Skip to content
Deep Dive high FinanceHealthcareCritical InfrastructureCommunications

UNC6671: Inside the Vishing Crew Behind BlackFile, Redact, Pink, Helix, and Falcon

Executive Summary

While most extortion coverage in 2026 has focused on ransomware encryptors, one of the year’s most financially effective threat actors has never needed to touch an encryption binary at all. UNC6671 — the Google Threat Intelligence Group (GTIG) designation for a cluster first documented in January 2026 — built a pure data-theft extortion operation on a deceptively simple foundation: phone calls. By impersonating corporate IT helpdesks and calling employees on their personal mobile numbers, the group has bypassed multi-factor authentication at dozens of organizations, walked out with terabytes of SharePoint, OneDrive, Salesforce, and Zendesk data, and collected more than $10.6 million in Bitcoin between January and May 2026 alone.

What makes UNC6671 a genuinely notable case study is not the vishing technique itself — voice phishing has been a known vector for years — but the operational structure GTIG has exposed underneath it. The group launched publicly in February 2026 under the brand “BlackFile,” staged a fake retirement in May, and then re-emerged within weeks running four parallel extortion brands — Redact, Pink, Helix, and Falcon — from shared infrastructure, identical phishing kits, and a consistent playbook. In August 2026, reporting tied the group to a coordinated campaign against some of the world’s largest hedge funds, including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel, marking a deliberate pivot into high-value financial services and private equity targets. UNC6671 is not on Adversary Wire and represents a distinct, well-documented cluster from the SIM-swapping “Com” ecosystem groups already profiled on this site.

Threat Actor Profile

UNC6671 is GTIG’s placeholder designation for an uncategorized, financially motivated cluster — Mandiant has not yet upgraded it to a named “FIN” designation, and no nation-state sponsorship is alleged. The group is assessed to be part of the broader English-speaking cybercriminal “Com” ecosystem that has also produced Scattered Spider (UNC3944) and ShinyHunters, sharing techniques such as helpdesk-impersonation vishing and adversary-in-the-middle (AiTM) phishing. Analysts have observed UNC6671 co-opting the ShinyHunters name for credibility in at least one instance, but GTIG treats it as operationally and infrastructurally distinct from both Scattered Spider and ShinyHunters proper — separate Tox/Session communication channels, unique domain registration patterns, and a dedicated data leak site (DLS) lineage set it apart.

The group first surfaced publicly in January 2026, and by February 2026 had formally adopted the “BlackFile” brand, launching a DLS on February 6. Unlike leak sites designed for maximum public shaming, BlackFile’s DLS was deliberately low-profile — not SEO-indexed or widely advertised, posting only limited file samples rather than full datasets, and using language that framed the operators as “security researchers” rather than extortionists. The DLS went dark in late April 2026, and on May 11 a message announced BlackFile was “shutting down… under this name.” GTIG’s telemetry shows this was theater: Bitcoin cashouts continued through the announced shutdown window, and by June 27, 2026 the same core infrastructure, phishing templates, and domain-registration fingerprints reappeared under a new brand, “Redact,” which publicly claimed BlackFile had been “hijacked” by a rogue affiliate. Two more brands, Pink and Helix, and a fourth, Falcon, followed in short succession, with GTIG documenting the same passkey-themed phishing domains (e.g., passkeyhelpdesk[.]com) serving victims across multiple “brands” simultaneously — direct evidence the DLSes are fronts for one coordinated intrusion operation rather than genuinely separate groups.

GTIG lays out several plausible explanations for the multi-brand structure without settling on one definitively: a single core group compartmentalizing operations to obscure true breach volume and complicate law-enforcement attribution; an actor split following an internal dispute where former affiliates retained shared tooling; a looser ecosystem of operators renting the same commoditized phishing-panel and AiTM infrastructure (“vishing-as-a-service”); or a model where a stable core intrusion team outsources negotiation and leak-site operations to separate extortion “storefronts.” Whichever is accurate, the practical effect for defenders is the same: victim organizations showing up on Redact, Pink, Helix, or Falcon leak sites are very likely facing the same intrusion tradecraft regardless of which brand name appears on the ransom note.

Tactics, Techniques, and Procedures

Initial Access: Helpdesk Vishing and Real-Time AiTM

UNC6671’s entire initial-access model runs through the phone, not the inbox. Operators call employees directly on personal mobile numbers — deliberately routing around corporate phishing filters, EDR, and security awareness training tied to corporate email and devices. The pretext is consistently a mandatory, urgent “security migration”: victims are told they must re-enroll in multi-factor authentication or set up a new passkey immediately, often with spoofed caller ID mimicking the legitimate internal helpdesk number.

