The Google Threat Intelligence Group (GTIG) reports that the UNC6671 extortion group has rebranded its operations. Previously known as BlackFile, the group now operates under multiple new names including Redact, Pink (also known as CL-CRI-1147), Helix, and Falcon (also known as CL-CRI-1182). This rebranding occurred despite an alleged announcement in May 2026 of the BlackFile brand's retirement.
UNC6671 continues to rely on voice phishing (vishing) as its primary attack method. Threat actors pose as IT helpdesk staff, contacting enterprise employees, often on their personal mobile devices, under the pretext of urgent security migrations. These calls direct victims to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens.
Once session persistence is established, the group deploys automated scripts, including Python and PowerShell, for data exfiltration. Their targets include enterprise cloud environments and SaaS applications such as Microsoft 365 and Okta. This method allows them to bypass defenses and gain access to sensitive corporate data.
The latest attacks by UNC6671 have primarily focused on organizations within the financial services, private equity, and professional services sectors. Specific firms reportedly targeted include Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. Point72 stated it found no evidence of client data theft, while Two Sigma reported blocking an attempted intrusion with no indication of system or data compromise.
The group emerged in early 2026, and GTIG previously warned of its targeting of dozens of organizations across North America, Australia, and the UK. The diversification of its operations across multiple brands indicates a continued and active threat, despite the alleged retirement of its initial brand.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The data extortion group UNC6671 is conducting vishing attacks by posing as IT help desk staff and contacting employees on personal mobile devices to steal credentials and MFA tokens. This allows them to exfiltrate data from enterprise cloud environments and SaaS applications like Microsoft 365 and Okta, impacting financial services, private equity, and professional services.
The extortion group UNC6671, known for its IT helpdesk vishing attacks, has rebranded from 'BlackFile' to multiple new identities including Redact, Pink, Helix, and Falcon. This diversification allows the group to continue targeting organizations, primarily in financial services, private equity, and professional services, using consistent tactics to bypass multi-factor authentication and gain cloud access.
A series of cyberattacks targeting hedge funds and financial firms, including Point72 and Two Sigma, has been attributed to the UNC6671 extortion group. This group uses voice phishing (vishing) to gain access to corporate systems, and Google's Threat Intelligence Group (GTIG) tracks its operations across multiple extortion brands.
The UNC6671 threat group, previously known for BlackFile extortion, has rebranded its operations under multiple new names including Redact, Pink, Helix, and Falcon, despite an alleged retirement announcement. The group continues to use voice phishing (vishing) to target enterprise employees, leading to data theft from cloud environments like Microsoft 365 and Okta, particularly focusing on financial and professional services.