UNC6671 Exploits Vishing to Breach SaaS Platforms via Personal Devices

A recent surge in cyber attacks targeting sectors such as financial services, private equity, and professional services has been linked to the data extortion group UNC6671. This group employs sophisticated voice phishing (vishing) techniques, impersonating IT help desk personnel to deceive employees into divulging sensitive information.

Notably, UNC6671 has shifted its focus to contacting employees through their personal mobile devices. During these calls, victims are directed to counterfeit login portals designed to capture credentials and multi-factor authentication (MFA) tokens. By utilizing adversary-in-the-middle (AitM) infrastructure, the attackers intercept this data, enabling them to establish persistent sessions within enterprise cloud environments and Software-as-a-Service (SaaS) applications, including Microsoft 365 and Okta.

Once access is secured, UNC6671 deploys automated scripts written in Python and PowerShell to exfiltrate data from these platforms. The group’s operations have evolved over time, operating under various extortion brands such as Redact, Pink (also known as CL-CRI-1147), Helix, and Falcon (CL-CRI-1182). Previously, they operated under the BlackFile brand (CL-CRI-1116), which was retired on May 11, 2026.

The timeline of UNC6671’s activities is as follows:

  • Early January 2026: Emergence of UNC6671.
  • February 6, 2026: Launch of the BlackFile Data Leak Site (DLS).
  • Late April 2026: BlackFile DLS site goes offline.
  • May 11, 2026: Brief reappearance of BlackFile DLS site announcing the cessation of operations under the BlackFile name.
  • May 19, 2026: Redact operators declare the official and permanent cessation of all operations under the BlackFile name.
  • May 31, 2026: Launch of the Pink DLS site.
  • June 27, 2026: Redact claims that the original BlackFile brand was compromised and hijacked by a former associate, leading to unauthorized extortion campaigns.

UNC6671 was first identified in January 2026, employing tactics traditionally associated with the financially motivated hacking group ShinyHunters (also known as Bling Libra). Despite these similarities, it is believed that UNC6671 operates independently. The group maintains a high operational tempo, targeting numerous organizations across North America, Australia, and the United Kingdom.

These breaches are not due to vulnerabilities in vendor products or infrastructure but highlight the effectiveness of social engineering tactics. This underscores the critical need for organizations to adopt phishing-resistant MFA solutions to safeguard their SaaS and identity platforms.

Cybersecurity firm CrowdStrike, tracking the group under the moniker Cordial Spider, describes UNC6671’s operations as rapid data theft and extortion campaigns. The group impersonates IT staff during vishing calls, creating a false sense of urgency related to account issues or security updates. Victims are led to fraudulent AitM pages that capture their authentication data and active session tokens in real time.

By exploiting these credentials, the attackers gain access to the organization’s identity provider (IdP), serving as a gateway to various SaaS applications. They further establish persistence by registering attacker-controlled MFA devices to compromised accounts, often removing existing MFA devices in the process.

UNC6671’s evolving tactics, particularly their use of personal mobile devices for vishing attacks, highlight the increasing sophistication of cyber threats. Organizations must enhance their security awareness training, implement robust MFA solutions, and remain vigilant against social engineering tactics to mitigate the risk posed by such adversaries.