A recent surge in sophisticated cyberattacks targeting prominent hedge funds, private-equity firms, and other critical financial institutions has been definitively linked to the extortion group UNC6671, an entity with strong operational ties to the threat actors previously known as BlackFile. This attribution follows extensive reporting by Reuters and Bloomberg, which detailed attempts to breach the defenses of major players such as Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel, alongside several other private-equity firms. The attackers’ modus operandi relies heavily on voice phishing, commonly known as vishing, a tactic designed to exploit human trust and trick employees into inadvertently granting access to sensitive corporate systems.
The scope and impact of these attacks underscore a growing trend in cybercriminal sophistication, moving beyond brute-force methods to exploit social engineering vulnerabilities with a high degree of precision. The financial sector, with its immense wealth and sensitive data, remains a prime target, and UNC6671’s evolving tactics present a significant challenge for even the most well-resourced security teams.
A Pattern of Aggression: The Rise of UNC6671
The attribution of these recent attacks to UNC6671 comes from Google’s Threat Intelligence Group (GTIG), which has been meticulously tracking the group’s activities. Austin Larsen, a principal threat analyst at GTIG, confirmed that the vishing operations observed are indeed orchestrated by UNC6671. Larsen further elaborated on the group’s strategic evolution, stating, "While previously operating under the public brand ‘BlackFile,’ UNC6671 has diversified its extortion operations across multiple public brands, including Redact, Pink, Helix, and Falcon." This multi-brand strategy allows the group to obfuscate its origins, broaden its attack surface, and potentially evade detection by cybersecurity firms that might be tracking specific brand names. GTIG’s assessment suggests a singular, core intrusion group is responsible for the helpdesk vishing and subsequent cloud data theft across these disparate public extortion fronts.
The origins of BlackFile, the precursor to UNC6671’s current operations, can be traced back to February 2025. At that time, the group first emerged with a series of attacks that primarily targeted organizations within the retail and hospitality sectors. This initial phase of activity provided the group with valuable experience and likely allowed them to refine their techniques before escalating their ambitions.

Shifting Sands: From Retail to High Finance
A significant shift in UNC6671’s targeting strategy was observed by Mandiant’s threat intelligence, as detailed in a recent report. Beginning in July 2026, the group demonstrably pivoted its focus away from its earlier targets in manufacturing, healthcare, real estate, technology, transportation, and hospitality. Their new prime targets became private-equity firms, hedge funds, major law firms, and financial-rating agencies. This strategic redirection signifies a calculated move towards sectors holding greater financial leverage and more sensitive intellectual property, indicating a significant escalation in their operational maturity and risk appetite.
The financial repercussions of these attacks are also substantial. Between January and May 2026 alone, GTIG documented over $10.6 million USD in Bitcoin payments flowing to wallets associated with the group. While initial ransom demands can reach staggering figures of upwards of $3 million, Larsen noted that negotiations often result in the group settling for approximately $750,000 USD. This indicates a pragmatic approach to extortion, where the group balances aggressive demands with a willingness to secure a substantial payout through negotiation, maximizing their return on investment.
The Falcon Statement: A Challenge to Attribution
Following the publication of initial reports, the Falcon extortion group, identified as one of UNC6671’s public-facing brands, issued a statement on its data leak site. This statement explicitly disputed certain aspects of Mandiant’s reporting, particularly concerning its affiliations. "Falcon is a Redact affiliate. We are exclusively a Redact affiliate. We are not affiliated with, connected to, or under the same umbrella as Helix, Pink, or any other group named in Mandiant’s reporting," the threat actors declared. They further emphasized their operational independence from other named entities, stating, "We share no operators, infrastructure, tooling, negotiation channels, or proceeds with any group other than Redact." This assertion suggests a potential internal dynamic within the UNC6671 network or an attempt by Falcon to distance itself from less reputable affiliates, a common tactic in the cybercriminal underground to manage reputation and operational security.
The rebranding of BlackFile to Redact was officially announced in May 2026 via the group’s data leak site, signaling a strategic rebranding effort under which its operations would continue. This move is typical for cybercriminal organizations seeking to shed negative publicity associated with past activities or to present a fresh face to potential victims and law enforcement.
Vishing: The Art of Deception
The core methodology employed by UNC6671 involves a sophisticated form of vishing. Attackers typically initiate contact with employees via their personal mobile phones, spoofing the caller ID to appear as if the call originates from the targeted organization’s internal helpdesk. The attackers then fabricate a pretext, often claiming that employees need to enroll in new security measures like passkeys or update their multi-factor authentication (MFA) settings.

