A hacking campaign led by the group UNC6671 is impersonating IT support to steal multi-factor authentication (MFA) credentials from over 200 firms, including major financial organizations like Blackstone and CME Group. Attackers create a sense of urgency by calling employees, spoofing company help desk numbers, and directing them to fake websites to harvest login information.
Despite shutting down its public-facing identity in May 2026, UNC6671 continues operations under various names, utilizing ransom demands ranging from $1 million to $3 million. Victims are selected based on their likelihood to pay ransoms to prevent data breaches, with reported average payments around $750,000. The group has adapted its tactics, moving toward higher-value targets like private equity firms and law firms.