Close Menu
NCIJ Network NCIJ Network
    What's Hot

    You’re only as secure as your last evaluation

    August 7, 2026

    Morning Minute: MetaMask Hands AI Agents a Wallet

    August 7, 2026

    Flames reach edge of orangutan rehabilitation center, with fire season set to intensify

    August 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • You’re only as secure as your last evaluation
    • Morning Minute: MetaMask Hands AI Agents a Wallet
    • Flames reach edge of orangutan rehabilitation center, with fire season set to intensify
    • ExxonMobil books McDermott for Mozambique’s multibillion-dollar LNG project
    • Can anyone buy Wisconsin voter roll data?
    • US-backed Venezuela political transition talks begin without Nobel laureate Machado
    • Why does Apple keep banning Telegram, but never X?
    • Vishing Extortion Group UNC6671 Rebrands After Making Millions
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, August 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Vishing Extortion Group UNC6671 Rebrands After Making Millions

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 7, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    UNC6671, an extortion group engaging in tailored IT helpdesk voice phishing (vishing), has rebranded and diversified its operations over the past several months, Google Threat Intelligence Group (GTIG) reports.

    The threat actor emerged in early 2026, operating under the ‘BlackFile’ name. In May, GTIG warned it had targeted dozens of organizations across North America, Australia, and the UK in sophisticated vishing and single sign-on (SSO) compromise attacks.

    Mainly focusing on Microsoft 365 and Okta infrastructure, it was leveraging adversary-in-the-middle (AiTM) techniques to bypass defenses and multi-factor authentication (MFA) and gain access to cloud environments.

    In May, GTIG now says, the group retired the BlackFile extortion name, but has continued its activities under multiple brands: Redact, Pink, Helix, and Falcon. The latest attacks have focused on the financial services, private equity, and professional services sectors.

    Posing as IT helpdesk employees, UNC6671 threat actors have been calling employees at the victim organizations, often on personal mobile phones, under the pretext of mandatory, urgent security migrations, luring them to spoofed login portals to intercept their credentials and MFA tokens.

    Despite different branding in extortion messages, UNC6671’s initial access and post-compromise tactics, techniques, and procedures (TTPs) have remained consistent, GTIG says.

    Advertisement. Scroll to continue reading.

    In June, the group established a new data leak site under the Redact brand, announcing the departure from BlackFile, claiming the operation had been hijacked by an affiliate. GTIG’s monitoring of UNC6671’s digital footprint showed overlaps with the operations of other extortion brands.

    “These overlaps support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands, although other scenarios such as splintered affiliates or shared Phishing-as-a-Service infrastructure may also be plausible,” GTIG says.

    The group has been using generic root domains across multiple victims, such as passkeyhelpdesk[.]com, portalpasskey[.]com, addssopasskey[.]com, passkeydeploy[.]com, mysecurepasskey[.]com, and passkeyuser[.]com.

    While some domains were exclusively used by specific extortion brands, they could be linked to UNC6671 activity through the phishing templates deployed to harvest credentials.

    “UNC6671’s domain registration patterns demonstrate a regular shift in target selection, seemingly towards those that are more likely to hold sensitive information. UNC6671 leverages subdomains that incorporate prospective victim names to host tailored credential harvesting panels,” GTIG notes.

    Recent attacks have demonstrated an evolution in tactics, with the threat actor spoofing legitimate helpdesk phone numbers and using compromised email addresses to reset the passwords for non-SSO enterprise applications, while deleting confirmation messages, alerts, and notifications to prevent detection.

    Between January and May, the group received over $10 million in Bitcoin across 18 wallet addresses, representing ransom payments. Some of the payments were made after the BlackFile shutdown announcement.

    “Initial ransom demands typically range from $1 million to upwards of $3 million USD. However, the extortion operators shifted demands during negotiations, often agreeing to reductions between 50% and 75% of the initial ransom demand. In over 53% of tracked cases in this timeframe, final payments averaged $750,000,” GTIG notes.

    Related: Snowflake Hacker Pleads Guilty in US Court

    Related: Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison

    Related: Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

    Related: The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict

    extortion Group Making millions Rebrands UNC6671 vishing
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    You’re only as secure as your last evaluation

    What is the cost of a data breach cost?

    Trump Administration Suggested Funding Afrikaner Group in South Africa — ProPublica

    Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

    Meta joins OpenAI, Anthropic in latest AI test breach

    ClickFix attack pushes macOS infostealer for crypto theft attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    You’re only as secure as your last evaluation

    August 7, 2026

    Morning Minute: MetaMask Hands AI Agents a Wallet

    August 7, 2026

    Flames reach edge of orangutan rehabilitation center, with fire season set to intensify

    August 7, 2026

    ExxonMobil books McDermott for Mozambique’s multibillion-dollar LNG project

    August 7, 2026
    Latest Posts

    Bitcoin treasury company erases 7.7M shares after selling 177 BTC

    July 24, 2026

    New Dolphin X malware uses AI to rank high-value targets

    July 24, 2026

    An FDA Panel Just Endorsed These Unproven Peptides

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    You’re only as secure as your last evaluation

    August 7, 2026

    Morning Minute: MetaMask Hands AI Agents a Wallet

    August 7, 2026

    Flames reach edge of orangutan rehabilitation center, with fire season set to intensify

    August 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.