised service principals
Microsoft documented the Azure intrusion of the JADEPUFFER actor (Storm-3168), which used two compromised service principals to map a tenant and then delete more than one hundred storage accounts in seven minutes. Protect workload identities, enforce least privilege, and enable independent locks and deletion protection.