Activity timeline
T1589.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 8 reports, and 30 of the 30 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1589.001 Credentials is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of T1589 Gather Victim Identity Information. Threadlinqs maps 30 of 2623 tracked threats (1.1%) to it; by severity that is 3 critical, 22 high, 5 medium.
Threats that use T1589.001 most often also use T1657 Financial Theft (16 threats), T1078.004 Cloud Accounts (13 threats), T1566.002 Spearphishing Link (10 threats), T1078 Valid Accounts (9 threats), T1119 Automated Collection (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
12 tracked threat actors appear in the threats that use T1589.001; the most frequent are Scattered Spider (2), TheHatman (2), UNK_OutFlareAZ (2), APT37 (1), Ghost Stadium (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1589.001.
Threat actors using it
Tracked threats
30 tracked threats use T1589.001.
- Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guiltyhigh
- TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files…high
- Fake American Express "non-compliance" card-lock phishing campaign targets Australiansmedium
- Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image…high
- TELUS Warns Customers of 16-Month Account Takeover Breach via Compromised Credentialsmedium
- OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 /…high
- CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…high
- Password spraying attacks surge 155x as hackers exploit MFA gaps via Azure CLI / ROPC flowhigh
- Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chainshigh
- Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCShigh
- "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's…high
- ZeroBytes Breaches French Tax Authority (DGFiP): Stolen Credentials and MFA Bypass Expose Tax Data of…high
- Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidentshigh
- Coldcard Hardware Wallet Firmware RNG Vulnerability (Yasmarang Fallback) Leads to ~$116M Bitcoin Theftcritical
- Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Datahigh
- Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action…medium
- APT37 Pretexting Campaign: Facebook Social Engineering Delivers RokRAT via Tampered PDFelement Installerhigh
- Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattackhigh
- OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 &…high
- Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft…medium
- Phantom Squatting: Adversaries Preemptively Register AI-Hallucinated Domains to Hijack Software Supply Chain…high
- Phantom Squatting: Attackers Register AI-Hallucinated Domains to Hijack LLM-Guided Traffic (Montana Empire /…high
- CVE-2026-24294: NTLM Reflection Bypass via SMB on Arbitrary TCP Ports — Local Privilege Escalation to SYSTEMcritical
- "Total Access to All Your Devices" Sextortion Email Extortion Campaignmedium
- EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing…high
- FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN…high
- Dashlane Device-Registration API 2FA OTP Brute-Force Campaign — Encrypted Vaults of <20 Personal-Plan…high
- GHOST STADIUM — FIFA World Cup 2026 Phishing Operation: 4,300+ Fraudulent Domains and 300+ Cloned fifa.com…high
- 2026 FIFA World Cup Phishing Campaign — 222 Typosquatting Domains, 203 IPs, 4 Operator Clusters (Flare)high
- Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltrationcritical
Detection coverage
Threadlinqs maintains 33 detection rules mapped to T1589.001 (SPL 15, KQL 11, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1589 Gather Victim Identity Information — 228 tracked threats at the technique level.