
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 has rebranded from BlackFile to Redact and expanded into several other extortion brands, including Pink, Helix, and Falcon. The group uses voice phishing to steal data from enterprise cloud environments for extortion.
Why it matters
Attackers target employees' personal mobile phones using fake IT helpdesk calls to bypass corporate security. This increases the risk of sensitive data theft for organizations in financial and legal sectors.
The details
- Targeting shifted toward financial services, private equity, and law firms by July 2026.
- The group intercepts login credentials and session tokens using spoofed authentication portals.
- BlackFile wallets received approximately $10.69 million USD between January and May 2026.
Show entities and relationshipsHide entities and relationships
In this article
Products
Technologies
Key connections
Okta owns Okta Fastpass
Show 14 more connectionsShow fewer connections
UNC6671 uses Cloudflare
UNC6671 uses DDOS-GUARD
UNC6671 is related to Microsoft 365
UNC6671 uses Voice Phishing
Microsoft Entra ID is built with Multi-Factor Authentication
Okta is built with Single Sign-On
Windows Hello for Business is built with FIDO2
Get the weekly recap
The stories like this one, picked and explained — once a week, straight to your inbox.