Victims are walked through registering on a lookalike SSO portal hosted on a purpose-built subdomain (patterns include <organization>.enrollms[.]com, <organization>.passkeyms[.]com, and <organization>.setupsso[.]com, alongside generic root domains like passkeyhelpdesk[.]com, createssopasskey[.]com, and oskeysync[.]com). These portals run adversary-in-the-middle reverse-proxy kits that capture the victim’s username and password and immediately relay them to the real identity provider (Microsoft Entra ID or Okta) in real time. When the legitimate MFA challenge fires — push notification, SMS, or TOTP — the victim is coached to relay the code back to the “helpdesk agent” on the phone. With a valid, MFA-satisfied session in hand, the operators immediately register a new, attacker-controlled MFA device or passkey on the account, establishing durable persistence that survives the victim resetting their password.

GTIG documented an operational tempo acceleration through mid-2026: from roughly one new root phishing domain every 2.2 days in April-May, to one every 1.6 days by June-July, with a peak of seven new domains registered in a 72-hour window in late July — consistent with sustained, high-volume campaign operations rather than opportunistic one-off attacks. Infrastructure spans Cloudflare-fronted domains, DDOS-GUARD, Switzerland-based Private Layer, and Poland-based MEVSPACE, registered through Tucows and NiceNIC, with authentication traffic frequently routed through residential proxy services (AT&T, Comcast, Optimum) to defeat geolocation-based anomaly detection.

Data Theft: From Bulk Downloads to Stealthy “Direct Fetch”

Once inside a victim’s Microsoft 365 or Okta-federated environment, UNC6671 pivots via single sign-on into connected SaaS platforms — SharePoint, OneDrive, Salesforce, Zendesk, and ServiceNow — prioritizing content flagged by keyword searches such as “confidential” and “SSN.” Early campaigns used standard bulk download operations, generating conventional FileDownloaded audit events. GTIG observed the group evolve this into a stealthier “direct fetch” method: reusing valid session cookies (including Microsoft’s FedAuth tokens) obtained during the vishing call to issue direct HTTP GET requests via the Python requests library or PowerShell, which SharePoint logs as lower-visibility FileAccessed events rather than downloads. Forensic review of these sessions reveals telltale mismatches — a ClientAppId spoofed to appear as “Microsoft Office” while the actual UserAgent string reads python-requests/2.28.1 or WindowsPowerShell/5.1 — and access originating from non-managed devices via commercial VPN or hosting-provider IP space. Scale has been substantial: GTIG cites individual incidents involving exfiltration of more than one million files, and others involving rapid access to tens of thousands of documents in short windows.

Extortion: Branding, Escalation, and Negotiation

Ransom notes evolved alongside the brand structure. Early, unbranded notes were sent from throwaway Gmail addresses with 24-48 hour deadlines and a Tox ID for contact. By the BlackFile era, notes had standardized around a 72-hour deadline, a consistent subject line format (“[COMPANY NAME] DATA BREACH 72 HOURS TO CONTACT US”), and migrated communications to the Session messenger, with some contact attempts routed through hijacked internal email and Microsoft Teams accounts for added psychological pressure. When victims are unresponsive, UNC6671 escalates with spam floods from dozens of Gmail accounts, threatening voicemails directed at C-suite executives, and in some cases swatting attempts against company personnel.

Initial demands typically start in the low millions of dollars (GTIG cites figures exceeding $3 million in some cases), but the group negotiates aggressively downward — in more than 53% of tracked cases, final settlements landed around $750,000, roughly a 50-75% reduction from the opening demand. Across 18 tracked BlackFile-linked Bitcoin wallets, GTIG documented 141.65 BTC received between January 7 and May 12, 2026 alone — approximately $10.69 million at the time of the transactions — and cashout activity continued through the group’s staged “shutdown” in late April/early May, undercutting the retirement narrative.

Targeting and Victim Sectors

UNC6671’s targeting has visibly evolved in phases throughout 2026, reflecting a shift toward higher-value, higher-leverage targets as the operation matured:

  • April-May 2026: Broad, high-volume targeting across manufacturing, real estate, healthcare, and insurance — consistent with an opportunistic ramp-up phase focused on building victim volume and refining tradecraft.
  • June 2026: A pivot toward technology, transportation, and hospitality firms, sectors likely to hold valuable intellectual property, source code, or VIP client data with strong extortion leverage.
  • July-August 2026: A deliberate narrowing to financial services, private equity, and legal organizations — law firms, financial rating agencies, M&A advisors, and hedge funds — where confidential deal data, litigation records, and investor information carry acute reputational and regulatory stakes.

That final phase produced UNC6671’s highest-profile activity to date: an August 2026 campaign against major hedge funds and private equity firms, with reporting naming Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel among the targets. Point72 reportedly told investors it had been attacked but found no evidence client data was stolen; Two Sigma said it detected and blocked an intrusion attempt with no impact to its systems. The targeting of firms managing hundreds of billions of dollars in assets, using the same low-cost phone-call intrusion technique deployed against manufacturers and dental practices months earlier, underscores how effective and scalable vishing-based AiTM has become against even security-mature organizations — and how quickly a technique proven on softer targets gets redirected at marquee victims once operators are confident in the playbook.

