Vishing attacks on personal phones: UNC6671 steals SaaS data from banks and law firms

Financial firms, private equity funds, and professional services are facing a new wave of attacks attributed to the extortion group UNC6671. Attackers call employees on personal mobile numbers, posing as IT support, and convince them to visit fake login pages. This approach allows intercepting credentials and multi-factor authentication tokens, then gaining access to corporate clouds.
According to Google Threat Intelligence Group and Mandiant, the attacks rely on voice phishing, or vishing. The criminals simulate an urgent security migration and trick the victim into entering a password on a spoofed portal. Adversary-in-the-middle infrastructure collects logins and MFA codes, after which hackers gain persistent session access. Automated Python and PowerShell scripts are used to exfiltrate data from Microsoft 365 and Okta.
The group operates under multiple extortion brands: Redact, Pink, Helix, and Falcon. It previously worked under the BlackFile name, which was retired on May 11, 2026. Google data shows the first spike in UNC6671 activity was recorded in early January 2026, and the BlackFile leak site launched on February 6. By late April the site went offline, and on May 11 it briefly returned with a message about ceasing operations under that name. The new Redact brand officially announced the full closure of BlackFile on May 19, and the Pink leak site opened on May 31. In late June, Redact claimed the original brand had been compromised and hijacked by a former associate who ran unsanctioned extortion campaigns in their name.
Google first documented UNC6671 in January 2026, noting tactical similarities to the financially motivated group ShinyHunters, also known as Bling Libra. However, experts assess the operations act independently. The group maintains a high operational cadence, targeting dozens of organizations in North America, Australia, and the U.K. The primary goal is stealing data from corporate cloud environments and SaaS applications, followed by ransom demands.


