T1078.004 - Cloud Accounts - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
April 15, 2026
Last Seen
June 21, 2026

T1078.004 - Cloud Accounts is a mitre_attack tracked by ThreatCluster, appearing in 3 threat clusters built from 3 intelligence report mentions.

T1078.004 - Cloud Accounts is a mitre_attack tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed April 15, 2026; most recent activity June 21, 2026.

Related Threat Clusters

  • Salesloft Drift OAuth Token Breach Exposes Salesforce Data

    Between August 9 and August 17, 2025, the threat actor UNC6395 exploited stolen OAuth tokens from Salesloft's Drift integration to access Salesforce environments of over 700 organizations, including major tech firms.…

    3 articles · Updated June 21, 2026
  • Kubernetes Cluster Compromised via Leaked AWS Credentials

    Recent incidents highlight a significant threat to Kubernetes clusters, where attackers exploited leaked AWS IAM credentials from developer workstations. This allowed them to deploy poisoned Docker images, facilitating…

    5 articles · Updated May 20, 2026
  • Claroty Enhances CPS Security with New Visibility Orchestration Capabilities

    On April 14, 2026, Claroty announced the launch of its new Visibility Orchestration capabilities in the Claroty xDome SaaS platform. This innovation aims to address the rising threat of cyber attacks targeting…

    3 articles · Updated April 15, 2026

Recent Intelligence Reports

  • Salesloft Drift OAuth Token Breach Enables Salesforce Data Theft in UNC6395 'Icarus ... — Rescana · June 21, 2026
  • Leaked Kubernetes Secrets: Impact Assessment and Mitigation Strategies — Blog.Gitguardian · May 20, 2026
  • Claroty Bridges Gap Between Asset Visibility And Actionable Risk Reduction With Industry First Visibility Orchestration Capabilities — claroty.com · April 15, 2026

Frequently asked questions

What is T1078.004 - Cloud Accounts?

T1078.004 - Cloud Accounts is a mitre_attack tracked by ThreatCluster, appearing in 3 threat clusters built from 3 intelligence report mentions.

Is T1078.004 - Cloud Accounts still active?

The most recent intelligence report mentioning T1078.004 - Cloud Accounts on ThreatCluster is dated June 21, 2026. Activity was first observed April 15, 2026, giving a tracked span from then to June 21, 2026.

What is T1078.004 - Cloud Accounts associated with?

Across ThreatCluster reporting, T1078.004 - Cloud Accounts most frequently co-occurs with Data Breach, Supply Chain Attack, AWS, Azure, DigitalOcean, among 12 tracked related entities.

What are the latest developments involving T1078.004 - Cloud Accounts?

The most significant recent cluster is “Salesloft Drift OAuth Token Breach Exposes Salesforce Data” (3 articles · Updated June 21, 2026). T1078.004 - Cloud Accounts appears across 3 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on T1078.004 - Cloud Accounts?

T1078.004 - Cloud Accounts appears in 3 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown