Activity timeline
T1589.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 20 reports, and 51 of the 51 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1589.002 Email Addresses is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of T1589 Gather Victim Identity Information. Threadlinqs maps 51 of 2623 tracked threats (1.9%) to it; by severity that is 6 critical, 28 high, 17 medium.
Threats that use T1589.002 most often also use T1566.002 Spearphishing Link (36 threats), T1583.001 Domains (30 threats), T1204.001 Malicious Link (26 threats), T1684.001 Impersonation (25 threats), T1027 Obfuscated Files or Information (19 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
19 tracked threat actors appear in the threats that use T1589.002; the most frequent are UNK_OutFlareAZ (2), EvilTokens (1), Ghost Stadium (1), Kali365 PhaaS operators (1), Luna Moth (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1589.002.
Data sources
Telemetry that can reveal T1589.002, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content
Threat actors using it
Tracked threats
The 30 most recent of 51 tracked threats that use T1589.002.
- cPanel/WHM CalDAV/CardDAV and WP Toolkit Flaws Enable Cross-Account Access and Root Privilege Escalation…critical
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…high
- Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image…high
- OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 /…high
- Trezor Warns of Phishing Attacks After Third-Party Email Provider Breach ("STM32 Entropy Vulnerability" Lure)medium
- Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructurehigh
- DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Networkmedium
- Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizationsmedium
- Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visitmedium
- ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and…critical
- Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusionhigh
- AnonyMousKIT: AI-Enabled Phishing-as-a-Service Platform Automates Apple Activation Lock Bypasshigh
- CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…high
- Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Accessmedium
- ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customersmedium
- Mass Phishing and Scam Campaign Abuses 450+ Compromised Google Workspace Accounts in the Education Sectorhigh
- BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detectionmedium
- U.S. Defense Manufacturer IEH Corporation Breached via Phishing, Potential Export-Controlled Data Exposurehigh
- Coldcard Security Audit Phishing Campaign Installs ConnectWise ScreenConnect RATcritical
- LogoKit Phishing-as-a-Service Evolves to Real-Time "Environment Impersonation"medium
- OAuth Consent Phishing Abuses Microsoft's Legitimate Login System to Harvest Microsoft 365 Tokenshigh
- AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams…high
- Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Paymentsmedium
- Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…critical
- Check Point Q2 2026 Brand Phishing Report: Microsoft Leads at 23%, ChatGPT Enters Top 10 Impersonated Brandsmedium
- Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accountshigh
- Apple Hide My Email Flaw Exposed Real Email Addresses via Spam-Filter/Bounce Triggeringcritical
- Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action…medium
- GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous…high
- "The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365)…high
Detection coverage
Threadlinqs maintains 74 detection rules mapped to T1589.002 (SPL 26, KQL 28, Sigma 20). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1589 Gather Victim Identity Information — 228 tracked threats at the technique level.