Compromised Service Principals Wreak Havoc on Azure Resources
Microsoft's Security Research team has identified an automated Azure destruction incident that was traced back to compromised machine identities. The attackers used two compromised service principals, one for discovery and the other for reconnaissance, destructive operations, and credential collection.
The first service principal performed over 300 successful discovery operations in approximately 15.5 hours, while the second attempted more than 150 destructive or credential-related operations within just 35 minutes.
The main destructive sequence lasted about seven minutes and included over 100 attempts to delete storage accounts. Most of these targeted storage accounts were deleted, along with a Key Vault, Function App, and App Service plan.
Microsoft notes that resource locks and storage-level deletion protection blocked some operations, limiting the damage despite the broad access granted by the compromised identities.