Activity timeline
T1650 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 8 reports, and 25 of the 25 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1650 Acquire Access is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix. Threadlinqs maps 25 of 2623 tracked threats (1%) to it; by severity that is 1 critical, 15 high, 6 medium, 1 low.
Threats that use T1650 most often also use T1078 Valid Accounts (16 threats), T1657 Financial Theft (16 threats), T1213 Data from Information Repositories (13 threats), T1567 Exfiltration Over Web Service (13 threats), T1566 Phishing (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
11 tracked threat actors appear in the threats that use T1650; the most frequent are Everest (2), TheHatman (2), APT43 (1), Coinbase Cartel (1), CoinbaseCartel (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1650.
Threat actors using it
Tracked threats
25 tracked threats use T1650.
- Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guiltyhigh
- Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Rolesmedium
- Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)high
- Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnelhigh
- Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…high
- Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap…medium
- "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's…high
- ModernStealer: Cross-Platform Dark Web/Telegram Broker Network Claims Sale of Government and Defense Datamedium
- Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and…high
- SplitVPN (formerly NotVPN) Breach Exposes 58M Connection Logs, 23.4M User Records Despite 'No Logs' Claimshigh
- SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltrationhigh
- Sextortion Scammers Impersonate ShinyHunters, Exploit Leaked Breach Data for Bitcoin Extortionlow
- Everest Ransomware Gang Extorts Stadler Rail via Compromised Supplier Credentials, CHF 10M Demand Refusedmedium
- Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Datahigh
- ReHub: Russian-Language Cybercrime Marketplace Sponsoring DragonForce, LockBit, CHAOS, Anubis, The…medium
- Ransomware Attack Halts Fairlife (Coca-Cola Subsidiary) US Dairy Production Operationshigh
- Threat Actors Mass-Probe Gitea Docker Deployments for CVE-2026-20896 Authentication Bypass Amid Exploitarium…critical
- "Total Access to All Your Devices" Sextortion Email Extortion Campaignmedium
- Dark Web Identity-Theft Ecosystem: $0.95 Fullz, STORM Infostealer-as-a-Service, and Scam-as-a-Service…high
- Anthropic claude.ai Shared-Chat Feature Abused in ClickFix Malvertising Campaign Delivering MacSync macOS…high
- Ransomware Double-Claiming: Why the Same Victim Appears on Two Leak Sites
- Duplicate Ransomware Leak-Site Claims: RaaS Cartels, Affiliate Re-Extortion, Access-Broker Resale, and…
- Dark Web Data-Leak Roundup (June 2026): Iran Hajj Organization (168M records), AdressFakta/SUPEReROI Sweden…high
- Grafana Labs Source Code Theft via Stolen GitHub Access Token — CoinbaseCartel Extortion Campaignhigh
- Storm-2755 'Payroll Pirate' Campaign: AiTM Phishing and Workday Account Hijacking Targeting Canadian…high
Detection coverage
Threadlinqs maintains 18 detection rules mapped to T1650 (SPL 7, KQL 5, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.