WHS A.I CyberSecurity Scoring
WHS
Company Information
Website:https://whitehat.eu
Employees number:26
Number of followers:3,958
NAICS:
Industry Type:Information Technology & Services
Homepage:whitehat.eu
WHS Risk Score (AI oriented)
Between 650 and 699
WHSInformation Technology & Services
Updated:
26/09/2026
26/09/2026
655/1000
Weak
B
WHS Global Score (TPRM)
xxxx
WHSInformation Technology & Services
Score locked

WHSWeak
Current Score
655B (WEAK)
01000
1 incidents
-98 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
655
SEPTEMBER 2026
753
Ransomware
25 Sep 2026 • WHS
Microsoft and Unnamed Affected Organization: Storm-3168: Agentic-driven cloud attacks using compromised service principals
JADEPUFFER: Microsoft Uncovers Destructive Cloud Attack by Storm-3168
655
CRITICAL-98
MICWHI1790396923
JADEPUFFER: Microsoft Uncovers Destructive Cloud Attack by Storm-3168
In July 2026, Microsoft Security Research exposed JADEPUFFER, a threat actor first documented by Sysdig as the first agentic ransomware operation a sophisticated, AI-driven attack framework targeting cloud environments. Tracked by Microsoft as Storm-3168, the group has evolved its tactics, demonstrating a shift toward automated, large-scale destructive operations in Azure.
### The Attack: A Coordinated Cloud Destruction Campaign
In early June 2026, Storm-3168 compromised two Azure service principals within the same tenant, dividing tasks between reconnaissance and destruction/credential theft. Over 15 hours, the first principal conducted 300+ read operations, mapping the victim’s Azure environment including Virtual Machines, subscriptions, resource groups, and storage accounts. The second principal followed, executing a high-speed, scripted attack in under 35 minutes, with a 7-minute destructive sequence targeting:
- 100+ Azure Storage accounts (most successfully deleted)
- Azure Key Vaults, Function Apps, and App Service plans (all deleted)
- Azure SQL databases (deletion failed due to unsupported API version)
- Backup and recovery protections (Site Recovery locks, Backup protection locks unsuccessfully targeted)
The threat actor also collected storage account access keys, potentially enabling data exfiltration, though no ransom note or confirmed exfiltration was observed. The attack’s parallel targeting of multiple resource types storage, databases, and recovery mechanisms aligns with ransomware objectives, aiming to maximize disruption and impair recovery.
### Initial Access: A Preventable Exposure
While the exact compromise vector remains unconfirmed, Microsoft identified a critical misstep: the client ID, client secret, and tenant ID of the compromised service principal were exposed in plaintext in a public GitHub issue by an employee of the affected organization. Though later edited, the credentials remained accessible via the issue’s edit history, underscoring a key risk: publicly exposed secrets remain valid until revoked, regardless of redaction.
Additionally, Storm-3168 had been probing Azure App Services since early 2026, scanning for vulnerable endpoints (e.g., WordPress admin paths, PHP-CGI, LangFlow’s code validation API). However, these probes did not directly lead to the observed breach.
### Automation & AI-Driven Tactics
The attack’s precision and speed including overlapping token usage and divided labor between service principals reveal automated execution, likely leveraging AI-driven orchestration. Microsoft observed:
- Five unique tokens issued for the destructive principal, with two active simultaneously (one for storage deletion, another for mixed SQL/storage attacks).
- Role-based permissions exploited: Storage Account Contributor (for deletions), Contributor (for app resource deletions), and SQL DB Contributor (for failed database attacks).
- Selective targeting: A storage account in the same resource group as deleted resources was spared later accessed for key retrieval, suggesting strategic credential harvesting.
### Defensive Lessons & MITRE ATT&CK Techniques
The incident highlights critical vulnerabilities in cloud security:
- Exposed credentials (T1078.004 – Valid Cloud Accounts) enabled the attack.
- Discovery operations (T1526 – Cloud Service Discovery) mapped the environment before destruction.
- Data destruction (T1485) and recovery inhibition (T1490) were core objectives.
- Public-facing app probing (T1190) preceded the breach.
### Key Takeaways
Storm-3168’s JADEPUFFER campaign marks a new era of AI-augmented cloud attacks, where threat actors automate complex, multi-stage operations at scale. The incident underscores:
- The persistent risk of exposed credentials, even after redaction.
- The effectiveness of Azure resource locks in mitigating damage.
- The need for least-privilege access and AI-driven defense tools (e.g., Microsoft’s Project Perception, MDASH) to counter automated threats.
While no ransom demand was confirmed, the attack’s destructive intent and credential theft align with extortion-focused tactics, signaling a growing threat to cloud-native environments.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
753
JULY 2026
753
JUNE 2026
753
MAY 2026
753
APRIL 2026
753
MARCH 2026
753
FEBRUARY 2026
753
JANUARY 2026
753
DECEMBER 2025
753
NOVEMBER 2025
753
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for WHS ??
What was WHS's A.I Rankiteo Cyber Score in September 2026 ??
What was WHS's A.I Rankiteo Cyber Score in August 2026 ??
What was WHS's A.I Rankiteo Cyber Score in July 2026 ??
What was WHS's A.I Rankiteo Cyber Score in June 2026 ??
What was WHS's A.I Rankiteo Cyber Score in May 2026 ??
What was WHS's A.I Rankiteo Cyber Score in April 2026 ??
What was WHS's A.I Rankiteo Cyber Score in March 2026 ??
What was WHS's A.I Rankiteo Cyber Score in February 2026 ??
What was WHS's A.I Rankiteo Cyber Score in January 2026 ??
What was WHS's A.I Rankiteo Cyber Score in December 2025 ??
What was WHS's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on WHS's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with WHS ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view WHS's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?