Compliance Node Overview
MITRE ATT&CK T1589 covers adversary collection of identity information about a target organisation - employee names, email addresses, credentials in breach corpora, executive identifiers - to enable phishing, social engineering, and credential-stuffing campaigns. Sub-techniques include Credentials (T1589.001), Email Addresses (T1589.002), and Employee Names (T1589.003). LinkedIn, breach corpora (SpyCloud, Have I Been Pwned), and public DNS/WHOIS are the dominant data sources. Compliance obligations include data minimisation under GDPR Article 5, NIST SP 800-53 SI-12, ISO 27001 A.8.12, A.5.34, and NIS2 Article 21(2)(j).
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1589/
SHA-256 integrity: 89789b674bce7162313e2d23939673ade020093c59d54d001d0f3938a730f92b
Primary Citations — 8 traced to source
- MITRE ATT&CK Technique T1589: Gather Victim Identity Information (https://attack.mitre.org/techniques/T1589/) with 3 sub-techniques
- GDPR Regulation (EU) 2016/679 Article 5(1)(c): data minimisation principle
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access