CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Details emerge on BlackFile’s recent attacks on financial companies

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4562

As cited

Copy frozen at (site build).

threat intel

Details emerge on BlackFile’s recent attacks on financial companies

BlackFile, tracked by Google as UNC6671, has conducted sustained attacks against financial firms, private equity, law firms, and other organizations since the start of the year, recently splitting extortion operations across four brands (Redact, Pink, Helix, Falcon) with shared infrastructure. The group uses voice-phishing and social engineering to impersonate IT support, targets an average of 1.5 new victims daily, and negotiates extortion demands typically down from $3 million to under $1 million. Mandiant has responded to compromises at more than two dozen organizations since January, with continued targeting observed into the most recent week.

Why it matters: Financial services, private equity, healthcare, and med tech organizations face immediate risk from BlackFile's high-frequency targeting and escalation tactics including swatting; practitioners should treat inbound calls impersonating IT support as a primary attack vector and prepare incident response for potential data theft extortion.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Details emerge on BlackFile’s recent attacks on financial companies

BlackFile, tracked by Google as UNC6671, has conducted sustained attacks against financial firms, private equity, law firms, and other organizations since the start of the year, recently splitting extortion operations across four brands (Redact, Pink, Helix, Falcon) with shared infrastructure. The group uses voice-phishing and social engineering to impersonate IT support, targets an average of 1.5 new victims daily, and negotiates extortion demands typically down from $3 million to under $1 million. Mandiant has responded to compromises at more than two dozen organizations since January, with continued targeting observed into the most recent week.

Why it matters: Financial services, private equity, healthcare, and med tech organizations face immediate risk from BlackFile's high-frequency targeting and escalation tactics including swatting; practitioners should treat inbound calls impersonating IT support as a primary attack vector and prepare incident response for potential data theft extortion.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary