CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

August 7, 2026

A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to the data extortion group UNC6671. According to a report from Google Threat Intelligence Group (GTIG) and Mandiant, UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff to facilitate mandatory, urgent security migrations. Notably, the threat actor often contacts employees via their personal mobile devices.

The calls are designed to trick victims into spoofed login portals where adversary-in-the-middle (AitM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens. The threat actors then use the captured data to establish session persistence and deploy automated Python and PowerShell scripts for data exfiltration from enterprise cloud environments and SaaS applications, including Microsoft 365 and Okta.

UNC6671 has diversified its operations across multiple extortion brands, including Redact, Pink (aka CL-CRI-1147), Helix, and Falcon (aka CL-CRI-1182). Previously, it operated under the BlackFile (aka CL-CRI-1116) brand, which was retired on May 11, 2026. The group was first documented by Google in January 2026 as one of the threat clusters leveraging tradecraft traditionally associated with the financially motivated hacking group ShinyHunters (aka Bling Libra), though it is assessed to be acting independently.

CrowdStrike, tracking the collective as Cordial Spider, characterized the group as conducting rapid data theft and extortion campaigns by impersonating IT during vishing calls and creating a false sense of urgency. The threat actors establish persistence by registering adversary-controlled MFA devices to compromised accounts, often after removing existing MFA devices. By abusing the trust relationship between the identity provider (IdP) and connected services, they bypass the need to compromise individual SaaS apps and move laterally across the victim’s entire SaaS ecosystem.

In an analysis of Pink’s operations, SOCRadar described the group as focused on Big Game Hunting using tailored Okta and Microsoft Entra ID phishing kits, access gates to block sandboxes, and hosting on Cloudflare and DDoS-Guard. The threat actors also use credential harvesting panels on generic root domains, spoof legitimate help desk phone numbers, and rely on compromised email accounts to initiate password resets and delete security alerts for defense evasion.

Between January 7 and May 12, 2026, Google tracked over $10.6 million in Bitcoin payments to wallets associated with the group. Initial ransom demands reach north of $3 million, with reductions between 50% and 75% during negotiations. In more than 53% of tracked cases, the threat actors settled for an average of $750,000.

To counter the threat, organizations are recommended to enforce phishing-resistant MFA, integrate SaaS applications with SSO, implement session controls, restrict authentication to trusted network sources, require corporate-managed devices, monitor IdP logs for suspicious MFA registration events, and deploy security tooling to alert if corporate password hashes are entered into unauthorized domains.

CVEs: CVE-2026-50522

Attack groups: UNC6671, ShinyHunters, Cordial Spider, Scattered LAPSUS$ Hunters

Companies: Google, Mandiant, CrowdStrike, SOCRadar, Microsoft, Okta, Cloudflare, DDoS-Guard, Tucows, Nicenic

Products: Microsoft 365, Okta, Microsoft Entra ID