UNC6671 Gang Hijacks Corporate Accounts for Voice Phishing Extortion
The cybercrime group UNC6671 has been using voice phishing attacks to steal corporate data and extort financial firms, according to Google Threat Intelligence Group (GTIG). Although the BlackFile extortion brand shut down in May 2026, the group's operations appear to have continued under several new names, including Redact, Pink, Helix, and Falcon.
The group targets enterprise workers by posing as internal IT helpdesk staff, calling employees on their personal mobile numbers to claim that an urgent security update is required. Victims are then directed to fraudulent login pages hosted on domains that imitate passkey, multi-factor authentication (MFA), single sign-on (SSO), and helpdesk services.
The group uses adversary-in-the-middle (AiTM) phishing infrastructure, which can capture usernames, passwords, MFA approvals, and active session tokens. After gaining access, UNC6671 abuses compromised cloud accounts to access data stored in Microsoft 365, Okta, and other SaaS platforms.