UNC6671 Targets Financial Sector via Vishing and AiTM Phishing
Recent cyberattacks on hedge funds, private-equity firms, and other financial institutions have been attributed to UNC6671, an extortion group with ties to the BlackFile threat actors. This group employs sophisticated voice phishing (vishing) and Adversary-in-the-Middle (AiTM) phishing tactics to gain unauthorized access to corporate systems and exfiltrate sensitive cloud data. Financial entities like Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel have reportedly been targeted in this ongoing campaign, highlighting a significant threat to the sector according to BleepingComputer.
Threat Actor Profile: UNC6671 and its Evolution
Google’s Threat Intelligence Group (GTIG) tracks this activity under the designation UNC6671. While initially operating under the public brand “BlackFile,” the group has diversified its extortion operations, using multiple public aliases including Redact, Pink, Helix, and Falcon. GTIG assesses that a single core intrusion group is responsible for the widespread helpdesk vishing and cloud data theft observed across these various brands. BlackFile, which first appeared in February 2025 targeting retail and hospitality, shifted its focus towards private-equity firms, hedge funds, major law firms, and financial-rating agencies by July 2026, according to a Mandiant report mentioned in the source. In May 2026, BlackFile officially rebranded as Redact, continuing its operations under the new name. The group has demonstrated significant financial success, with GTIG tracking over $10.6 million USD in Bitcoin payments to group wallets between January and May 2026, often settling for approximately $750,000 USD after initial demands upward of $3 million.
Attack Vector: Vishing and AiTM Phishing Tactics
The primary method of initial access for UNC6671 involves vishing. Operators contact employees directly on their personal mobile phones, often spoofing corporate helpdesks. The pretext typically involves urgent requests for workers to enroll in passkeys or update their multi-factor authentication (MFA) settings. Victims are then directed to malicious domains that impersonate their company’s legitimate portal. These domains host Adversary-in-the-Middle phishing kits, which are designed to intercept and steal credentials and session cookies in real-time. This sophisticated approach bypasses many traditional MFA protections by capturing active session tokens.
Technical Details of Cloud Data Theft and Extortion
Once Microsoft 365 or Okta single sign-on (SSO) accounts are compromised, the attackers leverage the stolen credentials and session cookies to log into the victim’s SSO dashboard. This grants them access to all cloud platforms and services linked to that SSO account. The threat actors then employ automated tools to systematically steal data from every accessible cloud service. To hinder detection and remediation efforts, they also delete security notifications and password-reset emails from compromised inboxes, making it harder for victims and security teams to realize the extent of the breach promptly.
While these helpdesk social-engineering tactics bear similarities to those historically used by Scattered Spider (UNC3944), GTIG explicitly tracks UNC6671 as a distinct entity based on its specific infrastructure, domain registration patterns, and multi-brand extortion network. This distinction is critical for organizations looking into detecting Adversary-in-the-Middle phishing in Microsoft 365 environments, as detection signatures and incident response playbooks might need to be tailored.
Recommendations for Defenders
Organizations, particularly those in the financial sector, must prioritize defenses against these advanced social engineering and AiTM techniques. To mitigate the risk of UNC6671 vishing tactics financial sector, consider the following actions:
- Intensive User Awareness Training: Educate employees about the tactics used in vishing and AiTM phishing attacks. Emphasize that legitimate IT support will rarely ask for credentials over the phone or direct users to unverified links for MFA updates. Train staff to verify requests through official, pre-established channels.
- Strengthen MFA: Implement strong, phishing-resistant MFA methods such as FIDO2 security keys where possible. While AiTM phishing can bypass some MFA, strong MFA makes it significantly harder. Regularly review MFA configurations and ensure all critical systems require it.
- Monitor SSO and Cloud Access Logs: Continuously monitor logs for unusual access patterns, anomalous login locations, and large data transfers from cloud services. Look for unusual activity immediately after an MFA reset or enrollment attempt.
- Endpoint Detection and Response (EDR) & Security Information and Event Management (SIEM): Ensure EDR and SIEM solutions are configured to detect suspicious activity indicative of stolen session cookies or unauthorized access to cloud applications. This includes monitoring for the creation of new inbox rules, deletion of security emails, or bulk data downloads.
- Incident Response Planning: Develop and regularly test incident response plans specifically for credential compromise and cloud data exfiltration scenarios. Focus on rapid detection, containment, and recovery to limit impact.
- Implement Conditional Access Policies: Use conditional access to restrict access to sensitive applications based on device posture, location, and user behavior. This can help prevent unauthorized access even if credentials or session cookies are stolen.
- Security for Personal Devices: Remind employees of the risks of using personal devices for work-related communication, as these are often targeted in vishing campaigns to bypass corporate security controls.
Proactive measures are essential for mitigating cloud data theft extortion groups like UNC6671. Regular security audits and staying informed on evolving threat actor TTPs will help organizations protect their sensitive information and prevent financial losses.
Related: BlackFile: Analyzing UNC6671 Vishing & Cloud Data Extortion, UNC3753: Vishing and Physical Intrusions Fuel U.S. Data Extortion