Pink extortion group uses fake help-desk calls and MFA phishing to steal Microsoft 365 and cloud data

A newly identified extortion group called Pink is calling employees while pretending to be IT support, then stealing account credentials and company data to demand payment. Palo Alto Networks Unit 42 says the group, tracked as CL-CRI-1147 and likely linked to the criminal network known as The Com, uses voice phishing and fake help-desk interactions to capture passwords and multifactor authentication (MFA) approvals, then raids services such as SharePoint, OneDrive, and Microsoft Teams. Unit 42 said Pink's leak site went live on May 31 and published domains and IP addresses tied to the campaign as indicators of compromise.
Why it matters: This matters to organizations that rely on cloud productivity tools because attackers do not need malware or software flaws if they can talk staff into handing over access. Companies should warn staff about unsolicited help-desk calls, tighten help-desk identity checks, review Microsoft 365 logs, and block or investigate the listed phishing infrastructure immediately.

Sources

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
info@thehackernews.com (The Hacker News) 2026.09.07 68% relevant
The tactics in the article—fake IT calls, Microsoft 365 compromise, cloud data theft, and extortion—also resemble the Pink extortion playbook, but this source sounds closer to the finance-focused executive-targeting campaign already tracked under UNC6671.
Security Bulletin: Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms
Arctic Wolf 2026.09.03 91% relevant
This bulletin adds Arctic Wolf's broader tracking of the same vishing-led cloud extortion activity, tying Pink to a larger PREY-0058 cluster that also includes BlackFile, Redact, and Helix, and adds details on NodeMaven residential proxy use, executive targeting, rapid Microsoft 365/SaaS data theft, and extortion without ransomware.
Vishing Extortion Group UNC6671 Rebrands After Making Millions
Ionut Arghire 2026.08.07 84% relevant
The article says Google now assesses Pink as one of several brands used by the same UNC6671 operation, connecting the previously tracked Pink activity to the broader BlackFile/Redact/Helix/Falcon campaign and clarifying the shared vishing-led initial access and extortion playbook.
Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
Ionut Arghire 2026.07.10 95% relevant
This is a direct update on the same underlying campaign and actor, adding Okta’s details on Pink/O-UNC-066 using voice calls, fake Microsoft Entra passkey enrollment pages, real-time operator-driven phishing, and attacker passkey registration to take over Microsoft 365 accounts.
Entra passkey enrollment vishing targets Microsoft 365 users
Bill Toulas 2026.07.08 95% relevant
This article adds specific tradecraft for the same Pink extortion activity: vishing calls that abuse Microsoft Entra passkey registration campaigns, a phishing kit that imitates Entra enrollment in real time, and post-login passkey registration under attacker control to persist access and steal SharePoint and OneDrive data.
Pink is the latest goon squad to use fake helpdesk calls to steal creds
2026.06.04 100% relevant
The article establishes a distinct new threat story: a newly branded extortion cluster, Pink, with a named leak site, tradecraft, likely affiliation, and concrete indicators of compromise.
← Back to all stories