BlackFile Vishing Poses as IT Support to Extort Firms

CyberScoop · Medium sophistication
Last updated August 18, 2026

Researchers say the BlackFile extortion group is actively targeting large financial and other organizations using voice-phishing calls where attackers impersonate IT support to get initial access. Victims are then pressured with multimillion-dollar extortion demands and, in some cases, escalations like threatening messages and swatting.

How the Attack Worked

BlackFile, tracked by Google as UNC6671, gains initial access to victim organizations through voice phishing calls rather than email. Callers impersonate internal IT support, telling employees they are calling to help resolve an access or login issue. The caller then walks the victim through steps that end up granting the attacker access to internal systems. According to reporting, the group uses hundreds of callers to run these calls at scale, and its operations are split across four brands, Redact, Pink, Helix and Falcon, that share infrastructure.

Why It Succeeded

The pretext works because it exploits a routine, expected interaction, an employee having a login or access problem and receiving what looks like helpful support. There is no malicious link or attachment to inspect, just a phone call that sounds legitimate and creates urgency to resolve an access issue quickly. Voice-based social engineering for data theft extortion is not new or technically sophisticated, but it continues to prove effective against large organizations, described as "big-game hunting" targets, because it bypasses email-focused security controls and relies on human trust in a phone call.

What to Watch For

  • An unsolicited phone call from someone claiming to be internal IT support
  • Pressure to act quickly to avoid losing account access
  • A request to make account or security changes without an existing support ticket or independent verification
  • Any follow-up contact involving extortion demands, threatening messages, or escalation beyond the digital environment

Mandiant has reported being engaged by more than two dozen organizations that were successfully compromised through this technique since January, and affected sectors reportedly include financial services, private equity, legal services, financial ratings, healthcare technology, technology, transportation, logistics, wholesale, retail and hospitality.

Building Resistance

Organizations can reduce risk from this type of vishing by training all employees, not just IT staff, to treat unsolicited "IT support" calls with the same suspicion as unexpected emails. Any request to change access, share credentials, or perform remote actions should be verified through a known internal channel, such as a ticketing system or a callback to a verified number, before anything is done. Because initial access can arrive by phone rather than email, awareness training should explicitly cover voice-based social engineering. Finally, organizations should prepare incident response and communication plans for extortion scenarios, including the possibility that threats may escalate into physical-world incidents like swatting, so that staff know exactly how and where to report such threats immediately.

Key findings

  • BlackFile (tracked by Google as UNC6671) remains active and continued targeting new victims as of late last week.
  • The group uses voice phishing and social engineering by impersonating IT support to obtain initial access.
  • Operations are split across four brands, Redact, Pink, Helix and Falcon, using shared infrastructure.
  • The group focuses on large organizations (“big-game hunting”) and extortion demands often start around $3 million, commonly negotiated below $1 million.
  • Some victims have faced escalation tactics including threatening messages and swatting incidents.
  • Mandiant has been engaged by more than two dozen organizations successfully compromised since January.

Who’s being targeted

  • Commonly targeted roles: All employees, IT Service Desk, Finance, Executive leadership, Security/Incident Response.
  • Affected industries: Financial services, Private equity, Legal services, Financial ratings, Healthcare (med tech), Technology, Transportation, Logistics, Wholesale, Retail, Hospitality.
  • Attack channels: vishing.
  • Impersonated: IT support / Helpdesk.

Red flags to watch for

  • Unsolicited phone call claiming to be internal IT support
  • Pressure to act quickly to avoid losing access
  • Request to perform account/security changes without a ticket or verification
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is BlackFile and how does it operate?

BlackFile, tracked by Google as UNC6671, is an extortion group that uses voice phishing calls impersonating IT support to gain initial access to large organizations. It operates under four brands, Redact, Pink, Helix and Falcon, that share infrastructure.

How does the BlackFile IT support scam work?

Attackers call employees claiming to be internal IT support offering to fix an access or login issue, then guide the victim through steps that grant the attacker initial access to systems.

What happens after BlackFile gains access?

Victims face extortion demands often starting around $3 million, which are commonly negotiated down below $1 million, and some victims have experienced escalation tactics including threatening messages and swatting incidents.

Which industries has BlackFile targeted?

Reported affected sectors include financial services, private equity, legal services, financial ratings, healthcare technology, technology, transportation, logistics, wholesale, retail and hospitality.

Read the video transcript

Imagine picking up the phone, helping “IT,” and that call turns into a three‑million‑dollar problem. Groups like BlackFile, tracked as UNC6671, use vishing, voice phishing. You hear, “Hi, this is IT support, I’m calling to help resolve an access issue on your account,” then they walk you through steps that quietly give them access. Here’s the tell: it’s an unsolicited “IT” call, urgent about losing access, and they want you to change settings or share info without a ticket. That’s how BlackFile got into dozens of firms and pushed multimillion‑dollar extortion, even threats and swatting. Your move is simple: if “IT support” calls you out of the blue, hang up and call your real helpdesk using the number in the company directory before you do anything.

Similar attacks

Fake IT Help Desk Calls Hit Private Equity

Fake IT Help Desk Calls Hit Private Equity

Researchers say a threat group tracked as UNC6671 is calling employees and posing as IT help desk staff to steal login credentials and multi-factor authentication (MFA) tokens. After gaining access, the attackers reportedly exfiltrate large amounts of corporate data and then issue extortion…

August 11, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026
Fake Bank Calls Trick Victims Into NFC Card Fraud

Fake Bank Calls Trick Victims Into NFC Card Fraud

Researchers described a real scam where criminals called victims pretending to be bank support and convinced them to install a “legitimate” Android app. The app was actually SpyNote malware, giving the attacker remote control of the phone, after which a second tool (WindRelay) was used to relay…

August 14, 2026
Levi’s Breach Started With IT Helpdesk Impersonation

Levi’s Breach Started With IT Helpdesk Impersonation

Levi Strauss reported that an unauthorized party used social-engineering to compromise three employees’ company-issued computers and steal corporate data. Reporting tied the incident to a wider campaign where attackers impersonated IT help desks using spoofed phone numbers and fraudulent websites…

August 10, 2026