Microsoft says Storm-3168 is using compromised Azure service principals to run reconnaissance, pull credentials, and delete cloud resources, activity it links to JADEPUFFER tooling. That is an identity with a client ID and a secret, already present in Entra ID, with roles you assigned months ago. The same week, a U.S. Army soldier took 70 months in federal prison for hacking telecom firms and stealing mobile call and text metadata covering more than 100 million AT&T customers in 2024, plus Verizon-linked extortion, with nearly $300,000 in restitution. If your cybersecurity program still ranks packet filters above app registrations, you are scoring the wrong layer.
Kiteworks then told customers to stop using its platform after federal intelligence authorities warned that a threat actor may target some customer systems. Three incidents. One operational fact: the access you already issued is doing the damage.
Storm-3168: Principals Enumerated Azure, Then Deleted Resources
Storm-3168’s move is ugly because it looks legitimate in the control plane. A service principal authenticates. It enumerates subscriptions, vaults, and role assignments. It harvests credentials. Then it deletes. Your threat detection stack is often tuned for brute-force noise against VPN and RDP. An issued principal talking to ARM and Graph does not trip those signatures. It looks like automation. In a lot of tenants, it is automation, right up until a resource group vanishes and the ticket queue lights up.
Microsoft’s write-up frames the cluster as agentic-driven, meaning the attacker chains cloud APIs the way a tired operator would click through the portal, only faster and with less shame. You do not need a philosophy of autonomous malice to take the permissions seriously. If a principal can list Key Vault, read secrets, and hold Contributor on a resource group, the rest of defense in depth is commentary. Contributor plus a long-lived client secret is a remote admin session that never opens a browser.

Watch the API surface, not the story about the tooling. Resource deletion is a high-signal event. So is a principal that suddenly lists every subscription after months of silence. So is a new federated credential or a client secret created at 03:00. If those events only land in a log archive nobody queries, Storm-3168 already has the dwell time it needs.
Cybersecurity Inventories Still Skip Workload Identity Blast Radius
Most cybersecurity inventories still treat human accounts as the privileged class and app registrations as plumbing. That split is how you get a principal with Owner on a subscription and a client secret that expires in 2029. Workload identities skip MFA theater. They skip the impossible-travel rules you put in last year’s board deck. They persist after the engineer who created them leaves, because offboarding checklists still ask for the laptop and the user account, then stop.
Security hardening here is boring on purpose. List every service principal with a role more powerful than Reader. Kill unused apps. Rotate secrets on a calendar you can defend in an audit, not when a vendor blog scares you. Prefer certificates or federated credentials over long-lived client secrets. Put Azure activity logs and Entra sign-in logs for service principals in the same incident response queue as global admin logins. If nobody can tell you which principals can delete resource groups, you do not have an identity program. You have a gallery of forgotten apps with production rights.
Your firewall still matters at the edge. It does not see a Graph token minted from a stolen secret. Threat-protection products that only watch inbound SYN floods will file this week under quiet. That is a coverage gap you can name in the next control review, with a principal roster attached.
AT&T Metadata Theft and the Kiteworks Customer Shutdown
The AT&T case is the human twin of that principal. Metadata on more than 100 million lines is the haul you get when someone is already inside the business of moving calls and texts. Krebs reports a 70-month sentence and restitution near $300,000, numbers that will not price a class action, and that is useful context for your board. Criminal court is a lagging indicator. Telecom metadata is high-value, durable, and handy for targeting. If you run a carrier, a CPaaS stack, or a roaming partner integration, treat call-detail and message-header stores as crown jewels. Lock the admin APIs the way you lock billing. Log every bulk export. Alert on new tokens against those stores.
Kiteworks is the vendor version of the same week. CISO Frank Balonis told Recorded Future News the company received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers. The company’s guidance was blunt: stop using the platform. You rarely hear a vendor say that in public. Treat it as an incident trigger, not a status-page footnote. File-transfer appliances sit next to legal, M&A, and regulated exports. If you cannot fail over to another path in hours, you already accepted a single-vendor outage as a business process.

Dark Reading’s note on AI sandbox escapes lands in the same bucket. Containment fails when the identity can already call production APIs. Forensic readiness, meaning you can reconstruct who authenticated, what they listed, and what they deleted, is the control that still works after a principal walks out of the box you thought was sealed. Collect Entra sign-ins, ARM activity, Key Vault diagnostics, and vendor SSO logs before you argue about whose sandbox was supposed to hold.

Security Hardening Steps While the Principal Is Still Valid
You cannot patch Storm-3168 out of a tenant that already handed out delete rights. You can shrink what a stolen principal can do, and you can see it happen. Do the work in two speeds: same day, then on a calendar you will actually keep.
- Export Entra application and service principal role assignments today. Flag Owner, Contributor, User Access Administrator, and any Key Vault data-plane access. Disable unused principals. Rotate every remaining client secret. Revoke refresh tokens for the apps you keep.
- Turn on Azure resource deletion alerts and Entra workload sign-in reporting. Confirm they fire with a test principal in a non-prod subscription. Silence is a finding.
- If you are a Kiteworks customer, follow the shutdown guidance, freeze related SSO apps, preserve vendor and IdP logs, and open incident response with legal and records owners on an alternate transfer path.
- Review admin and API access to call-detail, messaging, and subscriber metadata stores as if they were payment files. New tokens and bulk reads get pages, not weekly reports.
- Quarterly, recertify every workload role. Pair Conditional Access for workloads with just-in-time elevation for human cloud admins, and deny-by-default on delete. Tabletop a stolen client secret at 2 a.m.: who pulls logs, who revokes, who restores from a backup the principal could not wipe.
Cyber security teams that live in ticket queues will try to turn this into a purchase. The work is inventory, least privilege, and a delete-path you have rehearsed. Storm-3168, a soldier with telecom metadata, and a vendor telling you to power down are the same class of failure: access you granted, then stopped watching.
Sources
- Storm-3168: Agentic-driven cloud attacks using compromised service principals
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
- Kiteworks urges customers to stop using platform after warning from federal intelligence agencies
- AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
