securityaffairs.com 8/7/2026, 4:50:00 PM · external

UNC6671 hackers pose as IT support to steal MFA from 200 firms.

UNC6671 hackers pose as IT support to steal MFA from 200 firms.
CyberSIXT Evidence Panel
Primary Source cloud.google.com
Threat Actor

A hacking campaign led by the group UNC6671 is impersonating IT support to steal multi-factor authentication (MFA) credentials from over 200 firms, including major financial organizations like Blackstone and CME Group. Attackers create a sense of urgency by calling employees, spoofing company help desk numbers, and directing them to fake websites to harvest login information.

Despite shutting down its public-facing identity in May 2026, UNC6671 continues operations under various names, utilizing ransom demands ranging from $1 million to $3 million. Victims are selected based on their likelihood to pay ransoms to prevent data breaches, with reported average payments around $750,000. The group has adapted its tactics, moving toward higher-value targets like private equity firms and law firms.

View Primary Source Via securityaffairs.com

Article by CyberSIXT