Breakthroughs and research·September 25, 2026, 17:35
Hackers used stolen cloud key to delete data
AI-generated and checked against the sources listed below.
Microsoft warns of the hacker group Storm-3168, which used a leaked password to break into a company's Microsoft cloud, map the system and then delete more than 100 data stores in a matter of minutes.

Microsoft has disclosed an attack in which the hacker group Storm-3168 gained access to a company's account in the Microsoft cloud (Azure) and used it to destroy large amounts of data.
The attack targeted so-called "service principals," a kind of automated account that apps and systems use to log in to the cloud without a human user. According to Microsoft, the hackers likely found the access because an employee had accidentally shared a secret password in a public GitHub post. Even though the employee later removed the code, it was still stored in the post's edit history, where the hackers could find it.
With that access, the attackers spent about 16 hours mapping the company's systems and made more than 300 lookups. Then things moved fast: in just seven minutes, they tried to delete more than 100 data stores (Azure Storage Accounts), and they also managed to delete a key vault service and an app. In total, they carried out more than 150 destructive actions in about 35 minutes. Some deletions of databases and backup systems failed because the company had given them extra protection.
After the destruction, the hackers stole access keys to more than 30 data stores, which could allow them to read or copy data. However, Microsoft has found no evidence that data was actually stolen, and no ransom demands were left behind.
Microsoft calls the attack "agent-driven" because the speed and pattern of the actions resemble automated tools rather than a person clicking manually.
For ordinary employees, the point is simple: never share passwords or keys in code, chat or public posts. Even if you delete them afterward, they can still be found. Companies are advised to rotate leaked credentials immediately and limit what automated accounts are allowed to do.
Sources
Get the week's AI news in your inbox
Choose your level, topics and length. One email a week, unsubscribe at any time.
Subscribe to Promptly Newsletter



