Suspicious activity

Storage account was deleted from malicious IP address

Risk Level

Informational (4)



Orca detected that an API call to delete storage account was made from a malicious IP address - {MaliciousIp.MaliciousIp}, the operation was successful. This action may indicate of a presence of an unauthorized actor in the cloud environment, trying to establish an exfiltration mechanism or committing a data deletion activities in the subscription.
  • Recommended Mitigation

    It is recommended to review the permissions which were used to make this api call. In addition, review the deleted storage account content and restore it if needed.