# T1530 Data from Cloud Storage

> As of 2026-10-05, T1530 (Data from Cloud Storage) appears in 135 tracked threats, first reported 2026-02-02 and most recently 2026-10-04, with linked actors including ShinyHunters, Scattered LAPSUS$ Hunters, Scattered Spider; it most often appears alongside T1528 (Steal Application Access Token).

- **Tracked threats:** 135 (42 critical, 74 high, 17 medium, 1 low)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-04
- **Threat actors:** 50
- **Detection rules:** 173 (counts only; Blue tier and above)

## Key facts

- **ID:** T1530
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1530/

## Activity timeline

T1530 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 38 reports, and 135 of the 135 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1530 Data from Cloud Storage is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 135 of 2623 tracked threats (5.1%) to it; by severity that is 42 critical, 74 high, 17 medium, 1 low.

Threats that use T1530 most often also use [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (77 threats), [T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567) (73 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (70 threats), [T1526 Cloud Service Discovery](https://intel.threadlinqs.com/technique/T1526) (67 threats), [T1213 Data from Information Repositories](https://intel.threadlinqs.com/technique/T1213) (65 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

50 tracked threat actors appear in the threats that use T1530; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (17), [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (8), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (8), [The Com](https://intel.threadlinqs.com/actor/The%20Com) (8), [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) (8).

## Mitigations

MITRE ATT&CK lists 6 mitigations for T1530.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)
- [M1041 Encrypt Sensitive Information](https://attack.mitre.org/mitigations/M1041/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1530, per MITRE ATT&CK.

- Cloud Service — Cloud Service Metadata
- Cloud Storage — Cloud Storage Access

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 17
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 8
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 8
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 8
- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 8
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 7
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 7
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 7
- [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) — 6
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 6
- [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) — 4
- [Icarus](https://intel.threadlinqs.com/actor/Icarus) — 4

## Tracked threats

The 30 most recent of 135 tracked threats that use T1530.

- [Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guilty](https://intel.threadlinqs.com/threat/TL-2026-2908) — high — 2026-10-04
- [Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Group](https://intel.threadlinqs.com/threat/TL-2026-2829) — high — 2026-10-01
- [OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)](https://intel.threadlinqs.com/threat/TL-2026-2628) — high — 2026-09-23
- [Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials](https://intel.threadlinqs.com/threat/TL-2026-2626) — medium — 2026-09-23
- [ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak](https://intel.threadlinqs.com/threat/TL-2026-2620) — critical — 2026-09-22
- [BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection](https://intel.threadlinqs.com/threat/TL-2026-2610) — medium — 2026-09-21
- [Dell ObjectScale Critical Deserialization Flaw (CVE-2026-70416, CVSS 10.0) Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2475) — critical — 2026-09-13
- [Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-2472) — high — 2026-09-13
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — critical — 2026-09-06
- [DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patients](https://intel.threadlinqs.com/threat/TL-2026-2328) — high — 2026-09-04
- [FBI/IC3 PSA260901: OAuth Consent Phishing Campaign Targeting High-Profile Individuals via Commercial…](https://intel.threadlinqs.com/threat/TL-2026-2286) — high — 2026-09-01
- [ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and…](https://intel.threadlinqs.com/threat/TL-2026-2208) — critical — 2026-08-29
- [Hospital for Sick Children (SickKids) Data Breach Exposes Employee Information via Third-Party Software…](https://intel.threadlinqs.com/threat/TL-2026-2106) — medium — 2026-08-21
- [Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical…](https://intel.threadlinqs.com/threat/TL-2026-2103) — high — 2026-08-21
- [Insider Threat Landscape: Dark Web Recruitment & Access Broker Trends — July 2026](https://intel.threadlinqs.com/threat/TL-2026-2078) — medium — 2026-08-20
- [Critical Microsoft Copilot CoSnitch Vulnerability (CVE-2026-24301) Enabled One-Click Data Theft From…](https://intel.threadlinqs.com/threat/TL-2026-2065) — critical — 2026-08-19
- [Personal GitHub Repositories Are a Major Blind Spot for Corporate Secret Leaks (Wiz Research)](https://intel.threadlinqs.com/threat/TL-2026-2009) — medium — 2026-08-13
- [UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data…](https://intel.threadlinqs.com/threat/TL-2026-1962) — high — 2026-08-09
- [UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for…](https://intel.threadlinqs.com/threat/TL-2026-1959) — critical — 2026-08-09
- [UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijacking](https://intel.threadlinqs.com/threat/TL-2026-1926) — high — 2026-08-07
- [Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables Gmail/Slack/X/Claude.ai Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-1923) — high — 2026-08-07
- [OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applications](https://intel.threadlinqs.com/threat/TL-2026-1913) — medium — 2026-08-06
- [Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal OAuth Tokens](https://intel.threadlinqs.com/threat/TL-2026-1873) — high — 2026-08-04
- [Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1871) — high — 2026-08-04
- [Apple challenges UK Home Office Technical Capability Notice over encrypted iCloud access (Advanced Data…](https://intel.threadlinqs.com/threat/TL-2026-1868) — high — 2026-08-04
- [CosmosEscape: Gremlin API Sandbox Escape Exposed Platform-Wide Key for Every Azure Cosmos DB Database](https://intel.threadlinqs.com/threat/TL-2026-1802) — critical — 2026-07-31
- [Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys](https://intel.threadlinqs.com/threat/TL-2026-1793) — high — 2026-07-31
- [ShutterGap: Ephemeral Public Exposure of AWS RDS/DocumentDB Snapshots, AMIs & SSM Documents Evades…](https://intel.threadlinqs.com/threat/TL-2026-1788) — medium — 2026-07-31
- [CosmosEscape: Platform-Wide Cosmos Master Key Exposure via Gremlin API Sandbox Escape in Azure Cosmos DB](https://intel.threadlinqs.com/threat/TL-2026-1784) — critical — 2026-07-31
- [CosmosEscape: Azure Cosmos DB Gremlin Sandbox Escape Exposed Platform-Wide Master Key (CVE-2026-66803)](https://intel.threadlinqs.com/threat/TL-2026-1779) — critical — 2026-07-30