Following this initial contact, victims are directed to malicious websites. These sites are meticulously designed to impersonate the targeted company’s legitimate web domains. Upon arrival, users are often presented with adversary-in-the-middle (AiTM) phishing kits. These kits are engineered to intercept credentials and session cookies in real-time as employees attempt to log in, effectively capturing the information needed to bypass authentication barriers.
Exploiting Cloud Infrastructure: The Crown Jewels
The primary objective of UNC6671’s vishing attacks is to gain unauthorized access to cloud environments, particularly those secured by Microsoft 365 or Okta single sign-on (SSO) solutions. Once attackers successfully steal credentials and session cookies for these SSO accounts, they gain access to the SSO dashboard. This dashboard acts as a central control panel, granting them access to a vast array of cloud platforms and services that are linked to the compromised account. This includes email, document storage, collaboration tools, and potentially sensitive customer relationship management (CRM) systems.
Once inside the cloud environment, the attackers deploy automated tools to systematically exfiltrate data from all accessible cloud services. In a critical step to cover their tracks and prevent detection or recovery, they also meticulously delete security notifications and password-reset emails from the compromised inboxes. This action aims to delay or prevent victims from realizing they have been breached and to hinder forensic investigations.
Distinguishing Tactics: UNC6671 vs. Scattered Spider
While the helpdesk vishing and AiTM authentication interception techniques bear similarities to methods historically associated with the threat actor group Scattered Spider (also tracked as UNC3944), Mandiant emphasizes crucial distinctions. The specific infrastructure, domain registration patterns, and the multi-brand extortion network employed by UNC6671 are recognized as unique identifiers. This suggests that while the tactics may overlap, the underlying operational infrastructure and organizational structure differ. This differentiation is vital for cybersecurity firms and law enforcement agencies to effectively attribute attacks and develop targeted countermeasures.
Mandiant reports that it is currently providing assistance to several dozen organizations that have fallen victim to UNC6671’s intrusions. This figure underscores the widespread nature of the threat and the significant resources being deployed to combat it. The ongoing engagement highlights the persistent and evolving nature of advanced persistent threats (APTs) and sophisticated extortion gangs in the global cybersecurity landscape.

Broader Implications and Future Outlook
The sustained targeting of financial institutions by UNC6671, leveraging advanced social engineering tactics, poses a significant threat to global financial stability and data security. The ability of such groups to adapt their methods, diversify their branding, and effectively exploit human vulnerabilities through vishing highlights the ongoing need for robust security awareness training, multi-layered security controls, and proactive threat intelligence.
The reliance on vishing as a primary attack vector is particularly concerning. While technical defenses against malware and network intrusions are continually improving, the human element remains a persistent weak link. Organizations must invest in comprehensive training programs that educate employees about the signs of phishing and vishing, emphasizing skepticism towards unsolicited communications and reinforcing proper protocols for handling sensitive information and system access requests.
Furthermore, the sophistication of the AiTM phishing kits and the attackers’ ability to navigate and exfiltrate data from cloud environments indicate a high level of technical proficiency. This necessitates a continuous evaluation and strengthening of cloud security postures, including rigorous access controls, continuous monitoring, and rapid incident response capabilities. The challenge lies not only in preventing initial access but also in detecting and mitigating the lateral movement and data exfiltration that often follow a successful breach.
The evolution of UNC6671 from targeting retail and hospitality to high-value financial targets demonstrates a clear escalation in ambition and capability. As these groups mature, their methods will likely become even more sophisticated, making attribution and defense increasingly complex. The ongoing efforts by organizations like Google’s Threat Intelligence Group and Mandiant are crucial in shedding light on these operations, enabling the cybersecurity community to stay ahead of the curve and protect critical infrastructure from the ever-present threat of cyber extortion. The financial sector, in particular, must remain vigilant, adapt its defenses, and foster a security-conscious culture to withstand the persistent and evolving threats posed by groups like UNC6671.








