BlackFile Vishing Poses as IT Support to Extort Firms

CyberScoop · Medium sophistication
Last updated August 18, 2026

Researchers say the BlackFile extortion group is actively targeting large financial and other organizations using voice-phishing calls where attackers impersonate IT support to get initial access. Victims are then pressured with multimillion-dollar extortion demands and, in some cases, escalations like threatening messages and swatting.

How the Attack Worked

BlackFile, tracked by Google as UNC6671, gains initial access to victim organizations through voice phishing calls rather than email. Callers impersonate internal IT support, telling employees they are calling to help resolve an access or login issue. The caller then walks the victim through steps that end up granting the attacker access to internal systems. According to reporting, the group uses hundreds of callers to run these calls at scale, and its operations are split across four brands, Redact, Pink, Helix and Falcon, that share infrastructure.

Why It Succeeded

The pretext works because it exploits a routine, expected interaction, an employee having a login or access problem and receiving what looks like helpful support. There is no malicious link or attachment to inspect, just a phone call that sounds legitimate and creates urgency to resolve an access issue quickly. Voice-based social engineering for data theft extortion is not new or technically sophisticated, but it continues to prove effective against large organizations, described as "big-game hunting" targets, because it bypasses email-focused security controls and relies on human trust in a phone call.

What to Watch For

  • An unsolicited phone call from someone claiming to be internal IT support
  • Pressure to act quickly to avoid losing account access
  • A request to make account or security changes without an existing support ticket or independent verification
  • Any follow-up contact involving extortion demands, threatening messages, or escalation beyond the digital environment

Mandiant has reported being engaged by more than two dozen organizations that were successfully compromised through this technique since January, and affected sectors reportedly include financial services, private equity, legal services, financial ratings, healthcare technology, technology, transportation, logistics, wholesale, retail and hospitality.

Building Resistance

Organizations can reduce risk from this type of vishing by training all employees, not just IT staff, to treat unsolicited "IT support" calls with the same suspicion as unexpected emails. Any request to change access, share credentials, or perform remote actions should be verified through a known internal channel, such as a ticketing system or a callback to a verified number, before anything is done. Because initial access can arrive by phone rather than email, awareness training should explicitly cover voice-based social engineering. Finally, organizations should prepare incident response and communication plans for extortion scenarios, including the possibility that threats may escalate into physical-world incidents like swatting, so that staff know exactly how and where to report such threats immediately.

Key findings

  • BlackFile (tracked by Google as UNC6671) remains active and continued targeting new victims as of late last week.
  • The group uses voice phishing and social engineering by impersonating IT support to obtain initial access.
  • Operations are split across four brands, Redact, Pink, Helix and Falcon, using shared infrastructure.
  • The group focuses on large organizations (“big-game hunting”) and extortion demands often start around $3 million, commonly negotiated below $1 million.
  • Some victims have faced escalation tactics including threatening messages and swatting incidents.
  • Mandiant has been engaged by more than two dozen organizations successfully compromised since January.

Who’s being targeted

  • Commonly targeted roles: All employees, IT Service Desk, Finance, Executive leadership, Security/Incident Response.
  • Affected industries: Financial services, Private equity, Legal services, Financial ratings, Healthcare (med tech), Technology, Transportation, Logistics, Wholesale, Retail, Hospitality.
  • Attack channels: vishing.
  • Impersonated: IT support / Helpdesk.

Red flags to watch for

  • Unsolicited phone call claiming to be internal IT support
  • Pressure to act quickly to avoid losing access
  • Request to perform account/security changes without a ticket or verification
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is BlackFile and how does it operate?

BlackFile, tracked by Google as UNC6671, is an extortion group that uses voice phishing calls impersonating IT support to gain initial access to large organizations. It operates under four brands, Redact, Pink, Helix and Falcon, that share infrastructure.

How does the BlackFile IT support scam work?

Attackers call employees claiming to be internal IT support offering to fix an access or login issue, then guide the victim through steps that grant the attacker initial access to systems.

What happens after BlackFile gains access?

Victims face extortion demands often starting around $3 million, which are commonly negotiated down below $1 million, and some victims have experienced escalation tactics including threatening messages and swatting incidents.

Which industries has BlackFile targeted?

Reported affected sectors include financial services, private equity, legal services, financial ratings, healthcare technology, technology, transportation, logistics, wholesale, retail and hospitality.

Read the video transcript

Imagine picking up the phone, helping “IT,” and that call turns into a three‑million‑dollar problem. Groups like BlackFile, tracked as UNC6671, use vishing, voice phishing. You hear, “Hi, this is IT support, I’m calling to help resolve an access issue on your account,” then they walk you through steps that quietly give them access. Here’s the tell: it’s an unsolicited “IT” call, urgent about losing access, and they want you to change settings or share info without a ticket. That’s how BlackFile got into dozens of firms and pushed multimillion‑dollar extortion, even threats and swatting. Your move is simple: if “IT support” calls you out of the blue, hang up and call your real helpdesk using the number in the company directory before you do anything.

Similar attacks

Wall Street Hit by Help Desk Impersonation Calls

Wall Street Hit by Help Desk Impersonation Calls

A real campaign of voice-phishing (vishing) calls targeted major hedge funds and private equity firms by impersonating internal IT/help desk staff. Victims were pressured into completing “routine” security steps and were sent to fake login pages that captured usernames, passwords, and MFA codes in…

August 20, 2026
Fake IT Help Desk Calls Hit Private Equity

Fake IT Help Desk Calls Hit Private Equity

Researchers say a threat group tracked as UNC6671 is calling employees and posing as IT help desk staff to steal login credentials and multi-factor authentication (MFA) tokens. After gaining access, the attackers reportedly exfiltrate large amounts of corporate data and then issue extortion…

August 11, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
Apollo Breach Tied to IT Support Impersonation

Apollo Breach Tied to IT Support Impersonation

Apollo Global Management disclosed a data breach after attackers used social engineering to gain unauthorized access to certain cloud platforms over several days in July. The attackers obtained sensitive personal data (including Social Security numbers), highlighting how stolen credentials and…

August 25, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026