Activity timeline
T1619 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 8 reports, and 19 of the 19 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1619 Cloud Storage Object Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 19 of 2623 tracked threats (0.7%) to it; by severity that is 9 critical, 7 high, 3 medium.
Threats that use T1619 most often also use T1078 Valid Accounts (15 threats), T1526 Cloud Service Discovery (14 threats), T1552 Unsecured Credentials (14 threats), T1213 Data from Information Repositories (12 threats), T1528 Steal Application Access Token (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
14 tracked threat actors appear in the threats that use T1619; the most frequent are ShinyHunters (3), Scattered LAPSUS$ Hunters (2), Scattered Spider (2), The Com (2), UNC5537 (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1619.
Data sources
Telemetry that can reveal T1619, per MITRE ATT&CK.
- Cloud Storage — Cloud Storage Access, Cloud Storage Enumeration
Threat actors using it
Tracked threats
19 tracked threats use T1619.
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…critical
- Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and…high
- CosmosEscape: Gremlin API Sandbox Escape Exposed Platform-Wide Key for Every Azure Cosmos DB Databasecritical
- ShutterGap: Ephemeral Public Exposure of AWS RDS/DocumentDB Snapshots, AMIs & SSM Documents Evades…medium
- Coordinated GitHub API Enumeration and Access Token Abuse Campaign (Ghost Accounts + Compromised PAT/OAuth…medium
- 14 Vulnerabilities Expose Citizen PII in Indian Government Systems — UPSC Portal Admin Takeover, Delhi…critical
- Lone Attacker Uses AI-Assisted Workflows to Breach Large AWS Cloud Environment in 72 Hours (Sygnia…high
- npm 12 Disables Install Scripts, Git Dependencies, and Remote Tarball URLs by Default to Curb Supply-Chain…medium
- JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion Attackcritical
- JADEPUFFER Agentic Ransomware: Autonomous LLM Agent Exploits Langflow (CVE-2025-3248) and Nacos…critical
- Cloud Bucket Hijacking — Global Namespace Risk: Silent Data-Stream Redirection via Statically-Named Storage…critical
- Global Namespace Bucket Hijacking: Universal Cloud Data Exfiltration via Storage Bucket Name Reclamation…high
- Pickle in the Middle: Vertex AI Model Upload Hijacking via GCS Bucket Squatting Enables Cross-Tenant RCE…high
- Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltrationcritical
- ShinyHunters Breach of Instructure Canvas LMS via Free-For-Teacher Programhigh
- AWS Bedrock AgentCore Sandbox Escape via DNS Tunneling and Metadata Service Exploitationhigh
- Escalating Kubernetes Attacks: React2Shell (CVE-2025-55182), Slow Pisces, and Cloud-Native Threat Actorscritical
- ShinyHunters-Branded Extortion Campaign Expands with Vishing & SSO Attackshigh
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineeringcritical
Detection coverage
Threadlinqs maintains 13 detection rules mapped to T1619 (SPL 4, KQL 5, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.