Stolen Azure identities let automated attackers erase cloud assets
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, September 29th, 2026.
Attackers targeted cloud data and recovery controls after compromising two Azure service principals in the same tenant. One identity handled reconnaissance, while the other performed discovery, collected credentials, and carried out destructive operations. The destructive stage lasted seven minutes and targeted more than 100 storage accounts, along with a Key Vault, Function Apps, Virtual Machines, and App Services. The attackers also tried to remove backup and recovery protections.
Because these were valid application identities, the destructive activity could resemble normal cloud administration. Workload identities therefore need the same ownership, oversight, and risk controls as powerful human accounts. Defenders should rotate exposed secrets, narrow service-principal roles, protect backups with independent locks, and alert on bulk deletions and key requests. Existing resource locks and account-level protections prevented some deletions in this case, showing the value of safeguards that remain effective even when a privileged identity is compromised. Automation can compress cloud destruction into minutes. Audit all privileged service principals, rotate any publicly exposed secrets, and apply independent deletion locks to critical data and recovery resources.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.