CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Welcome to BlackFile: Inside a Vishing Extortion Operation

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 312

As cited

Copy frozen at (site build).

threat intel

Welcome to BlackFile: Inside a Vishing Extortion Operation

Google Threat Intelligence Group identified UNC6671, operating under the BlackFile brand, conducting a large-scale extortion campaign targeting organizations across North America, Australia, and the UK through voice phishing and single sign-on compromise. The group uses adversary-in-the-middle techniques to capture credentials and multi-factor authentication (MFA) codes in real-time, gaining access to cloud environments like Microsoft 365 and Okta to exfiltrate data for extortion. UNC6671 employs social engineering pretexts such as mandatory passkey migrations and MFA updates, along with lookalike credential harvesting domains, to deceive employees into providing access.

Why it matters: Organizations should implement phishing-resistant MFA and security awareness training to defend against real-time credential interception, as traditional MFA can be bypassed when victims are socially engineered during active vishing calls.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Welcome to BlackFile: Inside a Vishing Extortion Operation

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Welcome to BlackFile: Inside a Vishing Extortion Operation

Google Threat Intelligence Group documented UNC6671, a threat actor operating under the BlackFile brand, conducting a large-scale extortion campaign since early 2026 targeting dozens of organizations in North America, Australia, and the UK. The group uses sophisticated voice phishing and real-time adversary-in-the-middle techniques to bypass multifactor authentication (MFA) and compromise Microsoft 365 and Okta environments, then exfiltrates data for extortion. UNC6671 operates independently from ShinyHunters despite occasional brand co-option, and registers credential harvesting domains with Tucows using passkey and enrollment-themed subdomains to enhance social engineering credibility.

Why it matters: Organizations using Microsoft 365 or Okta are actively targeted by UNC6671's vishing campaigns, which exploit human factors rather than software vulnerabilities; security teams must implement phishing-resistant MFA and add real-time monitoring for suspicious device registrations and MFA approval patterns to detect compromise in progress.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Welcome to BlackFile: Inside a Vishing Extortion Operation

Google Threat Intelligence Group documented UNC6671, a threat actor operating under the BlackFile brand, conducting a large-scale extortion campaign since early 2026 targeting dozens of organizations in North America, Australia, and the UK. The group uses sophisticated voice phishing and real-time adversary-in-the-middle techniques to bypass multifactor authentication (MFA) and compromise Microsoft 365 and Okta environments, then exfiltrates data for extortion. UNC6671 operates independently from ShinyHunters despite occasional brand co-option, and registers credential harvesting domains with Tucows using passkey and enrollment-themed subdomains to enhance social engineering credibility.

Why it matters: Organizations using Microsoft 365 or Okta are actively targeted by UNC6671's vishing campaigns, which exploit human factors rather than software vulnerabilities; security teams must implement phishing-resistant MFA and add real-time monitoring for suspicious device registrations and MFA approval patterns to detect compromise in progress.

VendorsMicrosoftGoogleOkta
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary