← All stories
● Covered by 4 sources · 4 reportsMedium impact2 negative2 neutral

UNC6671 Extortion Group Rebrands and Continues Vishing Attacks on Financial Firms

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • UNC6671 rebranded from BlackFile to Redact, Pink, Helix, and Falcon.
  • The group uses vishing, posing as IT helpdesk, to target employees.
  • Attacks involve spoofed login portals to intercept credentials and MFA tokens.
  • Data exfiltration occurs from cloud environments like Microsoft 365 and Okta.
  • Targets include financial services, private equity, and professional services firms.

Extortion Group Rebrands Operations

The Google Threat Intelligence Group (GTIG) reports that the UNC6671 extortion group has rebranded its operations. Previously known as BlackFile, the group now operates under multiple new names including Redact, Pink (also known as CL-CRI-1147), Helix, and Falcon (also known as CL-CRI-1182). This rebranding occurred despite an alleged announcement in May 2026 of the BlackFile brand's retirement.

Continued Vishing Tactics

UNC6671 continues to rely on voice phishing (vishing) as its primary attack method. Threat actors pose as IT helpdesk staff, contacting enterprise employees, often on their personal mobile devices, under the pretext of urgent security migrations. These calls direct victims to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens.

Targeting Cloud Environments

Once session persistence is established, the group deploys automated scripts, including Python and PowerShell, for data exfiltration. Their targets include enterprise cloud environments and SaaS applications such as Microsoft 365 and Okta. This method allows them to bypass defenses and gain access to sensitive corporate data.

Focus on Financial and Professional Services

The latest attacks by UNC6671 have primarily focused on organizations within the financial services, private equity, and professional services sectors. Specific firms reportedly targeted include Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. Point72 stated it found no evidence of client data theft, while Two Sigma reported blocking an attempted intrusion with no indication of system or data compromise.

Broader Impact

The group emerged in early 2026, and GTIG previously warned of its targeting of dozens of organizations across North America, Australia, and the UK. The diversification of its operations across multiple brands indicates a continued and active threat, despite the alleged retirement of its initial brand.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The data extortion group UNC6671 is conducting vishing attacks by posing as IT help desk staff and contacting employees on personal mobile devices to steal credentials and MFA tokens. This allows them to exfiltrate data from enterprise cloud environments and SaaS applications like Microsoft 365 and Okta, impacting financial services, private equity, and professional services.

The extortion group UNC6671, known for its IT helpdesk vishing attacks, has rebranded from 'BlackFile' to multiple new identities including Redact, Pink, Helix, and Falcon. This diversification allows the group to continue targeting organizations, primarily in financial services, private equity, and professional services, using consistent tactics to bypass multi-factor authentication and gain cloud access.

A series of cyberattacks targeting hedge funds and financial firms, including Point72 and Two Sigma, has been attributed to the UNC6671 extortion group. This group uses voice phishing (vishing) to gain access to corporate systems, and Google's Threat Intelligence Group (GTIG) tracks its operations across multiple extortion brands.

The UNC6671 threat group, previously known for BlackFile extortion, has rebranded its operations under multiple new names including Redact, Pink, Helix, and Falcon, despite an alleged retirement announcement. The group continues to use voice phishing (vishing) to target enterprise employees, leading to data theft from cloud environments like Microsoft 365 and Okta, particularly focusing on financial and professional services.