logo

Microsoft IDs developers behind alleged generative AI hacking-for-hire scheme

ID: 15c3743e-4548-5fd3-ae18-016ecc253dbc

STIX ID: report--15c3743e-4548-5fd3-ae18-016ecc253dbc

Feed Name: CyberScoop

Threat Score
70/100

Date Published: 2025-02-27

Date Updated: 2026-04-21

Author: djohnson

...
...

Microsoft alleges an international hacking-as-a-service operation (Storm-2139) that exploited exposed Microsoft credentials and stolen API keys to sell access to Azure OpenAI accounts, which were then used to generate harmful content—including non-consensual intimate images and deepfakes. The company identified multiple alleged operators across Iran, Hong Kong, Vietnam, the UK and US, has sought court seizures of infrastructure, shared evidence of the group’s communications, and is preparing criminal referrals to domestic and foreign law enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.