In January 2025, Microsoft unsealed a lawsuit against a hacking-as-a-service operation that had broken into its Azure OpenAI Service using API keys stolen from its own customers. According to Microsoft's Digital Crimes Unit, members of the group, which Microsoft tracks as Storm-2139, "exploited exposed customer credentials scraped from public sources to unlawfully access accounts with certain generative AI services." They altered those services to bypass Microsoft's safety guardrails, then resold access with instructions for generating harmful content, including non-consensual sexual images of celebrities. Microsoft first saw the activity in July and August 2024, filed suit in December 2024, seized a website central to the scheme and, in February 2025, named four alleged developers in Iran, the UK, Hong Kong and Vietnam. It is a clear case of LLMjacking: the victims whose keys were stolen paid for, and were associated with, an AI service used by criminals.
Key takeaways
- Storm-2139 accessed Azure OpenAI with API keys leaked by "multiple" Microsoft customers and scraped from public sources, according to Microsoft and The Register.
- The group modified the services to bypass safety guardrails and resold access as a hacking-as-a-service offering with tools such as de3u, which sends DALL-E image requests through Microsoft's API.
- Microsoft says the network had creators, providers and end users, and it named four alleged developers: Arian Yadegarnia ("Fiz"), Alan Krysiak ("Drago"), Ricky Yuen ("cg-dot") and Phát Phùng Tấn ("Asakuri").
- Microsoft discovered the activity in July to August 2024, sued in December 2024 and seized a website used by the operation; it is preparing criminal referrals.
- The identity lesson: an AI service API key is a spending and content-generation credential, and leaking one hands attackers both your bill and your reputation.
At a glance
| Organisations | Microsoft (Azure OpenAI Service); multiple Microsoft customers whose API keys were stolen, including some US companies |
|---|---|
| When | Activity discovered July to August 2024; lawsuit filed 19 December 2024; unsealed January 2025; defendants named 27 February 2025 |
| Attacker | Storm-2139, a global network Microsoft calls the "Azure Abuse Enterprise"; four named alleged developers in Iran, the UK, Hong Kong and Vietnam, and others in the US and elsewhere |
| Entry point | Azure OpenAI API keys leaked by customers and scraped from public sources |
| Identities abused | Customer Azure OpenAI API keys; the customers' Azure OpenAI accounts |
| Impact | Customers' AI services modified and resold for generating harmful content, including non-consensual intimate images; legal action and infrastructure seizure by Microsoft |
| Category | NHI, LLM and AI platform. Incident class: confirmed NHI breach (stolen AI service API keys, LLMjacking) |
What happened
Microsoft's Digital Crimes Unit filed a civil lawsuit in the Eastern District of Virginia on 19 December 2024 against ten unnamed defendants. When the filings were unsealed in January 2025, The Register reported that the complaint accused them "of using API keys stolen from 'multiple' Microsoft customers along with custom-designed software to break into computers running Microsoft's Azure Open AI service." Microsoft said it uncovered the scheme in July 2024 and did not know exactly how the keys were stolen. CyberScoop reported that some of the stolen keys belonged to US companies and that the activity was first discovered between July and August 2024.
Once inside, the group used its access to "create harmful content in violation of Microsoft's policies and through circumvention of Microsoft's technical protective measures," according to the complaint quoted by The Register, and resold that access as a "hacking-as-a-service scheme". Tools such as de3u let customers of the scheme send image generation requests to the DALL-E model available in Azure OpenAI. A court order let Microsoft seize a website central to the operation, which it said would help it "gather crucial evidence about the individuals behind these operations."
On 27 February 2025, Microsoft filed an amended complaint naming four alleged developers. "Members of Storm-2139 exploited exposed customer credentials scraped from public sources to unlawfully access accounts with certain generative AI services. They then altered the capabilities of these services and resold access to other malicious actors, providing detailed instructions on how to generate harmful and illicit content, including non-consensual intimate images of celebrities and other sexually explicit content," Microsoft wrote. It described the network as creators, who built tools; providers, who modified and supplied them; and users, who generated the content. Microsoft said it had identified two further actors in the US and was preparing criminal referrals. After the seizure, some members turned on each other and doxed Microsoft's lawyers, Microsoft said.
