T1078.004 - Cloud Accounts is a mitre_attack tracked by ThreatCluster, appearing in 3 threat clusters built from 3 intelligence report mentions.
T1078.004 - Cloud Accounts is a mitre_attack tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed April 15, 2026; most recent activity June 21, 2026.
Between August 9 and August 17, 2025, the threat actor UNC6395 exploited stolen OAuth tokens from Salesloft's Drift integration to access Salesforce environments of over 700 organizations, including major tech firms.…
Recent incidents highlight a significant threat to Kubernetes clusters, where attackers exploited leaked AWS IAM credentials from developer workstations. This allowed them to deploy poisoned Docker images, facilitating…
On April 14, 2026, Claroty announced the launch of its new Visibility Orchestration capabilities in the Claroty xDome SaaS platform. This innovation aims to address the rising threat of cyber attacks targeting…
T1078.004 - Cloud Accounts is a mitre_attack tracked by ThreatCluster, appearing in 3 threat clusters built from 3 intelligence report mentions.
The most recent intelligence report mentioning T1078.004 - Cloud Accounts on ThreatCluster is dated June 21, 2026. Activity was first observed April 15, 2026, giving a tracked span from then to June 21, 2026.
Across ThreatCluster reporting, T1078.004 - Cloud Accounts most frequently co-occurs with Data Breach, Supply Chain Attack, AWS, Azure, DigitalOcean, among 12 tracked related entities.
The most significant recent cluster is “Salesloft Drift OAuth Token Breach Exposes Salesforce Data” (3 articles · Updated June 21, 2026). T1078.004 - Cloud Accounts appears across 3 threat clusters in total, listed above with sources.
T1078.004 - Cloud Accounts appears in 3 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.