As cited
Copy frozen at (site build).
threat intel
Welcome to BlackFile: Inside a Vishing Extortion Operation
Google Threat Intelligence Group identified UNC6671, operating under the BlackFile brand, conducting a large-scale extortion campaign targeting organizations across North America, Australia, and the UK through voice phishing and single sign-on compromise. The group uses adversary-in-the-middle techniques to capture credentials and multi-factor authentication (MFA) codes in real-time, gaining access to cloud environments like Microsoft 365 and Okta to exfiltrate data for extortion. UNC6671 employs social engineering pretexts such as mandatory passkey migrations and MFA updates, along with lookalike credential harvesting domains, to deceive employees into providing access.
Why it matters: Organizations should implement phishing-resistant MFA and security awareness training to defend against real-time credential interception, as traditional MFA can be bypassed when victims are socially engineered during active vishing calls.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Welcome to BlackFile: Inside a Vishing Extortion Operation
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Welcome to BlackFile: Inside a Vishing Extortion Operation
Google Threat Intelligence Group documented UNC6671, a threat actor operating under the BlackFile brand, conducting a large-scale extortion campaign since early 2026 targeting dozens of organizations in North America, Australia, and the UK. The group uses sophisticated voice phishing and real-time adversary-in-the-middle techniques to bypass multifactor authentication (MFA) and compromise Microsoft 365 and Okta environments, then exfiltrates data for extortion. UNC6671 operates independently from ShinyHunters despite occasional brand co-option, and registers credential harvesting domains with Tucows using passkey and enrollment-themed subdomains to enhance social engineering credibility.
Why it matters: Organizations using Microsoft 365 or Okta are actively targeted by UNC6671's vishing campaigns, which exploit human factors rather than software vulnerabilities; security teams must implement phishing-resistant MFA and add real-time monitoring for suspicious device registrations and MFA approval patterns to detect compromise in progress.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Welcome to BlackFile: Inside a Vishing Extortion Operation
Google Threat Intelligence Group documented UNC6671, a threat actor operating under the BlackFile brand, conducting a large-scale extortion campaign since early 2026 targeting dozens of organizations in North America, Australia, and the UK. The group uses sophisticated voice phishing and real-time adversary-in-the-middle techniques to bypass multifactor authentication (MFA) and compromise Microsoft 365 and Okta environments, then exfiltrates data for extortion. UNC6671 operates independently from ShinyHunters despite occasional brand co-option, and registers credential harvesting domains with Tucows using passkey and enrollment-themed subdomains to enhance social engineering credibility.
Why it matters: Organizations using Microsoft 365 or Okta are actively targeted by UNC6671's vishing campaigns, which exploit human factors rather than software vulnerabilities; security teams must implement phishing-resistant MFA and add real-time monitoring for suspicious device registrations and MFA approval patterns to detect compromise in progress.
- Source published
- First seen by Cybersecurity Tracker