Currently viewing ATT&CK v7.2 which was live between July 8, 2020 and October 26, 2020. Learn more about the versioning system or see the live site.
Register to stream the next session of ATT&CKcon Power Hour November 12

Remotely Wipe Data Without Authorization

An adversary who is able to obtain unauthorized access to or misuse authorized access to cloud services (e.g. Google's Android Device Manager or Apple iCloud's Find my iPhone) or to an EMM console could use that access to wipe enrolled devices [1].

ID: T1469
Sub-techniques:  No sub-techniques
Tactic Type: Without Adversary Device Access
Tactic: Remote Service Effects
Platforms: Android, iOS
MTC ID: ECO-5, EMM-7
Version: 1.0
Created: 25 October 2017
Last Modified: 17 October 2018

Mitigations

Mitigation Description
User Guidance

Encourage users to protect their account credentials and to enable available multi-factor authentication options.

Detection

Google provides the ability for users to view their general account activity. Apple iCloud also provides notifications to users of account activity.

References