Storm-2949 (May 2026): From a Fake IT Call to an Azure-Wide Breach
On May 18, 2026, Microsoft Threat Intelligence published details of Storm-2949, a threat actor that turned a single social-engineered identity into a breach spanning Microsoft 365 and multiple Azure services.
What Microsoft described
- Initial access: Storm-2949 targeted the self-service password reset (SSPR) process with social engineering, impersonating IT support and tricking users — including IT personnel and senior leaders — into approving fraudulent MFA prompts.
- Identity takeover: the actor compromised multiple cloud identities and removed legitimate MFA methods.
- Discovery: they enumerated users and applications through Microsoft Graph.
- Azure abuse: using Azure RBAC permissions held by compromised identities, they accessed Key Vaults, App Services and Storage accounts, and changed firewall rules and access controls.
- VM compromise: they used VMAccess extensions and Run Command to take control of virtual machines, installed ScreenConnect for persistence and disabled Microsoft Defender Antivirus.
- Exfiltration: data was taken from Microsoft 365, Azure Storage, SQL databases and production applications — across SaaS, PaaS and IaaS.
Microsoft's recommended mitigations
- Phishing-resistant MFA for administrators.
- Conditional Access with device compliance.
- Least privilege for Azure RBAC.
- Defender deployed across endpoints and cloud resources.
- Monitoring of Azure management events and restrictions on VM extensions.
- Immutable storage and private endpoints.
- Diagnostic logging and regular Key Vault access audits.
Why it matters
Storm-2949 shows how identity is the bridge between SaaS and cloud infrastructure. A help desk–style lure against SSPR led to control of Azure resources. Organizations often secure Microsoft 365 and Azure separately; attackers treat them as one environment.
Sources
- How to Harden SSPR, Azure RBAC and VM Run Command Against Identity-Led Attacks How-To & Hardening
- Detecting SSPR Social Engineering: Defender for Cloud and Sentinel KQL Detection & Response
- CIO Brief: One Compromised Identity, Every Cloud Layer CIO Briefings