Activity timeline
T1621 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 30 reports, and 62 of the 62 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1621 Multi-Factor Authentication Request Generation is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 62 of 2623 tracked threats (2.4%) to it; by severity that is 4 critical, 45 high, 12 medium, 1 low.
Threats that use T1621 most often also use T1566 Phishing (36 threats), T1078 Valid Accounts (34 threats), T1589 Gather Victim Identity Information (32 threats), T1567 Exfiltration Over Web Service (31 threats), T1539 Steal Web Session Cookie (29 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
28 tracked threat actors appear in the threats that use T1621; the most frequent are Scattered Spider (11), ShinyHunters (9), The Com (7), Scattered LAPSUS$ Hunters (5), UNC6040 (5).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1621.
Data sources
Telemetry that can reveal T1621, per MITRE ATT&CK.
- Application Log — Application Log Content
- Logon Session — Logon Session Creation, Logon Session Metadata
- User Account — User Account Authentication
Threat actors using it
Tracked threats
The 30 most recent of 62 tracked threats that use T1621.
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…high
- Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Rolesmedium
- Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Scriptmedium
- ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and…critical
- Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…high
- Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Accessmedium
- Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap…medium
- Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCShigh
- "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's…high
- Formula 1 Phishing Campaign & Kit Analysis: Real-Time BIN-Routed Ticketing Fraud Kit Targets Middle East…high
- Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidentshigh
- Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials…high
- AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams…high
- Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…high
- Sextortion Scammers Impersonate ShinyHunters, Exploit Leaked Breach Data for Bitcoin Extortionlow
- npm Supply-Chain Compromise (chalk/debug + 17 packages, Sept 2025) — Motivates GitHub Dependabot 'Cooldown'…high
- ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift Supply-Chain Compromise Targeting Salesforce…critical
- GCP Cross-Project Compute Image Exfiltration via Compromised Developer Credentialshigh
- DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)high
- AWS CLI Login Phishing: Abusing `aws login --remote` Cross-Device Authentication to Steal Console/CLI Sessionshigh
- German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM…high
- ASEC June 2026 Financial Sector Threat Roundup: Phishing-to-Infostealer Chains and Ransomware Dark Web Sales…medium
- "The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365)…high
- UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to Deliver RATs and Steal Credentialshigh
- Device Code Phishing Campaign Targets Microsoft 365 via OAuth Device Authorization Grant Abusehigh
- Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing) Persuasiveness Gap: 16.5% Compliance, 70.3%…medium
- Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattackhigh
- FaceTime Impersonation Scam Targets Bank and Apple Support Victims ("DarkSword"-style Campaign)medium
- Operation Fake KickOff: Recruiter-Impersonation AitM/BitB Toolkit Abuses Salesforce, SendGrid, Zoho and…high
- Sophos State of Ransomware 2026: Payments Drop as Encryption Success Climbs, Identity-Based Attacks Now…medium
Detection coverage
Threadlinqs maintains 96 detection rules mapped to T1621 (SPL 31, KQL 35, Sigma 30). Rule content is available to Blue tier accounts and above; this page shows counts only.