Two pieces of data landed within days of each other this week, and together they tell a story every small-business owner should hear before the end of the quarter.
First, the volume story. Security firm NCC Group published its monthly threat-intelligence report on September 23, 2026. A total of 1,073 firms fell victim to ransomware attacks globally in August — the highest monthly number recorded this year. North America was the most targeted region, with almost half (44%) of all attacks, followed by Europe with over a quarter (26%). 83 distinct ransomware groups were active during August alone, up sharply from the previous 2026 peak of 70 groups recorded in June. These are publicly disclosed figures. NCC Group's senior manager of operational threat intelligence noted that incidents resolved through payment or kept off criminal leak sites remain invisible in these statistics, meaning the true volume is almost certainly higher.
If a record like that feels abstract, the second story makes it concrete.
What JADEPUFFER Actually Did
Microsoft Security Research identified malicious cloud activity associated with JADEPUFFER, a threat actor discovered by Sysdig in July 2026 and reported to be the first documented agentic ransomware operation. Microsoft tracks the group under the name Storm-3168. "Agentic" means the attack was orchestrated by an artificial-intelligence (AI) agent — software that reasons, plans, and acts through a sequence of steps without a human directing each move.
JADEPUFFER entered the security community's vocabulary on July 1, 2026, when Sysdig published findings describing a ransomware operation conducted entirely by a large language model (LLM) — no human operator at the keyboard, no fixed exploit script, just an AI agent chaining reconnaissance, credential theft, lateral movement, and a destructive extortion sequence autonomously from a single initial foothold.
Microsoft's September 25 report documented what Storm-3168 did to a real organization's Microsoft Azure cloud tenant. In early June 2026, the first compromised service principal began mapping the victim's Azure environment, running for about 15 and a half hours and logging more than 300 successful read operations — including access keys for storage accounts and Azure Site Recovery storage. Then the destruction phase started. Storm-3168 used two compromised service principals to delete more than 100 Azure storage accounts in approximately seven minutes.
Seven minutes. That is not enough time for most IT providers to receive an alert, open a ticket, and type a response.
"The destructive operations targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services," the Microsoft researchers said. The attacker also removed Azure Site Recovery locks to prevent restoration.
How Did the Attacker Get In?
This is the part that should make any owner uncomfortable. The door was not kicked in — it was left unlocked by accident. Microsoft could not determine exactly how the initial access occurred, but noted that credentials for one service principal appeared in a public GitHub issue before the attacks. In plain English: someone on the team pasted a cloud password into a public code-collaboration comment. The attacker's AI agent found it, probably by scanning public repositories automatically, and used it.
A service principal is essentially a machine identity — a set of credentials your cloud-connected software uses to authenticate to Microsoft Azure on your behalf. Most small businesses that use Microsoft 365, Azure-hosted accounting or point-of-sale systems, or any software vendor that runs on Azure are living with service principals they never personally configured. Your vendor configured them. Their security hygiene is now your exposure.
What Survived — and Why
Not everything was destroyed. The only resources that survived were the ones already protected by Azure resource locks and storage-level deletion protection — passive controls that had been configured before the attack began. Attempts to delete Azure SQL databases failed because the attacker used an unsupported API version, and attempts to remove recovery protection locks also failed.
That is the single most actionable sentence in the entire Microsoft report. Pre-configured defenses held. Defenses that were not in place before the seven-minute clock started did not get a chance to matter.
The Bigger Picture: Volume Meets Velocity
The August data showed ransomware operators continuing to rely on established intrusion methods while expanding their use of data extortion. Some cyber-criminal groups have moved away from encryption in favor of going straight for outright data theft and extortion. That matters because many small businesses believe backups fully protect them against ransomware. They do against encryption. They do not protect against a criminal who copies your customer records and then threatens to publish them — no decryption key required.
"The challenge is not preparing for sentient AI, but for highly capable systems that can operate at machine speed while pursuing narrowly defined goals," NCC Group reported. That framing is worth sitting with. Nobody is claiming the AI is conscious. It just moves faster than your incident response.
What This Means for Your Business — and What to Ask
You probably use some form of cloud storage: Microsoft 365, Google Workspace, QuickBooks Online, a cloud-based point-of-sale, a payroll platform. Every one of those services authenticates to a cloud environment using credentials that could, in theory, be exposed. You are not Microsoft's target; you are collateral opportunity for a tool sweeping the internet for anything unlocked.
Here are the specific questions to put to your managed IT provider or cloud administrator this week — no technical background required to ask them:
- "Do we have resource locks or deletion protection enabled on our cloud storage and backup environments?" If they have to look it up, that is your answer.
- "Have you scanned our code repositories, internal wikis, and ticketing systems for any exposed cloud credentials or API keys?" Secret-scanning tools exist specifically for this and take minutes to run.
- "Are our service-principal permissions limited to exactly what each application needs — and no more?" This is called least-privilege access control, and it means a compromised credential can only reach a narrow slice of your environment rather than everything.
- "Are our cloud backups stored in a separate account that our primary environment cannot delete?" Immutable, independently locked backups are what separated survivors from victims in the JADEPUFFER incident.
- "How quickly would we know if a cloud identity started reading hundreds of our storage account keys?" Fifteen hours of reconnaissance ran undetected in the documented attack. Your provider should have an answer measured in minutes, not hours.
None of these questions require you to understand cloud architecture. They require your provider to have answers. If the answers are vague, that gap is worth closing before the AI finds it first.
Sources
- Microsoft Security Blog — Storm-3168: Agentic-driven cloud attacks using compromised service principals (2026-09-25)
- The Hacker News — JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources (2026-09-28)
- TechTimes — AI Ransomware Wiped 100 Azure Accounts in 7 Minutes: Only Pre-Configured Locks Survived (2026-09-28)
- Security Online — JadePuffer agentic AI attacks target Azure, destroy cloud resources (2026-09-30)
- NCC Group — NCC Group Monthly Threat Pulse – Review of August 2026 (2026-09-23)
- Infosecurity Magazine — Ransomware Attacks Reach Record High for 2026 (2026-09-23)
- TechTarget / SearchSecurity — August's ransomware activity hit new high for the year (2026-09-30)
- QUE.com — Ransomware Groups Shift Attack Strategies Toward Cloud Infrastructure (2026-09-30)
