account is hacked and permission to subscription has been blocked.

pouuggk 20 Reputation points
2023-11-25T14:40:00.5266667+00:00

I posted earlier that I had been hacked, deleted all the resources in my subscription and deactivated it, but since around 7pm, hackers have turned my subscriptions back to activation and the cost is now increasing as well But we don't even see the log-in records of the hackers. What should I do. I'm also not sure if this is going to be resolved, but I'm scared how to deal with this huge cost when it's not.

Azure Cost Management
Azure Cost Management
A Microsoft offering that enables tracking of cloud usage and expenditures for Azure and other cloud providers.
2,099 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. AdamZachary 2,871 Reputation points
    2023-11-25T21:02:16.76+00:00

    Immediate Actions if Azure Subscription is Compromised:

    • Change credentials for tenant admins and RBAC access on Azure Subscriptions.
    • Review and verify all global admin user password recovery emails and phone numbers within Microsoft Entra ID.
    • Disable/Delete any unfamiliar Service Principal or user inside your Entra ID. "He might have created a SPN inside your Entra ID with Global Admin permissions".
    • Investigate the risk by reviewing Identity Protection’s Risk Reports.
    • Review the Microsoft Entra sign-in logs on the customer tenant to see unusual sign-in patterns.
    • After evicting malicious actors, clean the compromised resources and keep a close eye on the impacted subscription.
    • Check for any unauthorized activity in the Azure Activity Log.
    • Review spending anomalies against the customer's spending budget in Azure cost management.
    • Disable or delete any compromised resources​​.

    Given the severity of the situation you can create a support ticket from Azure Portal.

    Hope this helps

    0 comments No comments