UNC6671: The Evolving Vishing Threat Targeting Financial Giants
A sophisticated extortion group, tracked by Google's Threat Intelligence Group as **UNC6671**, has escalated its attacks, now targeting major hedge funds, private-equity firms, and other financial organizations. Employing highly effective voice phishing (vishing) tactics, the group aims to compromise corporate systems and exfiltrate sensitive cloud data, reportedly amassing millions in Bitcoin payments.
A recent surge in cyberattacks against prominent financial institutions has been attributed to **UNC6671**, an extortion group with a shifting identity. This group, previously known as **BlackFile**, has diversified its operations across multiple public brands including **Redact**, **Pink**, **Helix**, and **Falcon**.
Reports from Reuters and Bloomberg indicate that firms such as **Point72 Asset Management**, **Millennium Management**, **Two Sigma Investments**, and **Citadel** were among those targeted. These attacks leveraged voice phishing (vishing) to trick employees into granting unauthorized access to corporate networks.
**Point72** informed investors of an attack but found no evidence of client data theft, while **Two Sigma** successfully blocked an attempted intrusion with no impact on its systems or data.
Austin Larsen, a principal threat analyst at **Google's Threat Intelligence Group (GTIG)**, confirmed that **GTIG** tracks this vishing activity as **UNC6671**.
"While previously operating under the public brand 'BlackFile,' **UNC6671** has diversified its extortion operations across multiple public brands, including Redact, Pink, Helix, and Falcon," Larsen stated. "GTIG assesses that a single core intrusion group is driving the helpdesk vishing and cloud data theft across these various public extortion brands."
**BlackFile** first emerged in February 2025, initially targeting retail and hospitality sectors. However, according to a **Mandiant** report, the group's focus shifted in July 2026 to private-equity firms, hedge funds, major law firms, and financial-rating agencies.
"Between January and May 2026, GTIG tracked over $10.6 million USD in Bitcoin payments to group wallets. While initial demands reach upwards of $3 million, operators routinely settle for around $750,000 USD after negotiations," Larsen added.
Following the publication of initial reports, the **Falcon** extortion group released a statement disputing some of **Mandiant**'s findings. "Falcon is a Redact affiliate. We are exclusively a Redact affiliate. We are not affiliated with, connected to, or under the same umbrella as Helix, Pink, or any other group named in Mandiant's reporting," the threat actors posted on their data leak site. "We share no operators, infrastructure, tooling, negotiation channels, or proceeds with any group other than Redact."
In May 2026, the group announced its rebranding to **Redact** on its data leak site, under which it continues its operations.
## Vishing Attacks Target Cloud Environments
**UNC6671**'s modus operandi involves contacting employees on their personal mobile phones, impersonating corporate helpdesks. Attackers claim employees need to enroll in passkeys or update their multi-factor authentication settings.
Victims are then directed to spoofed corporate domains hosting adversary-in-the-middle phishing kits. These kits are designed to steal credentials and session cookies in real time.

Upon successfully stealing **Microsoft 365** or **Okta** single-sign-on accounts, the attackers gain access to the SSO dashboard, which provides a gateway to all linked cloud platforms. From there, automated tools are used to exfiltrate data from accessible cloud services. The attackers also meticulously delete security notifications and password-reset emails from compromised inboxes to cover their tracks.
**Mandiant** clarifies that the infrastructure and extortion network utilized in these attacks are distinct from those associated with **Scattered Spider (UNC3944)**, despite similarities in helpdesk social-engineering tactics.
"While the helpdesk vishing and Adversary-in-the-Middle authentication interception share similarities with methods historically associated with Scattered Spider (UNC3944), GTIG tracks this specific infrastructure, domain registration pattern, and multi-brand extortion network as UNC6671," Larsen explained.
**Mandiant** is currently assisting dozens of organizations affected by **UNC6671**'s campaigns.