Microsoft IDs developers behind alleged generative AI hacking-for-hire scheme
ID: 15c3743e-4548-5fd3-ae18-016ecc253dbc
STIX ID: report--15c3743e-4548-5fd3-ae18-016ecc253dbc
Feed Name: CyberScoop
Microsoft alleges an international hacking-as-a-service operation (Storm-2139) that exploited exposed Microsoft credentials and stolen API keys to sell access to Azure OpenAI accounts, which were then used to generate harmful content—including non-consensual intimate images and deepfakes. The company identified multiple alleged operators across Iran, Hong Kong, Vietnam, the UK and US, has sought court seizures of infrastructure, shared evidence of the group’s communications, and is preparing criminal referrals to domestic and foreign law enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
