UNC6671 Uses Phone Calls to Hijack Employee Sessions for Microsoft 365 Data Theft
A group known as UNC6671 is carrying out data theft campaigns that start with a phone call. The callers pose as an IT helpdesk, claiming an urgent security migration is necessary, and direct employees to a fake sign-in page.
The calls create urgency before employees can verify the request independently, allowing the attackers to capture credentials and a live authentication token.
This token lets an intruder act as the employee in Microsoft 365 or Okta, accessing mail, files, and other stored corporate data. The group has been active despite its claimed retirement of its BlackFile brand, using various names such as Redact, Pink, Helix, and Falcon.