Fake IT Help Desk Calls Hit Private Equity

Cybersecurity Dive · High sophistication
Last updated August 11, 2026

Researchers say a threat group tracked as UNC6671 is calling employees and posing as IT help desk staff to steal login credentials and multi-factor authentication (MFA) tokens. After gaining access, the attackers reportedly exfiltrate large amounts of corporate data and then issue extortion demands, with recent targeting focused on private equity and related firms.

Key findings

  • Threat cluster UNC6671 is linked to a wave of extortion attacks against private equity, financial-ratings agencies and law firms.
  • Attackers pose as IT help desk staff and call employees on mobile phones to trick them into an adversary-in-the-middle setup that steals credentials and MFA tokens.
  • After initial access, the attackers use automated scripts to exfiltrate large corporate data repositories and then demand payment.
  • Researchers say former BlackFile affiliates likely rebranded under extortion front names including Helix, Redact, Pink and Falcon.
  • GTIG observed initial ransom demands commonly in the $1M–$3M range, with discounts during negotiation.

Who’s being targeted

  • Commonly targeted roles: All employees (especially mobile users), Executives, Finance, Legal, IT help desk / Service desk, M&A / Deal teams.
  • Affected industries: Private equity, Financial services, Financial ratings agencies, Legal services (law firms), Manufacturing, Insurance, Real estate, Healthcare, Hospitality, Technology, Transportation.
  • Attack channels: vishing, website.
  • Impersonated: IT help desk worker.

Awareness takeaways

  • Treat unsolicited ‘IT help desk’ phone calls as suspicious and verify via your official internal support channel before doing anything.
  • Never enter your credentials or approve MFA prompts/tokens as part of a call-driven ‘support’ workflow unless you initiated the request through a trusted method.
  • Assume stolen logins can quickly turn into data theft and extortion; escalate suspicious calls immediately so security can contain access fast.

Red flags to watch for

  • Unsolicited IT help desk call to a personal/mobile device
  • Pressure to complete an unexpected login flow immediately
  • Being routed to a login experience that is not a known corporate URL/process
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a call on your personal cell: “Hi, this is the IT help desk, I’m calling to help you with your account access.” Groups like UNC6671 use these voice-phishing calls to walk you through a fake login website, steal your password and even your MFA code, then script a massive data grab and hit the firm with million‑dollar extortion demands. Their script is simple: call your mobile, claim there’s an urgent access issue, rush you into a login flow that isn’t our normal URL, and have you type your credentials and approve MFA while you’re still on the call. If anyone claiming to be IT calls you out of the blue, hang up and contact the help desk through our official channel yourself, that one move shuts this whole scam down.

Similar attacks

Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
UNC6671 Rebrands, Runs IT Helpdesk Vishing

UNC6671 Rebrands, Runs IT Helpdesk Vishing

Google Threat Intelligence reports that extortion group UNC6671 (formerly branded “BlackFile”) is calling employees while posing as IT helpdesk staff and pushing “urgent security migrations.” Victims are lured to spoofed login pages to capture passwords and MFA tokens, enabling Microsoft 365/Okta…

August 7, 2026
Helix Extortion Hit Uber Freight via Helpdesk Vishing

Helix Extortion Hit Uber Freight via Helpdesk Vishing

Uber Freight is investigating unauthorized access after the Helix extortion group claimed it stole nearly one million files from company cloud and email repositories. Google-linked research says the broader cluster (UNC6671) commonly gets in by calling employees and posing as IT helpdesk staff…

August 12, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
Levi’s Breach Started With IT Helpdesk Impersonation

Levi’s Breach Started With IT Helpdesk Impersonation

Levi Strauss reported that an unauthorized party used social-engineering to compromise three employees’ company-issued computers and steal corporate data. Reporting tied the incident to a wider campaign where attackers impersonated IT help desks using spoofed phone numbers and fraudulent websites…

August 10, 2026
UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026