T1589: Gather Victim Identity Information
Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details, including personal data (ex: employee names, email addresses, security question responses, etc.) as well as sensitive details such as credentials or multi-factor authentication (MFA) configurations.
Adversaries may gather this information in various ways, such as direct elicitation via Phishing for Information. Information about users could also be enumerated via other active means (i.e. Active Scanning) such as probing and analyzing responses from authentication services that may reveal valid usernames in a system or permitted MFA /methods associated with those usernames.CitationGrimBlog UsernameEnumCitationObsidian SSPR Abuse 2023 Information about victims may also be exposed to adversaries via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites).CitationOPM LeakCitationRegister DeloitteCitationRegister UberCitationDetectify Slack TokensCitationForbes GitHub CredsCitationGitHub truffleHogCitationGitHub GitrobCitationCNET Leaks
Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Phishing for Information), establishing operational resources (ex: Compromise Accounts), and/or initial access (ex: Phishing or Valid Accounts).
Security context for executives and security teams
This technique matters because attackers often prepare intrusions before touching your environment by collecting employee names, email addresses, credentials, MFA details, and security-question data. That information can make later phishing, valid-account use, account compromise, and other reconnaissance more credible and harder for the SOC to recognize as hostile.
Executive priority
Treat this as a pre-compromise risk indicator: identity exposure can convert public information, leaked credentials, or authentication behavior into business-impacting access attempts. Leaders should ask whether the organization can prove what identity data is externally exposed, whether authentication services leak useful signals, and whether leaked or reused credentials are handled quickly enough to reduce phishing and valid-account risk.
Technical view
ATT&CK places T1589 in Reconnaissance on the PRE platform, with sub-techniques for credentials, email addresses, and employee names. Because the official detection field is not provided, SOC and detection teams should validate coverage around the evidence paths MITRE describes: username enumeration against authentication services, MFA or self-service password reset discovery, phishing-for-information reporting, exposed identities on public websites and social media, and credentials or tokens exposed in public datasets or repositories. Relationship context also links this behavior to multiple campaigns and groups, so threat intel teams should use it as early-stage context rather than as standalone attribution.
Likely telemetry
- Authentication service logs showing failed, invalid-user, or enumeration-like activity
- SSO, MFA, and self-service password reset audit logs where available
- Email security and user-reported phishing-for-information events
- External attack surface findings for public employee names, email formats, and exposed identity details
- Credential exposure monitoring for corporate email addresses, passwords, tokens, or secrets
Detection direction
- Do not rely on endpoint telemetry alone; this is PRE-stage reconnaissance and may occur outside owned infrastructure.
- Validate whether authentication and password-reset services reveal different responses for valid versus invalid users or disclose permitted MFA methods.
- Tune for patterns of username probing while accounting for legitimate failed logins, help-desk activity, onboarding, and user mistakes.
- Correlate exposed employee names and email addresses with phishing-for-information reports and later valid-account attempts.
- Track the sub-techniques separately: credentials, email addresses, and employee names drive different collection and response workflows.
Mitigation priorities
- Prioritize pre-compromise exposure reduction consistent with M1056: limit unnecessary public identity information and reduce attack surface useful to reconnaissance.
- Review authentication, MFA, and self-service password reset flows for information leakage about valid users or allowed methods.
- Run recurring external exposure checks for corporate credentials, email addresses, employee names, and secrets in public datasets or repositories.
- Strengthen identity controls that reduce the value of gathered information, including resilient MFA processes and rapid credential reset workflows when exposure is confirmed.
- Prepare IR playbooks for leaked credential or identity-exposure events so teams can move from discovery to containment without debating ownership.
Additional notes and limits
The relationship set shows this technique used by several campaigns and groups, including espionage and financially motivated activity, but those relationships should not be treated as proof of attribution in a local incident. The main decision value is readiness: knowing whether identity data exposure is measured, whether authentication services leak signals, and whether SOC/IR teams can connect reconnaissance to later phishing or valid-account behavior.
MITRE provides no official detection text for this object, and PRE-stage activity often happens on third-party, public, or attacker-controlled infrastructure. Local validation is required to determine which identity exposures are observable, which logs are retained, and whether authentication telemetry is detailed enough to distinguish probing from normal user error.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Gather Victim Identity Information
Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details, including personal data (ex: employee names, email addresses, security question responses, etc.) as well as sensitive details such as credentials or multi-factor authentication (MFA) configurations.
Adversaries may gather this information in various ways, such as direct elicitation via Phishing for Information. Information about users could also be enumerated via other active means (i.e. Active Scanning) such as probing and analyzing responses from authentication services that may reveal valid usernames in a system or permitted MFA /methods associated with those usernames.CitationGrimBlog UsernameEnumCitationObsidian SSPR Abuse 2023 Information about victims may also be exposed to adversaries via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites).CitationOPM LeakCitationRegister DeloitteCitationRegister UberCitationDetectify Slack TokensCitationForbes GitHub CredsCitationGitHub truffleHogCitationGitHub GitrobCitationCNET Leaks
Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Phishing for Information), establishing operational resources (ex: Compromise Accounts), and/or initial access (ex: Phishing or Valid Accounts).
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
