At a glance
| Actor or group | UNC6671 (suspected single coordinated group) |
| Activity type | Vishing-led data theft and extortion |
| Targets | Financial services, private equity, law firms, enterprise cloud tenants |
| Scale | 141.65 BTC (about $10.69M) tracked across BlackFile wallets |
| Status | Actively tracked; no arrests reported |
| Source | Google Threat Intelligence Group (GTIG) |
TL;DR
The UNC6671 vishing extortion crew did not shut down after retiring its BlackFile brand. Instead, it spread across four new names: Redact, Pink, Helix, and Falcon. GTIG links them through shared phishing infrastructure and matching tactics.
What happened
Google Threat Intelligence Group keeps tracking UNC6671 despite a public retirement claim. In May 2026, the group announced the “shutdown” of its BlackFile extortion brand. However, GTIG says the operators never disbanded.
Telemetry told a different story. Rather than closing, UNC6671 diversified across several extortion fronts. As GTIG puts it, the group has “diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon.”
The tradecraft stayed the same throughout. Every intrusion started with helpdesk voice phishing, followed by credential theft and cloud data exfiltration.
How the vishing attack works
UNC6671 callers pose as IT helpdesk staff. They push a fake, urgent security migration. Often, they even call employees on personal mobile numbers to skirt corporate controls.
In some recent cases, the callers spoofed the real helpdesk phone number. That trick adds a false sense of legitimacy. Next, victims land on spoofed login portals built for theft.
There, AiTM credential phishing infrastructure does the work. Adversary-in-the-Middle panels intercept both passwords and MFA tokens in real time. Once operators hold a live session, they run scripts to pull data from Microsoft 365 and Okta.
Who is behind it
GTIG attributes this activity to UNC6671 with moderate confidence. Importantly, the group frames a single coordinated crew as the most likely explanation. Still, analysts note other scenarios remain possible.
The evidence centers on shared infrastructure. UNC6671 reuses generic passkey-themed root domains across many victims. As a result, one domain often bridges two separate extortion brands.
For example, the domain passkeyhelpdesk[.]com targeted a Falcon victim and a Helix victim at the same time. Identical phishing templates also appeared across several domains. GTIG concludes these overlaps “support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands.”
Interestingly, the Redact operators offered their own story. They claimed an exiled affiliate hijacked BlackFile and ran a lookalike leak site. GTIG treats that claim with caution, since splintered affiliates or shared phishing-as-a-service could also fit.
Impact and scale
The financial figures are large, though many remain claims rather than confirmed totals. Between January and May 2026, GTIG reviewed 18 BlackFile Bitcoin wallets. Together they received 141.65 BTC, worth roughly $10.69 million at the time.
Notably, payments continued after the public shutdown notice. That timing suggests the money never stopped flowing during the rebrand. Initial demands typically ran from $1 million to more than $3 million.
Negotiations often cut those numbers sharply. Operators frequently agreed to reductions of 50% to 75%. In over half of tracked cases, final payments averaged about $750,000.
Targeting also shifted over time. Early waves hit manufacturing, healthcare, and insurance firms. By July 2026, the focus narrowed to private equity, law firms, and financial rating agencies. This UNC6671 vishing extortion push clearly chases high-value, confidential deal data.
What comes next and how to stay protected
The brands may keep multiplying, but the core method stays fixed. Therefore, defenders should target the tactics, not the names. GTIG stresses phishing-resistant authentication above all.
Priority defenses
First, deploy phishing-resistant MFA such as FIDO2 keys and passkeys. These bind logins to real domains, which breaks AiTM proxies. Second, connect SaaS apps to a single SSO provider for consistent control.
Next, tighten session controls with short lifetimes and step-up checks. Also restrict logins to trusted networks and corporate-managed devices. Finally, watch identity logs for odd MFA setups and script-driven data access.
In short, strong authenticators and behavioral auditing remain the best shield against this threat.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.