A wave of cyberattacks has targeted hedge funds, private-equity firms, and other financial organizations by tricking employees over the phone into giving attackers access to company systems. Google says it tracks the group as UNC6671, previously branded publicly as BlackFile and also linked to Redact, Pink, Helix, and Falcon. The attackers spoof help desks, lure staff to company-lookalike phishing sites, steal Microsoft 365 or Okta single sign-on credentials and session cookies, then access connected cloud services and steal data for extortion.
Why it matters: This is a live social-engineering campaign against high-value financial targets, and similar help-desk calls could hit other organizations. Firms should harden help-desk and identity workflows now, and employees should be wary of unsolicited MFA, passkey, or account-update calls.
Eduard Kovacs
2026.08.24
92% relevant
This article adds a publicly confirmed victim to the UNC6671/BlackFile help-desk vishing campaign, stating that Apollo Global Management suffered a successful cloud-platform compromise between July 6 and 10 and that names, contact details, and Social Security numbers were exposed.
2026.08.10
43% relevant
The article links Levi Strauss to the broader phone-based social engineering and credential-harvesting campaign Google tracks as UNC6671, but it does not confirm the same actor was responsible for Levi's breach.
info@thehackernews.com (The Hacker News)
2026.08.07
97% relevant
This appears to be the same UNC6671 campaign and adds detail that attackers are targeting victims through personal phones as part of vishing-led attempts to steal SaaS data.
Ionut Arghire
2026.08.07
96% relevant
This article directly updates the same UNC6671 campaign by adding that the group retired the BlackFile name and is now operating under Redact, Pink, Helix, and Falcon, while keeping the same Microsoft 365-, Okta-, AiTM-, and helpdesk-vishing-based tradecraft. It also adds new details on spoofed helpdesk numbers, password resets for non-SSO apps, domain patterns, and more than $10 million in Bitcoin payments between January and May.
Lawrence Abrams
2026.08.06
100% relevant
This article establishes a distinct, named campaign: UNC6671 is tied to recent vishing-led intrusions and attempted intrusions against major hedge funds and related financial firms, with concrete victims, tradecraft, and actor attribution.
← Back to all stories