SYS::ONLINE
Wasteland.
Briefs1802
Issues22
SinceFeb 2026
LIVE
▣ Breach UNC6671-HELPDESK-V 2026-08-09

Financial Sector: UNC6671 Helpdesk Vishing and Multi-Brand Extortion

"A single core intrusion crew operating behind at least four extortion brands has spent 2026 phoning employees at hedge funds, private equity firms, and professional services companies, posing as their IT help desk and…"

A single core intrusion crew operating behind at least four extortion brands has spent 2026 phoning employees at hedge funds, private equity firms, and professional services companies, posing as their IT help desk and walking them through fake "security migrations" that hand over passwords and live MFA codes. Google Threat Intelligence Group (GTIG) published its assessment on August 6, 2026, tracking the activity as UNC6671 and linking the Redact, Pink, Helix, and Falcon extortion brands to the retired BlackFile operation. Google itself named no victims. Reuters and Bloomberg reporting, relayed by Security Affairs, TechCrunch, and BleepingComputer, put Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, TPG, Clearlake Capital, Point72, Millennium Management, Two Sigma, and Citadel on the target list. Victim counts differ sharply across sources and are worth reading carefully: Security Affairs frames the campaign as targeting "over 200 firms," while GTIG's own May 2026 reporting described "dozens" of organizations across North America, Australia, and the UK, and the August update quantifies no total at all. Treat 200-plus as press framing, not a vendor-confirmed number.

What Happened

GTIG's core finding is that BlackFile did not shut down. The brand announced its retirement in May 2026, and in June the operators stood up a new data leak site under the Redact name, publishing a post on June 27 claiming the original BlackFile brand had been hijacked by an exiled affiliate who ran a lookalike leak site, used unlinked Tox identities, and orchestrated the supposed shutdown. GTIG's telemetry and infrastructure analysis tells a different story: overlaps in phishing templates, victimology, and shared infrastructure conduits tie BlackFile, Redact, Pink, Helix, and Falcon to the same operators.

Austin Larsen, a principal threat analyst at GTIG, told BleepingComputer that "a single core intrusion group is driving the helpdesk vishing and cloud data theft across these various public extortion brands." GTIG's public assessment is that the multi-brand structure "most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes and isolate any negotiation fallout." Google is explicit that this is an assessment, not a proof: it names splintered affiliates and shared phishing-as-a-service infrastructure as plausible alternative explanations, and TechCrunch notes it remains unclear whether the brands are affiliates, splinters, or something else.

Accounts also differ on the group's origin. BleepingComputer dates BlackFile's emergence to February 2025, tied to a wave of attacks on retail and hospitality targets. SecurityWeek says the actor emerged in early 2026 under the BlackFile name. Both are OUTLET-tier and the primary GTIG post excerpted here does not settle it.

Targeting shifted in July 2026 toward private equity, financial services, and professional services, per Mandiant's reporting as summarized by BleepingComputer. Victim responses vary. Point72 reportedly told investors it had been attacked but found no evidence client data was stolen. Two Sigma said it blocked an attempted intrusion with no indication its systems or data were affected. Millennium and Citadel declined to comment to BleepingComputer, with Citadel pointing to Bloomberg's reporting.

Separately, Levi Strauss & Co. disclosed in an SEC filing that an attacker social-engineered three employees and exfiltrated corporate data from company-issued machines. BleepingComputer reports that some media outlets have linked that incident to UNC6671, but could not identify any threat actor claiming the attack, and no leak-site claim has surfaced. That link is unconfirmed.

What Was Taken

There is no record count in this incident, and no source provides one. What GTIG describes is bulk data theft from enterprise cloud tenants: once the attackers establish session persistence using stolen credentials and intercepted MFA tokens, they deploy automated scripts to exfiltrate data from Microsoft 365 and Okta environments. The stolen material is then used as extortion leverage, published or threatened for publication on brand-specific leak sites.

