Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike login site that captures passwords and live session tokens to access Microsoft 365 and Okta. The activity targeted major private equity and financial firms (e.g., Blackstone, KKR, CME) and also included attempted intrusions at large hedge funds.
Key findings
- Attackers vish employees on personal phones using a spoofed number that matches the corporate IT help desk.
- Pretext is urgent same-day enrollment: “a FIDO2 passkey enrollment or a multifactor update has to be done that day.”
- Victims are sent to a look-alike subdomain (example: “[company].createssopasskey[.]com”) that uses an adversary-in-the-middle proxy to capture both password and live session token.
- Post-compromise activity includes deleting password reset confirmations and MFA-change alerts to reduce detection.
- Data is pulled from Microsoft 365 and Okta tenants using automated scripts; suspicious user agents include “python-requests” and “Windows PowerShell.”
- Google tied the activity to UNC6671 and notes multiple extortion ‘brands’ sharing infrastructure (Redact, Pink, Helix, Falcon) linked to the retired BlackFile brand.
- Ransom/extortion economics: Google tracked ~$10.7M into linked wallets; demands often started at $1M–$3M and sometimes settled near ~$750K.
Who’s being targeted
- Commonly targeted roles: All employees, Executives, Finance, Legal, IT help desk, Identity & Access Management (Okta/Microsoft 365) admins, Security operations / incident response.
- Affected industries: Private equity, Investment management / hedge funds, Financial services, Law firms, Manufacturing, Real estate, Healthcare (hospitals), Insurance.
- Attack channels: vishing, website.
- Impersonated: Corporate IT help desk, Employer single sign-on (SSO) / passkey enrollment portal.
Awareness takeaways
- Treat urgent ‘same-day’ MFA/passkey enrollment calls as suspicious and verify using a known internal channel (don’t trust caller ID).
- Don’t click login or enrollment links provided during unsolicited calls; navigate to the official company login portal yourself.
- Watch for stealth signs after an account is accessed, like missing password-reset emails or missing MFA-change alerts, report immediately.
- Flag unusually large, automated cloud file access as a potential account takeover, especially from scripting tools.
Red flags to watch for
- Unsolicited urgent call to personal mobile phone about same-day security enrollment
- Caller ID/number match is relied on as proof (spoofable)
- Link goes to an odd subdomain/domain not the company’s normal login URL
- Domain is not the legitimate corporate domain
- Unexpected login prompts after a phone call
- Any page that results in repeated login/MFA prompts (possible proxy-in-the-middle)
Read the video transcript
You’re at home, personal phone rings. Caller ID says it’s the company IT help desk, spoofed to look legit. The voice says, “We need your FIDO2 passkey or MFA updated today,” and texts you a link: yourcompany.createssopasskey.com. It looks like your SSO, but it’s an adversary-in-the-middle proxy stealing your password and live session token. Behind the scenes, scripts using agents like 'python-requests' and 'Windows PowerShell' start pulling data from Microsoft 365 and Okta, while password reset and MFA-change emails quietly disappear from your inbox. Aha to remember: if someone calls your personal phone about a same-day passkey or MFA update, hang up and contact IT through Teams, the helpdesk portal, or the number on our intranet, never through the number or link they just gave you.