# T1589 Gather Victim Identity Information

> As of 2026-10-05, T1589 (Gather Victim Identity Information) appears in 228 tracked threats, first reported 2026-01-19 and most recently 2026-10-02, with linked actors including Scattered Spider, The Com, ShinyHunters; it most often appears alongside T1566 (Phishing).

- **Tracked threats:** 228 (35 critical, 142 high, 48 medium, 3 low)
- **First seen:** 2026-01-19
- **Last seen:** 2026-10-02
- **Threat actors:** 90
- **Detection rules:** 102 (counts only; Blue tier and above)

## Key facts

- **ID:** T1589
- **Framework:** MITRE ATT&CK
- **Tactics:** Reconnaissance
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1589/

## Activity timeline

T1589 first appeared in tracked threats on 2026-01-19 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 85 reports, and 228 of the 228 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1589 Gather Victim Identity Information is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix. Threadlinqs maps 228 of 2623 tracked threats (8.7%) to it; by severity that is 35 critical, 142 high, 48 medium, 3 low.

Threats that use T1589 most often also use [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) (132 threats), [T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583) (124 threats), [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (106 threats), [T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567) (99 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (95 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

90 tracked threat actors appear in the threats that use T1589; the most frequent are [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (8), [The Com](https://intel.threadlinqs.com/actor/The%20Com) (8), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (7), [APT38](https://intel.threadlinqs.com/actor/APT38) (6), [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) (6).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1589.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1589, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content

## Threat actors using it

- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 8
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 8
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 7
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 6
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 6
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 5
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 5
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 5
- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 5
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 4
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 4
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 4

## Tracked threats

The 30 most recent of 228 tracked threats that use T1589.

- [Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and…](https://intel.threadlinqs.com/threat/TL-2026-2892) — high — 2026-10-02
- [Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data…](https://intel.threadlinqs.com/threat/TL-2026-2839) — high — 2026-10-02
- [Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles](https://intel.threadlinqs.com/threat/TL-2026-2799) — medium — 2026-09-30
- [Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…](https://intel.threadlinqs.com/threat/TL-2026-2770) — medium — 2026-09-29
- [Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks](https://intel.threadlinqs.com/threat/TL-2026-2745) — high — 2026-09-28
- [AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2668) — medium — 2026-09-26
- [Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)](https://intel.threadlinqs.com/threat/TL-2026-2713) — medium — 2026-09-25
- [Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script](https://intel.threadlinqs.com/threat/TL-2026-2695) — medium — 2026-09-25
- [TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…](https://intel.threadlinqs.com/threat/TL-2026-2616) — high — 2026-09-22
- [Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated](https://intel.threadlinqs.com/threat/TL-2026-2598) — high — 2026-09-21
- [Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Data](https://intel.threadlinqs.com/threat/TL-2026-2550) — high — 2026-09-17
- [Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists](https://intel.threadlinqs.com/threat/TL-2026-2543) — high — 2026-09-16
- [Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencies](https://intel.threadlinqs.com/threat/TL-2026-2534) — high — 2026-09-16
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…](https://intel.threadlinqs.com/threat/TL-2026-2526) — high — 2026-09-15
- [Revolut Discloses Data Breach via Government-Impersonation Social Engineering, Exposing Customer Financial…](https://intel.threadlinqs.com/threat/TL-2026-2498) — high — 2026-09-14
- [LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Technique](https://intel.threadlinqs.com/threat/TL-2026-2441) — medium — 2026-09-11
- [Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence…](https://intel.threadlinqs.com/threat/TL-2026-2390) — high — 2026-09-08
- [Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leak](https://intel.threadlinqs.com/threat/TL-2026-2383) — high — 2026-09-07
- [ASCII Smuggling Phishing Campaign Uses Invisible Unicode Tags-Block Characters to Evade Filters, Targeting…](https://intel.threadlinqs.com/threat/TL-2026-2338) — high — 2026-09-05
- [ADCS ESC1 Privilege Escalation: CISA AA26-237A Red Team Findings and CA Database Hunting Methodology](https://intel.threadlinqs.com/threat/TL-2026-2168) — high — 2026-08-27
- [Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…](https://intel.threadlinqs.com/threat/TL-2026-2170) — high — 2026-08-26
- ["The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware…](https://intel.threadlinqs.com/threat/TL-2026-2155) — high — 2026-08-26
- [AnonyMousKIT: AI-Powered Phishing-as-a-Service Platform Stealing Apple IDs from Stolen iPhones](https://intel.threadlinqs.com/threat/TL-2026-2141) — high — 2026-08-24
- [Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…](https://intel.threadlinqs.com/threat/TL-2026-2126) — high — 2026-08-23
- [Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)](https://intel.threadlinqs.com/threat/TL-2026-2109) — high — 2026-08-21
- [Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimi](https://intel.threadlinqs.com/threat/TL-2026-2056) — high — 2026-08-18
- [Pokémon Center Confirms Customer Data Breach via CEVA Logistics Supply-Chain Compromise](https://intel.threadlinqs.com/threat/TL-2026-2054) — high — 2026-08-18
- [Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap…](https://intel.threadlinqs.com/threat/TL-2026-2047) — medium — 2026-08-17
- [SafePal Data Breach: Order-Tracking Plug-in Authorization Flaw Exposes 39,798 Crypto Wallet Customers' PII…](https://intel.threadlinqs.com/threat/TL-2026-2032) — medium — 2026-08-16
- [Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage…](https://intel.threadlinqs.com/threat/TL-2026-2031) — high — 2026-08-16

## Related CVEs

CVEs referenced by the tracked threats that use T1589, most frequent first.

- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2012-1823](https://intel.threadlinqs.com/cve/CVE-2012-1823)
- [CVE-2017-11317](https://intel.threadlinqs.com/cve/CVE-2017-11317)
- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2017-3506](https://intel.threadlinqs.com/cve/CVE-2017-3506)
- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2018-8007](https://intel.threadlinqs.com/cve/CVE-2018-8007)
- [CVE-2019-18935](https://intel.threadlinqs.com/cve/CVE-2019-18935)
- [CVE-2019-3568](https://intel.threadlinqs.com/cve/CVE-2019-3568)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2020-28707](https://intel.threadlinqs.com/cve/CVE-2020-28707)
- [CVE-2021-1048](https://intel.threadlinqs.com/cve/CVE-2021-1048)
- [CVE-2021-22205](https://intel.threadlinqs.com/cve/CVE-2021-22205)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2021-34527](https://intel.threadlinqs.com/cve/CVE-2021-34527)
- [CVE-2021-37973](https://intel.threadlinqs.com/cve/CVE-2021-37973)

## Detection coverage

Threadlinqs maintains 102 detection rules mapped to T1589 (SPL 37, KQL 34, Sigma 31). Rule content is available to Blue tier accounts and above; this page shows counts only.

102 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1589.001 Credentials](https://intel.threadlinqs.com/technique/T1589.001) — 30 tracked threats
- [T1589.002 Email Addresses](https://intel.threadlinqs.com/technique/T1589.002) — 51 tracked threats
- [T1589.003 Employee Names](https://intel.threadlinqs.com/technique/T1589.003) — 12 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1589
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