## Related CVEs

CVEs referenced by the tracked threats that use T1530, most frequent first.

- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-39935](https://intel.threadlinqs.com/cve/CVE-2021-39935)
- [CVE-2025-32711](https://intel.threadlinqs.com/cve/CVE-2025-32711)
- [CVE-2025-3648](https://intel.threadlinqs.com/cve/CVE-2025-3648)
- [CVE-2025-55183](https://intel.threadlinqs.com/cve/CVE-2025-55183)
- [CVE-2025-55184](https://intel.threadlinqs.com/cve/CVE-2025-55184)
- [CVE-2025-59536](https://intel.threadlinqs.com/cve/CVE-2025-59536)
- [CVE-2025-67779](https://intel.threadlinqs.com/cve/CVE-2025-67779)
- [CVE-2026-20223](https://intel.threadlinqs.com/cve/CVE-2026-20223)
- [CVE-2026-2031](https://intel.threadlinqs.com/cve/CVE-2026-2031)
- [CVE-2026-21852](https://intel.threadlinqs.com/cve/CVE-2026-21852)
- [CVE-2026-24301](https://intel.threadlinqs.com/cve/CVE-2026-24301)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-33626](https://intel.threadlinqs.com/cve/CVE-2026-33626)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-42824](https://intel.threadlinqs.com/cve/CVE-2026-42824)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-55255](https://intel.threadlinqs.com/cve/CVE-2026-55255)
- [CVE-2026-63077](https://intel.threadlinqs.com/cve/CVE-2026-63077)
- [CVE-2026-65617](https://intel.threadlinqs.com/cve/CVE-2026-65617)
- [CVE-2026-65921](https://intel.threadlinqs.com/cve/CVE-2026-65921)
- [CVE-2026-65923](https://intel.threadlinqs.com/cve/CVE-2026-65923)
- [CVE-2026-65924](https://intel.threadlinqs.com/cve/CVE-2026-65924)
- [CVE-2026-65925](https://intel.threadlinqs.com/cve/CVE-2026-65925)
- [CVE-2026-66014](https://intel.threadlinqs.com/cve/CVE-2026-66014)
- [CVE-2026-66803](https://intel.threadlinqs.com/cve/CVE-2026-66803)

## Detection coverage

Threadlinqs maintains 173 detection rules mapped to T1530 (SPL 63, KQL 63, Sigma 47). Rule content is available to Blue tier accounts and above; this page shows counts only.

173 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1530
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
