Skip to content
Back to Guavy Wire
Stocks

UNC6671 Gang Hijacks Corporate Accounts for Voice Phishing Extortion

Instruments
GOOGL MSFT
Share

The cybercrime group UNC6671 has been using voice phishing attacks to steal corporate data and extort financial firms, according to Google Threat Intelligence Group (GTIG). Although the BlackFile extortion brand shut down in May 2026, the group's operations appear to have continued under several new names, including Redact, Pink, Helix, and Falcon.

The group targets enterprise workers by posing as internal IT helpdesk staff, calling employees on their personal mobile numbers to claim that an urgent security update is required. Victims are then directed to fraudulent login pages hosted on domains that imitate passkey, multi-factor authentication (MFA), single sign-on (SSO), and helpdesk services.

The group uses adversary-in-the-middle (AiTM) phishing infrastructure, which can capture usernames, passwords, MFA approvals, and active session tokens. After gaining access, UNC6671 abuses compromised cloud accounts to access data stored in Microsoft 365, Okta, and other SaaS platforms.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc