
A hacking campaign tracked as UNC6671 has been impersonating IT support staff to steal multi‑factor authentication details from more than 200 organisations, including major financial players such as Blackstone and CME Group, according to Security Affairs. The group uses urgent phone calls, spoofed help‑desk numbers and fake login pages to trick employees into handing over credentials and one‑time codes.
The attackers employ voice phishing (vishing) tactics and adversary‑in‑the‑middle techniques to intercept authentication flows for Microsoft 365 and Okta services, as detailed in Google’s threat intelligence blog. They also create counterfeit websites that mimic legitimate corporate portals to harvest usernames, passwords and MFA tokens.
By gaining access to compromised email accounts, UNC6671 can reset passwords and further abuse the stolen session cookies, a method highlighted in SecurityWeek’s analysis. The group has also launched a public data leak site to pressurise victims into paying ransoms.
First observed in early August 2026, the campaign has persisted despite the group’s public persona being shut down in May of that year, with UNC6671 operating under various aliases. Targets span North America, Australia and the United Kingdom, and ransom demands range from one to three million US dollars, with victims reportedly paying an average of around seven hundred and fifty thousand dollars. To date the attackers have collected more than ten million dollars in Bitcoin, according to the same sources.
Recent activity shows a shift toward higher‑value targets such as private equity firms and law practices, which are seen as more likely to settle quickly to avoid exposure. This evolution in targeting reflects the group’s refinement of its extortion model after earning millions from earlier victims.
Organisations should instruct staff to verify any unsolicited support call by ringing back on a known, official number rather than trusting caller ID. Deploying phishing‑resistant multi‑factor authentication, such as FIDO2 security keys, can block adversary‑in‑the‑middle attempts. Security teams must monitor login attempts for impossible travel or anomalous device patterns and enforce conditional access policies that block legacy authentication. Regular staff training on vishing tactics and clear help‑desk verification procedures are essential to reduce the success rate of these social engineering attacks.