UNC6671: Vishing Campaigns Target Financial Giants with Sophisticated MFA Bypass
A new wave of cyberattacks, attributed to the data extortion group **UNC6671**, is leveraging sophisticated vishing techniques to compromise major financial services, private equity, and professional services firms. The group employs adversary-in-the-middle (AitM) infrastructure to intercept credentials and MFA tokens, enabling widespread data exfiltration from enterprise cloud environments and SaaS applications.
A recent surge in cyberattacks has cast a spotlight on **UNC6671**, a data extortion group targeting financial services, private equity, and professional services sectors.
### The Vishing Vector
**UNC6671** primarily relies on voice phishing (vishing), impersonating IT help desk staff to trick enterprise employees. These threat actors frequently contact employees on their personal mobile devices, creating a false sense of urgency around mandatory security migrations.
During these vishing calls, victims are directed to spoofed login portals. Here, adversary-in-the-middle (AitM) infrastructure intercepts both credentials and multi-factor authentication (MFA) tokens. The stolen data is then used to establish session persistence and deploy automated Python and PowerShell scripts, facilitating data exfiltration from enterprise cloud environments and SaaS applications like **Microsoft 365** and **Okta**.
### A Shifting Extortion Landscape
**Google Threat Intelligence Group (GTIG)** and **Mandiant** have noted that **UNC6671** has diversified its operations across multiple extortion brands, including **Redact**, **Pink** (also known as **CL-CRI-1147**), **Helix**, and **Falcon** (also known as **CL-CRI-1182**). Previously, the group operated under the **BlackFile** (also known as **CL-CRI-1116**) brand, which was retired in May 2026.
Key events in **UNC6671**'s operational timeline:
* **Early January 2026**: **UNC6671** emerges.
* **February 6, 2026**: **BlackFile** Data Leak Site (DLS) launches.
* **Late April 2026**: **BlackFile** DLS site goes offline.
* **May 11, 2026**: **BlackFile** DLS site briefly returns online to announce its shutdown.
* **May 19, 2026**: **Redact** operators confirm the permanent cessation of **BlackFile** operations.
* **May 31, 2026**: **Pink** DLS site launches.
* **June 27, 2026**: **Redact** claims the original **BlackFile** brand was compromised by a former associate.
### Operational Cadence and Financial Gains
**Google** first documented **UNC6671** in January 2026, noting its use of tradecraft similar to the financially motivated hacking group **ShinyHunters** (also known as **Bling Libra**), though the operations are believed to be independent. The group maintains a high operational tempo, targeting dozens of organizations in North America, Australia, and the U.K.

**Google** emphasized that these compromises do not stem from vulnerabilities in vendor products, but rather highlight the effectiveness of social engineering. Between January 7 and May 12, 2026, **Google** tracked over $10.6 million in Bitcoin payments to wallets associated with the group. Initial ransom demands often exceed $3 million, with settlements averaging $750,000.
### Tactics and Mitigation Strategies
**CrowdStrike**, tracking this collective as **Cordial Spider**, characterizes the group as conducting rapid data theft and extortion. They create a false sense of urgency during vishing calls, leading victims to fraudulent AitM pages that capture authentication data and active session tokens in real-time. These credentials are then used to access the organization's identity provider (IdP), providing a single point of entry into various SaaS applications. The threat actors also establish persistence by registering adversary-controlled MFA devices to compromised accounts, often after removing existing ones.
**CrowdStrike** highlighted the group's ability to bypass individual SaaS app compromises by abusing the trust relationship between the IdP and connected services, enabling lateral movement across the victim's entire SaaS ecosystem with a single authenticated session.
**SOCRadar**'s analysis of **Pink**'s operations in June 2026 described a focus on 'Big Game Hunting' using tailored **Okta** and **Microsoft Entra ID** phishing kits, access gates to block sandboxes, and services like **Cloudflare** and **DDoS-Guard** for hosting.
Notable tactics include:
* Using credential harvesting panels on generic root domains (e.g., `passkeyhelpdesk[.]com`, `setupsso[.]com`, `idokta[.]com`) with victim-specific subdomains for targeted vishing.
* Spoofing legitimate help desk numbers to call employees on personal mobiles, directing them to fake AitM phishing pages.
* Leveraging compromised email accounts to initiate password resets for non-SSO enterprise applications, deleting confirmations and security alerts for evasion.
The group's targeting footprint has also evolved, shifting from manufacturing, real estate, healthcare, and insurance in April-May 2026, to technology, transportation, and hospitality in June 2026, and then to high-value financial and legal organizations in July 2026.
To counter this evolving threat, organizations are advised to:
* Enforce phishing-resistant MFA.
* Integrate SaaS applications and cloud platforms with SSO.
* Implement session controls.
* Restrict authentication to trusted network sources.
* Require corporate-managed devices for access.
* Monitor IdP logs for suspicious MFA registration events.
* Deploy security tooling to alert if corporate password hashes are entered into unauthorized domains.
These findings underscore how modern extortion groups operate like decentralized corporate networks, utilizing shared infrastructure across multiple public-facing brands to manage negotiations and insulate their operations. The consistent initial infection vector and campaign goals suggest a cohesive, albeit fractured, threat group or affiliate network.