Researchers say the BlackFile extortion group is actively targeting large financial and other organizations using voice-phishing calls where attackers impersonate IT support to get initial access. Victims are then pressured with multimillion-dollar extortion demands and, in some cases, escalations like threatening messages and swatting.
How the Attack Worked
BlackFile, tracked by Google as UNC6671, gains initial access to victim organizations through voice phishing calls rather than email. Callers impersonate internal IT support, telling employees they are calling to help resolve an access or login issue. The caller then walks the victim through steps that end up granting the attacker access to internal systems. According to reporting, the group uses hundreds of callers to run these calls at scale, and its operations are split across four brands, Redact, Pink, Helix and Falcon, that share infrastructure.
Why It Succeeded
The pretext works because it exploits a routine, expected interaction, an employee having a login or access problem and receiving what looks like helpful support. There is no malicious link or attachment to inspect, just a phone call that sounds legitimate and creates urgency to resolve an access issue quickly. Voice-based social engineering for data theft extortion is not new or technically sophisticated, but it continues to prove effective against large organizations, described as "big-game hunting" targets, because it bypasses email-focused security controls and relies on human trust in a phone call.
What to Watch For
- An unsolicited phone call from someone claiming to be internal IT support
- Pressure to act quickly to avoid losing account access
- A request to make account or security changes without an existing support ticket or independent verification
- Any follow-up contact involving extortion demands, threatening messages, or escalation beyond the digital environment
Mandiant has reported being engaged by more than two dozen organizations that were successfully compromised through this technique since January, and affected sectors reportedly include financial services, private equity, legal services, financial ratings, healthcare technology, technology, transportation, logistics, wholesale, retail and hospitality.
Building Resistance
Organizations can reduce risk from this type of vishing by training all employees, not just IT staff, to treat unsolicited "IT support" calls with the same suspicion as unexpected emails. Any request to change access, share credentials, or perform remote actions should be verified through a known internal channel, such as a ticketing system or a callback to a verified number, before anything is done. Because initial access can arrive by phone rather than email, awareness training should explicitly cover voice-based social engineering. Finally, organizations should prepare incident response and communication plans for extortion scenarios, including the possibility that threats may escalate into physical-world incidents like swatting, so that staff know exactly how and where to report such threats immediately.
Key findings
- BlackFile (tracked by Google as UNC6671) remains active and continued targeting new victims as of late last week.
- The group uses voice phishing and social engineering by impersonating IT support to obtain initial access.
- Operations are split across four brands, Redact, Pink, Helix and Falcon, using shared infrastructure.
- The group focuses on large organizations (“big-game hunting”) and extortion demands often start around $3 million, commonly negotiated below $1 million.
- Some victims have faced escalation tactics including threatening messages and swatting incidents.
- Mandiant has been engaged by more than two dozen organizations successfully compromised since January.
Who’s being targeted
- Commonly targeted roles: All employees, IT Service Desk, Finance, Executive leadership, Security/Incident Response.
- Affected industries: Financial services, Private equity, Legal services, Financial ratings, Healthcare (med tech), Technology, Transportation, Logistics, Wholesale, Retail, Hospitality.
- Attack channels: vishing.
- Impersonated: IT support / Helpdesk.
Red flags to watch for
- Unsolicited phone call claiming to be internal IT support
- Pressure to act quickly to avoid losing access
- Request to perform account/security changes without a ticket or verification
Frequently asked questions
What is BlackFile and how does it operate?
BlackFile, tracked by Google as UNC6671, is an extortion group that uses voice phishing calls impersonating IT support to gain initial access to large organizations. It operates under four brands, Redact, Pink, Helix and Falcon, that share infrastructure.
How does the BlackFile IT support scam work?
Attackers call employees claiming to be internal IT support offering to fix an access or login issue, then guide the victim through steps that grant the attacker initial access to systems.
What happens after BlackFile gains access?
Victims face extortion demands often starting around $3 million, which are commonly negotiated down below $1 million, and some victims have experienced escalation tactics including threatening messages and swatting incidents.
Which industries has BlackFile targeted?
Reported affected sectors include financial services, private equity, legal services, financial ratings, healthcare technology, technology, transportation, logistics, wholesale, retail and hospitality.
Read the video transcript
Imagine picking up the phone, helping “IT,” and that call turns into a three‑million‑dollar problem. Groups like BlackFile, tracked as UNC6671, use vishing, voice phishing. You hear, “Hi, this is IT support, I’m calling to help resolve an access issue on your account,” then they walk you through steps that quietly give them access. Here’s the tell: it’s an unsolicited “IT” call, urgent about losing access, and they want you to change settings or share info without a ticket. That’s how BlackFile got into dozens of firms and pushed multimillion‑dollar extortion, even threats and swatting. Your move is simple: if “IT support” calls you out of the blue, hang up and call your real helpdesk using the number in the company directory before you do anything.