UNC6671 vishing and extortion campaign targets hedge funds and private-equity firms

A wave of cyberattacks has targeted hedge funds, private-equity firms, and other financial organizations by tricking employees over the phone into giving attackers access to company systems. Google says it tracks the group as UNC6671, previously branded publicly as BlackFile and also linked to Redact, Pink, Helix, and Falcon. The attackers spoof help desks, lure staff to company-lookalike phishing sites, steal Microsoft 365 or Okta single sign-on credentials and session cookies, then access connected cloud services and steal data for extortion.
Why it matters: This is a live social-engineering campaign against high-value financial targets, and similar help-desk calls could hit other organizations. Firms should harden help-desk and identity workflows now, and employees should be wary of unsolicited MFA, passkey, or account-update calls.

Sources

Personal Information Exposed in Apollo Global Data Breach
Eduard Kovacs 2026.08.24 92% relevant
This article adds a publicly confirmed victim to the UNC6671/BlackFile help-desk vishing campaign, stating that Apollo Global Management suffered a successful cloud-platform compromise between July 6 and 10 and that names, contact details, and Social Security numbers were exposed.
Attackers pick Levi's pockets in social engineering attack
2026.08.10 43% relevant
The article links Levi Strauss to the broader phone-based social engineering and credential-harvesting campaign Google tracks as UNC6671, but it does not confirm the same actor was responsible for Levi's breach.
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
info@thehackernews.com (The Hacker News) 2026.08.07 97% relevant
This appears to be the same UNC6671 campaign and adds detail that attackers are targeting victims through personal phones as part of vishing-led attempts to steal SaaS data.
Vishing Extortion Group UNC6671 Rebrands After Making Millions
Ionut Arghire 2026.08.07 96% relevant
This article directly updates the same UNC6671 campaign by adding that the group retired the BlackFile name and is now operating under Redact, Pink, Helix, and Falcon, while keeping the same Microsoft 365-, Okta-, AiTM-, and helpdesk-vishing-based tradecraft. It also adds new details on spoofed helpdesk numbers, password resets for non-SSO apps, domain patterns, and more than $10 million in Bitcoin payments between January and May.
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
Lawrence Abrams 2026.08.06 100% relevant
This article establishes a distinct, named campaign: UNC6671 is tied to recent vishing-led intrusions and attempted intrusions against major hedge funds and related financial firms, with concrete victims, tradecraft, and actor attribution.
← Back to all stories