All incidents

UNC6671 vishing gang rebrands, uses AiTM phishing for extortion

incidentopenAug 7, 2026 — Aug 12, 2026
UNC6671 vishing gang rebrands, steals cash from banks, law firms

UNC6671, the vishing extortion outfit formerly known as BlackFile, has resurfaced under new aliases such as Redact, Pink, Helix and Falcon, siphoning cash from banks and law firms.

The group has moved over 141.65 BTC, worth roughly $10.69 million, in Bitcoin ransom payments since its rebrand.

They rely on voice phishing calls that pose as IT helpdesk staff, using adversary‑in‑the‑middle tactics to intercept Microsoft 365 and Okta authentication flows, as detailed by SecurityWeek.

By spoofing legitimate helpdesk numbers and hijacking compromised email accounts, attackers reset passwords and capture multi‑factor authentication tokens.

The operation also features a freshly launched data leak site to pressurise victims into paying.

The phishing templates and root domains reused across Redact, Pink, Helix and Falcon indicate a shared infrastructure, even though some researchers suggest the affiliate network may have splintered according to Infosecurity Magazine.

No CVEs have been tied to the campaign, highlighting its reliance on social engineering rather than software vulnerabilities.

Blockchain analysis shows the Bitcoin flow matches the $10 million figure reported by multiple security outlets.

Google’s Threat Intelligence Group first observed the activity between 7 August and 12 August 2026, noting targets across North America, Australia and the United Kingdom as reported in its threat intelligence blog.

The rebrand followed the claimed retirement of the BlackFile name after an exiled affiliate allegedly hijacked the brand, prompting the gang to adopt fresh monikers while keeping core tactics unchanged.

Despite the name changes, the group’s operational methods remain consistent, making it a persistent threat to financial and legal sectors.

Organisations should enforce phishing‑resistant authentication such as FIDO2 security keys or certificate‑based logins to blunt adversary‑in‑the‑middle attacks.

Monitoring for impossible travel logins, sudden MFA prompts and anomalous password reset requests can reveal early signs of a vishing attempt.

Employee training must stress that unsolicited helpdesk calls requesting credentials or OTPs are always suspect, and staff should verify such requests through known internal channels.

Keeping helpdesk contact numbers published and encouraging call‑back verification reduces the success of spoofed numbers.

Regular tabletop exercises that simulate vishing scenarios help validate detection and response procedures.

Sharing indicators of compromise, including the phishing domains and Bitcoin wallets linked to UNC6671, with industry ISACs improves collective defence per the same Google advisory.

Finally, reviewing and tightening conditional access policies in cloud identity platforms limits the value of stolen credentials even if they are obtained.

Intelligence briefing updated Aug 12, 2026

BlackFile UNC6671
Root sourcecloud.google.com
Timeline Coverage

Swipe to explore timeline