Activity timeline
T1530 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 38 reports, and 135 of the 135 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1530 Data from Cloud Storage is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 135 of 2623 tracked threats (5.1%) to it; by severity that is 42 critical, 74 high, 17 medium, 1 low.
Threats that use T1530 most often also use T1528 Steal Application Access Token (77 threats), T1567 Exfiltration Over Web Service (73 threats), T1078 Valid Accounts (70 threats), T1526 Cloud Service Discovery (67 threats), T1213 Data from Information Repositories (65 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
50 tracked threat actors appear in the threats that use T1530; the most frequent are ShinyHunters (17), Scattered LAPSUS$ Hunters (8), Scattered Spider (8), The Com (8), UNC6671 (8).
Mitigations
MITRE ATT&CK lists 6 mitigations for T1530.
Data sources
Telemetry that can reveal T1530, per MITRE ATT&CK.
- Cloud Service — Cloud Service Metadata
- Cloud Storage — Cloud Storage Access
Threat actors using it
Tracked threats
The 30 most recent of 135 tracked threats that use T1530.
- Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guiltyhigh
- Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Grouphigh
- OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)high
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentialsmedium
- ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leakcritical
- BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injectionmedium
- Dell ObjectScale Critical Deserialization Flaw (CVE-2026-70416, CVSS 10.0) Enables Unauthenticated RCEcritical
- Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltrationhigh
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)critical
- DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patientshigh
- FBI/IC3 PSA260901: OAuth Consent Phishing Campaign Targeting High-Profile Individuals via Commercial…high
- ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and…critical
- Hospital for Sick Children (SickKids) Data Breach Exposes Employee Information via Third-Party Software…medium
- Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical…high
- Insider Threat Landscape: Dark Web Recruitment & Access Broker Trends — July 2026medium
- Critical Microsoft Copilot CoSnitch Vulnerability (CVE-2026-24301) Enabled One-Click Data Theft From…critical
- Personal GitHub Repositories Are a Major Blind Spot for Corporate Secret Leaks (Wiz Research)medium
- UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data…high
- UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for…critical
- UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijackinghigh
- Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables Gmail/Slack/X/Claude.ai Account Takeoverhigh
- OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applicationsmedium
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal OAuth Tokenshigh
- Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign…high
- Apple challenges UK Home Office Technical Capability Notice over encrypted iCloud access (Advanced Data…high
- CosmosEscape: Gremlin API Sandbox Escape Exposed Platform-Wide Key for Every Azure Cosmos DB Databasecritical
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeyshigh
- ShutterGap: Ephemeral Public Exposure of AWS RDS/DocumentDB Snapshots, AMIs & SSM Documents Evades…medium
- CosmosEscape: Platform-Wide Cosmos Master Key Exposure via Gremlin API Sandbox Escape in Azure Cosmos DBcritical
- CosmosEscape: Azure Cosmos DB Gremlin Sandbox Escape Exposed Platform-Wide Master Key (CVE-2026-66803)critical
Detection coverage
Threadlinqs maintains 173 detection rules mapped to T1530 (SPL 63, KQL 63, Sigma 47). Rule content is available to Blue tier accounts and above; this page shows counts only.