BlackFile Crew Vishing Hits PE and Finance Firms

SiliconANGLE Security · High sophistication
Last updated August 12, 2026

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike login site that captures passwords and live session tokens to access Microsoft 365 and Okta. The activity targeted major private equity and financial firms (e.g., Blackstone, KKR, CME) and also included attempted intrusions at large hedge funds.

Key findings

  • Attackers vish employees on personal phones using a spoofed number that matches the corporate IT help desk.
  • Pretext is urgent same-day enrollment: “a FIDO2 passkey enrollment or a multifactor update has to be done that day.”
  • Victims are sent to a look-alike subdomain (example: “[company].createssopasskey[.]com”) that uses an adversary-in-the-middle proxy to capture both password and live session token.
  • Post-compromise activity includes deleting password reset confirmations and MFA-change alerts to reduce detection.
  • Data is pulled from Microsoft 365 and Okta tenants using automated scripts; suspicious user agents include “python-requests” and “Windows PowerShell.”
  • Google tied the activity to UNC6671 and notes multiple extortion ‘brands’ sharing infrastructure (Redact, Pink, Helix, Falcon) linked to the retired BlackFile brand.
  • Ransom/extortion economics: Google tracked ~$10.7M into linked wallets; demands often started at $1M–$3M and sometimes settled near ~$750K.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Legal, IT help desk, Identity & Access Management (Okta/Microsoft 365) admins, Security operations / incident response.
  • Affected industries: Private equity, Investment management / hedge funds, Financial services, Law firms, Manufacturing, Real estate, Healthcare (hospitals), Insurance.
  • Attack channels: vishing, website.
  • Impersonated: Corporate IT help desk, Employer single sign-on (SSO) / passkey enrollment portal.

Awareness takeaways

  • Treat urgent ‘same-day’ MFA/passkey enrollment calls as suspicious and verify using a known internal channel (don’t trust caller ID).
  • Don’t click login or enrollment links provided during unsolicited calls; navigate to the official company login portal yourself.
  • Watch for stealth signs after an account is accessed, like missing password-reset emails or missing MFA-change alerts, report immediately.
  • Flag unusually large, automated cloud file access as a potential account takeover, especially from scripting tools.

Red flags to watch for

  • Unsolicited urgent call to personal mobile phone about same-day security enrollment
  • Caller ID/number match is relied on as proof (spoofable)
  • Link goes to an odd subdomain/domain not the company’s normal login URL
  • Domain is not the legitimate corporate domain
  • Unexpected login prompts after a phone call
  • Any page that results in repeated login/MFA prompts (possible proxy-in-the-middle)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re at home, personal phone rings. Caller ID says it’s the company IT help desk, spoofed to look legit. The voice says, “We need your FIDO2 passkey or MFA updated today,” and texts you a link: yourcompany.createssopasskey.com. It looks like your SSO, but it’s an adversary-in-the-middle proxy stealing your password and live session token. Behind the scenes, scripts using agents like 'python-requests' and 'Windows PowerShell' start pulling data from Microsoft 365 and Okta, while password reset and MFA-change emails quietly disappear from your inbox. Aha to remember: if someone calls your personal phone about a same-day passkey or MFA update, hang up and contact IT through Teams, the helpdesk portal, or the number on our intranet, never through the number or link they just gave you.

Similar attacks

Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026
UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026
Helix Extortion Hit Uber Freight via Helpdesk Vishing

Helix Extortion Hit Uber Freight via Helpdesk Vishing

Uber Freight is investigating unauthorized access after the Helix extortion group claimed it stole nearly one million files from company cloud and email repositories. Google-linked research says the broader cluster (UNC6671) commonly gets in by calling employees and posing as IT helpdesk staff…

August 12, 2026
UNC6671 Rebrands, Runs IT Helpdesk Vishing

UNC6671 Rebrands, Runs IT Helpdesk Vishing

Google Threat Intelligence reports that extortion group UNC6671 (formerly branded “BlackFile”) is calling employees while posing as IT helpdesk staff and pushing “urgent security migrations.” Victims are lured to spoofed login pages to capture passwords and MFA tokens, enabling Microsoft 365/Okta…

August 7, 2026