Victim geography spans North America, the UK, and Australia, with dozens of confirmed organizations across the group’s operating history and additional unconfirmed intrusion attempts.

Historical Incidents and Impact

  • February 2026: BlackFile DLS launches, publishing limited samples from victims across manufacturing, real estate, healthcare, and insurance without full public leak dumps — an approach GTIG assesses was intended to pressure victims privately while minimizing public/regulatory attention.
  • Late April-May 11, 2026: BlackFile DLS goes offline; a shutdown notice claims the brand is retiring. Bitcoin wallet activity shows continued cashouts through this window.
  • June 27, 2026: “Redact” brand emerges from the same infrastructure and phishing templates, claiming BlackFile had been hijacked by a disgruntled affiliate — a narrative GTIG treats skeptically given the infrastructure overlap.
  • June-July 2026: Pink and Helix brands surface, sharing root domains and phishing kits with Redact and each other — in one documented case, a single domain (passkeyhelpdesk[.]com) served victims listed on both the Falcon and Helix leak sites simultaneously.
  • July 2026: Targeting pivots decisively to financial services, private equity, and legal sectors; domain registration tempo accelerates to a peak of seven new phishing domains in 72 hours (July 20-22).
  • August 2026: Reporting surfaces tying UNC6671 to attempted and successful intrusions against Point72, Millennium Management, Two Sigma, and Citadel, alongside additional private equity firms — prompting Google, SecurityWeek, and multiple financial-industry outlets to publish detailed advisories within days of each other.

Across the full campaign, GTIG’s tracked Bitcoin proceeds of roughly $10.6-10.7 million between January and May 2026 alone likely represent a floor rather than a ceiling, since the figure excludes wallets tied to the Redact/Pink/Helix/Falcon rebrand period and any payments settled outside cryptocurrency channels GTIG could trace.

Defensive Implications

UNC6671’s success rests almost entirely on defeating identity controls through social engineering rather than exploiting software vulnerabilities, which means the highest-leverage defenses are identity- and process-focused rather than patch-focused:

  • Deploy phishing-resistant MFA. FIDO2/WebAuthn security keys, platform passkeys, Windows Hello for Business, and Okta FastPass cannot be relayed through an AiTM proxy the way push notifications, SMS, and TOTP codes can. This is the single most effective mitigation against UNC6671’s core technique.
  • Lock down MFA/passkey self-enrollment. Alert on and require secondary verification for system.multifactor.factor.setup or equivalent events, particularly when preceded by authentication failures or originating from unmanaged devices — the exact pattern UNC6671 generates when registering a new authenticator post-compromise.
  • Treat helpdesk identity verification as a hard control, not a courtesy. Since UNC6671’s entire pretext depends on convincingly impersonating IT staff by phone, organizations should mandate out-of-band verification (e.g., callback to a known-good number, verification via a separate authenticated channel) before any MFA reset or passkey enrollment request is honored — especially requests received on personal devices.
  • Monitor SaaS access logs for automation fingerprints, not just volume. UNC6671’s “direct fetch” technique specifically targets the blind spot between FileDownloaded and FileAccessed event types. Flag FileAccessed events carrying scripting-library user agents (python-requests, PowerShell) or ClientAppId/UserAgent mismatches, and treat high-volume FileAccessed activity from unmanaged devices as seriously as bulk downloads.
  • Restrict authentication to managed devices and trusted networks where feasible. Requiring MDM/EDR-enrolled devices and blocking authentication from commercial VPN or residential-proxy IP ranges removes much of the infrastructure UNC6671 relies on to mask its access.
  • Shorten session lifetimes and bind tokens to device/context. Sub-24-hour session lifetimes, idle timeouts, and token binding reduce the window in which a stolen FedAuth or SSO session cookie remains useful for follow-on “direct fetch” exfiltration.
  • Don’t take DLS “retirements” at face value. BlackFile’s staged shutdown followed by rapid re-emergence under four new brands is a reminder that extortion-brand churn is often a rebranding exercise, not evidence an operator has actually stopped. Incident responders should treat indicators tied to any of BlackFile, Redact, Pink, Helix, or Falcon as belonging to a single active adversary.

UNC6671 is a useful case study in how far a purely social-engineering-driven intrusion model can scale in 2026: no custom malware, no software exploit, and no encryptor — just a convincing phone call, a well-built AiTM kit, and a rotating cast of extortion brand names. Its August pivot into the hedge fund and private equity space signals that identity-centric social engineering has become a credible threat vector even against organizations with mature security programs, and that defenders across financial services should expect continued targeting through the remainder of 2026.