Timeline
| Date | Event |
|---|---|
| July 2024 | Microsoft discovers abuse of Azure OpenAI with stolen customer API keys. |
| 19 December 2024 | Microsoft files a civil lawsuit against ten unnamed defendants in the Eastern District of Virginia. |
| January 2025 | Court filings are unsealed; Microsoft seizes a website used by the operation. |
| 27 February 2025 | Microsoft names four alleged developers in an amended complaint and describes Storm-2139. |
How it happened: the identity attack path
- Keys leaked by customers. Azure OpenAI API keys belonging to multiple Microsoft customers were exposed publicly.
- Keys harvested. Storm-2139 members scraped the exposed credentials from public sources.
- Accounts accessed. The group used the keys to reach customers' Azure OpenAI deployments.
- Guardrails bypassed. Custom tools altered the services' capabilities to get around safety protections.
- Access resold. Providers sold access and instructions to end users who generated harmful content at the victims' expense.
Impact
- Victim customers: their Azure OpenAI accounts were used without permission to generate prohibited content; the full number has not been published.
- Harm to third parties: non-consensual intimate imagery of celebrities and other sexually explicit content, according to Microsoft.
- Response: website seized, defendants named and criminal referrals being prepared.
What this means for NHI governance
This is one named case of the wider pattern we describe in our LLMjacking page: attackers steal the credentials organisations use to call AI models and then use, or resell, that access. The keys here were leaked by customers, not stolen from Microsoft, and they worked from anywhere for anyone. The costs, the policy violations and the reputational link all fall on the key's owner.
AI service keys deserve the same care as cloud keys. They should never be committed to code or client-side apps, should be scoped to specific deployments, should expire, and should be monitored for unusual usage volume or content types. Where possible, keyless authentication through managed identities removes the key entirely. See our LLMjacking Guide and API Key Management Guide.
Recommendations
- Find and revoke exposed AI service keys. Scan code, notebooks and public repositories for Azure OpenAI and other model keys. See the LLMjacking Guide.
- Use managed identities instead of keys. Keyless authentication to AI services removes the credential attackers scrape.
- Monitor usage and spend per key. Sudden spikes in image generation or content filter hits are signs of abuse.
- Restrict network access to AI deployments. Private endpoints and IP restrictions stop stolen keys working from the internet. See the AI Infrastructure Workload Identity Guide.
- Rotate keys regularly and on any suspicion. See our API Key Management Guide.
Frequently asked questions
What is Storm-2139?
Storm-2139 is Microsoft's name for a global network that used stolen customer API keys to access Azure OpenAI, bypass its guardrails and resell access for generating harmful content. Microsoft named four alleged developers in February 2025.
How did the attackers get Azure OpenAI access?
They used API keys that multiple Microsoft customers had exposed, which Microsoft says were scraped from public sources. Microsoft has said it does not know exactly how every key was stolen.
Is this LLMjacking?
Yes. LLMjacking is the theft of access to hosted AI models using someone else's credentials. Storm-2139 went further by reselling that access as a service.
Related NHI Mgmt Group resources
LLMjacking · 12,000 Secrets in LLM Training Data · LLMjacking Guide · API Key Management Guide · AI Infrastructure Workload Identity Guide
How NHI Mgmt Group can help
AI service keys are spreading faster than most teams can track them. We help organisations inventory model credentials, move to keyless access and monitor for abuse. See our NHI and AI agent security training.
References
- CyberScoop: Microsoft moves to disrupt hacking-as-a-service scheme that's bypassing AI safety measures (10 January 2025)
- The Register: Microsoft sues 'foreign-based' cyber-crooks, seizes sites used to abuse AI (13 January 2025)
- Microsoft (Steven Masada): Disrupting a global cybercrime network abusing generative AI (27 February 2025)
- The Register: Microsoft names alleged credential-snatching 'Azure Abuse Enterprise' operators (28 February 2025)