UNC6671 Vishing Steals SaaS Data via Personal Phones

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- UNC6671 conducts vishing attacks by calling employees on personal mobile phones, posing as IT help desk staff facilitating urgent security migrations and directing them to spoofed adversary-in-the-middle login portals that capture credentials and MFA tokens for Microsoft 365 and Okta.
- Google Threat Intelligence Group and Mandiant documented the group's brand evolution: UNC6671 emerged in early January 2026, launched the BlackFile data leak site on February 6, 2026, then transitioned through Redact (May 2026), Pink (May 31, 2026), Helix, and Falcon.
- Between January 7 and May 12, 2026, Google tracked over $10.6 million in Bitcoin payments to wallets associated with UNC6671, with initial ransom demands exceeding $3 million and average settlements of $750,000 in more than 53% of tracked cases after 50–75% negotiation reductions.
- UNC6671 shifted its targeting footprint from manufacturing, real estate, healthcare, and insurance sectors in April–May 2026 to technology, transportation, and hospitality in June 2026, then to high-value financial and legal organizations in July 2026.
- CrowdStrike, tracking the umbrella collective as Cordial Spider, found that by abusing trust relationships between identity providers and connected services, the adversaries bypass the need to compromise individual SaaS apps and move laterally across a victim's entire SaaS ecosystem with one authenticated session.
- In a post-publication update, Falcon claimed on its data leak site that it is an exclusive Redact affiliate sharing 'no operators, infrastructure, tooling, negotiation channels, or proceeds with any group other than Redact'—a claim Google acknowledged but declined to comment further on.
- Bridewell documented an unsuccessful vishing attempt where an employee refused to follow a caller to a fraudulent Okta login page despite the caller insisting they had been 'specifically routed to the employee directly' and offering an 'alternate way' to access an internal incident ticket.
Why it matters: For enterprise security teams in financial, legal, and tech sectors, UNC6671's pivot to personal mobile phones bypasses corporate security controls, while its multi-brand structure (Redact, Pink, Helix, Falcon) fragments attribution. With $10.6M in tracked Bitcoin and $750K average settlements, this is a profitable, active operation that makes phishing-resistant MFA and IdP log monitoring urgent priorities.
Ask SkimNews



