Activity timeline
T1589 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 85 reports, and 228 of the 228 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1589 Gather Victim Identity Information is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix. Threadlinqs maps 228 of 2623 tracked threats (8.7%) to it; by severity that is 35 critical, 142 high, 48 medium, 3 low.
Threats that use T1589 most often also use T1566 Phishing (132 threats), T1583 Acquire Infrastructure (124 threats), T1657 Financial Theft (106 threats), T1567 Exfiltration Over Web Service (99 threats), T1036 Masquerading (95 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
90 tracked threat actors appear in the threats that use T1589; the most frequent are Scattered Spider (8), The Com (8), ShinyHunters (7), APT38 (6), UNC6240 (6).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1589.
Data sources
Telemetry that can reveal T1589, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content
Threat actors using it
Tracked threats
The 30 most recent of 228 tracked threats that use T1589.
- Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and…high
- Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data…high
- Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Rolesmedium
- Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…medium
- Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attackshigh
- AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…medium
- Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)medium
- Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Scriptmedium
- TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…high
- Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltratedhigh
- Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Datahigh
- Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalistshigh
- Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencieshigh
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…high
- Revolut Discloses Data Breach via Government-Impersonation Social Engineering, Exposing Customer Financial…high
- LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Techniquemedium
- Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence…high
- Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leakhigh
- ASCII Smuggling Phishing Campaign Uses Invisible Unicode Tags-Block Characters to Evade Filters, Targeting…high
- ADCS ESC1 Privilege Escalation: CISA AA26-237A Red Team Findings and CA Database Hunting Methodologyhigh
- Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…high
- "The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware…high
- AnonyMousKIT: AI-Powered Phishing-as-a-Service Platform Stealing Apple IDs from Stolen iPhoneshigh
- Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…high
- Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)high
- Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimihigh
- Pokémon Center Confirms Customer Data Breach via CEVA Logistics Supply-Chain Compromisehigh
- Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap…medium
- SafePal Data Breach: Order-Tracking Plug-in Authorization Flaw Exposes 39,798 Crypto Wallet Customers' PII…medium
- Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage…high
Detection coverage
Threadlinqs maintains 102 detection rules mapped to T1589 (SPL 37, KQL 34, Sigma 31). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1589.001 Credentials — 30 tracked threats
- T1589.002 Email Addresses — 51 tracked threats
- T1589.003 Employee Names — 12 tracked threats