The sensitivity is a function of who was hit. Private equity firms, hedge funds, ratings agencies, and exchange operators hold deal documents, investor and LP correspondence, position data, and pre-public transaction material. That is data whose value comes from being non-public, which makes threatened publication unusually coercive compared with a commodity PII dump.

On payments, Security Affairs reports that some companies paid ransoms but that none of the payers have been identified. SecurityWeek's reporting characterizes the operation as having made millions across its rebrands. No source in this set gives a dollar figure or a count of paying victims.

For Levi's, the company's own SEC filing is the strongest evidence available: it believes certain corporate information was accessed and exfiltrated, that its response contained and terminated the unauthorized access, that no consumer data was impacted, and that there was no operational disruption or expected material financial impact. That investigation remains ongoing.

Why It Matters

This campaign is a direct refutation of the idea that MFA rollout closes the phishing problem. Every victim here presumably had multi-factor authentication deployed. The attackers did not break it; they asked for it, in real time, over the phone, and used it before it expired.

Three things make UNC6671 a harder defensive problem than a typical phishing crew. First, the attack channel bypasses corporate controls entirely: calls go to employees' personal mobile numbers, where no email gateway, no EDR, and no corporate telephony policy applies. Second, GTIG reports the actors have begun spoofing the organization's legitimate help desk number, which defeats the most common piece of user guidance ("check the number before you trust the caller"). Third, the compartmentalization strategy has an intelligence effect defenders should internalize: if one crew runs four leak sites, then every public breach tally derived from leak-site counting understates the real volume, and each victim negotiating with "Falcon" has no way to know they are talking to the same people who breached their peer under a different name.

The sector concentration matters too. A crew that has learned the vocabulary, tooling, and escalation rituals of one private equity firm's IT organization can reuse that pretext against the next twenty. The financial services focus is not opportunistic; it is a pretext economy of scale.

The Attack Technique

The chain is consistent across every brand, and consistency is itself part of GTIG's attribution basis.

  1. Vishing to a personal device. The caller reaches the target on a personal mobile number, posing as internal IT help desk staff or, per TechCrunch, sometimes as a co-worker. In at least some recent cases the legitimate help desk number is spoofed to add legitimacy.
  2. Urgency pretext. The stated reason is a mandatory, urgent security migration. PYMNTS, quoting the GTIG post, describes the specific pretext as an urgent help desk mandate to enable FIDO2 passkeys or update MFA enrollment. The irony is deliberate: the lure is a security improvement.
  3. AiTM credential harvesting. The victim is directed to a spoofed login portal backed by adversary-in-the-middle infrastructure that relays the session to the real identity provider, capturing the password and the second-factor token as they are entered. Security Affairs describes the operator harvesting the passcode live over the phone and hijacking the account before the call ends.
  4. Session persistence. With a valid session established, the attackers hold access independent of the original credential, which survives a routine password change.
  5. Automated cloud exfiltration. Scripts pull data from Microsoft 365 and Okta tenants at speed.
  6. Anti-forensics. Security Affairs reports the attackers delete security alerts and password reset notifications from compromised accounts, so the employee who took the call sees nothing unusual afterward.
  7. Extortion. Leak sites under the relevant brand carry the negotiation posture. One site quoted by TechCrunch reads: "We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement."

One note on source hygiene: the PYMNTS write-up quotes GTIG as saying "UNC6771 callers," which appears to be a transcription error for UNC6671. Security Affairs quotes the same passage with the correct designation.

What Organizations Should Do

Sources: Hackers Impersonate IT Support to Breach Leading Financial Companies | UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets ... | Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion... | Google says hackers are calling financial firm employees to hack an... | Vishing Extortion Group UNC6671 Rebrands After Making Millions | Google Links Redact Extortion Group to BlackFile Rebrand - Infosecu... | Levi Strauss & Co. says hackers stole corporate data in cyberattack | PYMNTS Hackers Spoof Helpdesk Numbers to Steal Enterprise Cloud Data