A newly identified extortion group called Pink is calling employees while pretending to be IT support, then stealing account credentials and company data to demand payment. Palo Alto Networks Unit 42 says the group, tracked as CL-CRI-1147 and likely linked to the criminal network known as The Com, uses voice phishing and fake help-desk interactions to capture passwords and multifactor authentication (MFA) approvals, then raids services such as SharePoint, OneDrive, and Microsoft Teams. Unit 42 said Pink's leak site went live on May 31 and published domains and IP addresses tied to the campaign as indicators of compromise.
info@thehackernews.com (The Hacker News)
2026.09.07
68% relevant
The tactics in the article—fake IT calls, Microsoft 365 compromise, cloud data theft, and extortion—also resemble the Pink extortion playbook, but this source sounds closer to the finance-focused executive-targeting campaign already tracked under UNC6671.
Arctic Wolf
2026.09.03
91% relevant
This bulletin adds Arctic Wolf's broader tracking of the same vishing-led cloud extortion activity, tying Pink to a larger PREY-0058 cluster that also includes BlackFile, Redact, and Helix, and adds details on NodeMaven residential proxy use, executive targeting, rapid Microsoft 365/SaaS data theft, and extortion without ransomware.
Ionut Arghire
2026.08.07
84% relevant
The article says Google now assesses Pink as one of several brands used by the same UNC6671 operation, connecting the previously tracked Pink activity to the broader BlackFile/Redact/Helix/Falcon campaign and clarifying the shared vishing-led initial access and extortion playbook.
Ionut Arghire
2026.07.10
95% relevant
This is a direct update on the same underlying campaign and actor, adding Okta’s details on Pink/O-UNC-066 using voice calls, fake Microsoft Entra passkey enrollment pages, real-time operator-driven phishing, and attacker passkey registration to take over Microsoft 365 accounts.
Bill Toulas
2026.07.08
95% relevant
This article adds specific tradecraft for the same Pink extortion activity: vishing calls that abuse Microsoft Entra passkey registration campaigns, a phishing kit that imitates Entra enrollment in real time, and post-login passkey registration under attacker control to persist access and steal SharePoint and OneDrive data.
2026.06.04
100% relevant
The article establishes a distinct new threat story: a newly branded extortion cluster, Pink, with a named leak site, tradecraft, likely affiliation, and concrete indicators of compromise.