# T1621 Multi-Factor Authentication Request Generation

> As of 2026-10-05, T1621 (Multi-Factor Authentication Request Generation) appears in 62 tracked threats, first reported 2026-02-02 and most recently 2026-09-30, with linked actors including Scattered Spider, ShinyHunters, The Com; it most often appears alongside T1566 (Phishing).

- **Tracked threats:** 62 (4 critical, 45 high, 12 medium, 1 low)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-30
- **Threat actors:** 28
- **Detection rules:** 96 (counts only; Blue tier and above)

## Key facts

- **ID:** T1621
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1621/

## Activity timeline

T1621 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-30. The busiest month was 2026-07 with 30 reports, and 62 of the 62 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1621 Multi-Factor Authentication Request Generation is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 62 of 2623 tracked threats (2.4%) to it; by severity that is 4 critical, 45 high, 12 medium, 1 low.

Threats that use T1621 most often also use [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) (36 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (34 threats), [T1589 Gather Victim Identity Information](https://intel.threadlinqs.com/technique/T1589) (32 threats), [T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567) (31 threats), [T1539 Steal Web Session Cookie](https://intel.threadlinqs.com/technique/T1539) (29 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

28 tracked threat actors appear in the threats that use T1621; the most frequent are [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (11), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (9), [The Com](https://intel.threadlinqs.com/actor/The%20Com) (7), [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (5), [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) (5).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1621.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1036 Account Use Policies](https://attack.mitre.org/mitigations/M1036/)

## Data sources

Telemetry that can reveal T1621, per MITRE ATT&CK.

- Application Log — Application Log Content
- Logon Session — Logon Session Creation, Logon Session Metadata
- User Account — User Account Authentication

## Threat actors using it

- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 11
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 9
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 7
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 5
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 5
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 5
- [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) — 4
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 4
- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 4
- [TheHatman](https://intel.threadlinqs.com/actor/TheHatman) — 3
- [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) — 2
- [Storm-2372](https://intel.threadlinqs.com/actor/Storm-2372) — 2

## Tracked threats

The 30 most recent of 62 tracked threats that use T1621.

- [CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…](https://intel.threadlinqs.com/threat/TL-2026-2802) — high — 2026-09-30
- [Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles](https://intel.threadlinqs.com/threat/TL-2026-2799) — medium — 2026-09-30
- [Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script](https://intel.threadlinqs.com/threat/TL-2026-2695) — medium — 2026-09-25
- [ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and…](https://intel.threadlinqs.com/threat/TL-2026-2208) — critical — 2026-08-29
- [Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…](https://intel.threadlinqs.com/threat/TL-2026-2170) — high — 2026-08-26
- [Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Access](https://intel.threadlinqs.com/threat/TL-2026-2129) — medium — 2026-08-24
- [Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap…](https://intel.threadlinqs.com/threat/TL-2026-2047) — medium — 2026-08-17
- [Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCS](https://intel.threadlinqs.com/threat/TL-2026-2028) — high — 2026-08-16
- ["TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's…](https://intel.threadlinqs.com/threat/TL-2026-2027) — high — 2026-08-16
- [Formula 1 Phishing Campaign & Kit Analysis: Real-Time BIN-Routed Ticketing Fraud Kit Targets Middle East…](https://intel.threadlinqs.com/threat/TL-2026-1944) — high — 2026-08-08
- [Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidents](https://intel.threadlinqs.com/threat/TL-2026-1938) — high — 2026-08-08
- [Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials…](https://intel.threadlinqs.com/threat/TL-2026-1888) — high — 2026-08-05
- [AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams…](https://intel.threadlinqs.com/threat/TL-2026-1777) — high — 2026-07-30
- [Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…](https://intel.threadlinqs.com/threat/TL-2026-1734) — high — 2026-07-28
- [Sextortion Scammers Impersonate ShinyHunters, Exploit Leaked Breach Data for Bitcoin Extortion](https://intel.threadlinqs.com/threat/TL-2026-1722) — low — 2026-07-27
- [npm Supply-Chain Compromise (chalk/debug + 17 packages, Sept 2025) — Motivates GitHub Dependabot 'Cooldown'…](https://intel.threadlinqs.com/threat/TL-2026-1714) — high — 2026-07-27
- [ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift Supply-Chain Compromise Targeting Salesforce…](https://intel.threadlinqs.com/threat/TL-2026-1711) — critical — 2026-07-26
- [GCP Cross-Project Compute Image Exfiltration via Compromised Developer Credentials](https://intel.threadlinqs.com/threat/TL-2026-1648) — high — 2026-07-23
- [DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)](https://intel.threadlinqs.com/threat/TL-2026-1647) — high — 2026-07-23
- [AWS CLI Login Phishing: Abusing `aws login --remote` Cross-Device Authentication to Steal Console/CLI Sessions](https://intel.threadlinqs.com/threat/TL-2026-1646) — high — 2026-07-23
- [German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM…](https://intel.threadlinqs.com/threat/TL-2026-1602) — high — 2026-07-22
- [ASEC June 2026 Financial Sector Threat Roundup: Phishing-to-Infostealer Chains and Ransomware Dark Web Sales…](https://intel.threadlinqs.com/threat/TL-2026-1597) — medium — 2026-07-21
- ["The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365)…](https://intel.threadlinqs.com/threat/TL-2026-1593) — high — 2026-07-21
- [UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to Deliver RATs and Steal Credentials](https://intel.threadlinqs.com/threat/TL-2026-1509) — high — 2026-07-19
- [Device Code Phishing Campaign Targets Microsoft 365 via OAuth Device Authorization Grant Abuse](https://intel.threadlinqs.com/threat/TL-2026-1492) — high — 2026-07-18
- [Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing) Persuasiveness Gap: 16.5% Compliance, 70.3%…](https://intel.threadlinqs.com/threat/TL-2026-1431) — medium — 2026-07-17
- [Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattack](https://intel.threadlinqs.com/threat/TL-2026-1429) — high — 2026-07-17
- [FaceTime Impersonation Scam Targets Bank and Apple Support Victims ("DarkSword"-style Campaign)](https://intel.threadlinqs.com/threat/TL-2026-1425) — medium — 2026-07-16
- [Operation Fake KickOff: Recruiter-Impersonation AitM/BitB Toolkit Abuses Salesforce, SendGrid, Zoho and…](https://intel.threadlinqs.com/threat/TL-2026-1388) — high — 2026-07-15
- [Sophos State of Ransomware 2026: Payments Drop as Encryption Success Climbs, Identity-Based Attacks Now…](https://intel.threadlinqs.com/threat/TL-2026-1365) — medium — 2026-07-15

## Related CVEs

CVEs referenced by the tracked threats that use T1621, most frequent first.

- [CVE-2024-57726](https://intel.threadlinqs.com/cve/CVE-2024-57726)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2024-57728](https://intel.threadlinqs.com/cve/CVE-2024-57728)

## Detection coverage

Threadlinqs maintains 96 detection rules mapped to T1621 (SPL 31, KQL 35, Sigma 30). Rule content is available to Blue tier accounts and above; this page shows counts only.

96 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1621
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
