Sandboxes didn't sound like security theatre to me. They were prevented from accessing the Internet but discovered they could edit /etc/hosts to point Azure storage subdomains to arbitrary IPs.

There's no theatre there, just an oversight that allowed them to access the Internet while no doubt evading security tools.