Follow the latest coverage, related explainers and connected technology stories.
Microsoft observed activity linked to Storm-3168 that carried out extensive reconnaissance and deletion of Azure resources, along with the collection of storage access keys, using compromised service identities. The company believes the pattern is consistent with potential ransomware objectives, although no ransom note was observed and data exfiltration was not confirmed in this incident.