
Microsoft has taken legal action against a foreign-based cybercriminal group accused of bypassing security protocols on its Azure OpenAI platform to generate harmful content and profit from unauthorized access. The lawsuit, filed in December 2024 in the U.S. District Court for the Eastern District of Virginia, targets ten unidentified individuals alleged to have orchestrated the attack.
The tech giant asserts that the group stole customer credentials by scraping publicly available websites and used custom software to manipulate Azure OpenAI services. These actions allegedly allowed them to override safety mechanisms, repurpose the platform for illicit use, and resell access to other malicious actors.
Azure OpenAI, a service enabling businesses to integrate OpenAI technologies into their cloud applications, powers Microsoft products such as GitHub Copilot, an AI-assisted coding tool. The lawsuit outlines how the cybercriminals exploited the platform to create and distribute illicit content, violating Microsoft’s policies and terms of service.
According to court documents, the attackers infiltrated the system using stolen Azure API keys and Entra ID credentials. They then modified the AI services to suit their purposes, including generating offensive imagery through tools like DALL-E. The group also provided step-by-step guides to other bad actors, facilitating widespread misuse of the platform.
Microsoft discovered the breach in July 2024 and has since taken significant steps to mitigate the damage. The company has implemented enhanced security measures, revoked unauthorized access, and sought legal permission to seize the website aitism[.]net, a central hub for the operation. The seizure aims to dismantle the group’s infrastructure, identify the perpetrators, and gather critical evidence.
The cybercriminals’ activities extended beyond Azure OpenAI, with evidence suggesting they targeted other AI providers, including OpenAI, Anthropic, AWS Bedrock, and Google Cloud Vertex AI. Microsoft’s Digital Crimes Unit (DCU) labeled the operation part of a larger “Azure Abuse Enterprise,” citing its coordination and persistence.
The attackers reportedly used proxy services like “de3u” to mask their activities and facilitate unauthorized API calls. Although some of their infrastructure, including a GitHub repository associated with the proxy tool, has been removed, Microsoft noted efforts by the group to erase traces of their activities, such as deleting pages on platforms like Rentry.org.
In response to the incident, Microsoft emphasized its dedication to safeguarding its platforms and holding cybercriminals accountable. The company seeks injunctive relief, damages, and other remedies to prevent further exploitation. It also highlighted violations of multiple U.S. laws, including the Computer Fraud and Abuse Act and the Digital Millennium Copyright Act.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543