Researchers say a threat group tracked as UNC6671 is calling employees and posing as IT help desk staff to steal login credentials and multi-factor authentication (MFA) tokens. After gaining access, the attackers reportedly exfiltrate large amounts of corporate data and then issue extortion demands, with recent targeting focused on private equity and related firms.
Key findings
- Threat cluster UNC6671 is linked to a wave of extortion attacks against private equity, financial-ratings agencies and law firms.
- Attackers pose as IT help desk staff and call employees on mobile phones to trick them into an adversary-in-the-middle setup that steals credentials and MFA tokens.
- After initial access, the attackers use automated scripts to exfiltrate large corporate data repositories and then demand payment.
- Researchers say former BlackFile affiliates likely rebranded under extortion front names including Helix, Redact, Pink and Falcon.
- GTIG observed initial ransom demands commonly in the $1M–$3M range, with discounts during negotiation.
Who’s being targeted
- Commonly targeted roles: All employees (especially mobile users), Executives, Finance, Legal, IT help desk / Service desk, M&A / Deal teams.
- Affected industries: Private equity, Financial services, Financial ratings agencies, Legal services (law firms), Manufacturing, Insurance, Real estate, Healthcare, Hospitality, Technology, Transportation.
- Attack channels: vishing, website.
- Impersonated: IT help desk worker.
Awareness takeaways
- Treat unsolicited ‘IT help desk’ phone calls as suspicious and verify via your official internal support channel before doing anything.
- Never enter your credentials or approve MFA prompts/tokens as part of a call-driven ‘support’ workflow unless you initiated the request through a trusted method.
- Assume stolen logins can quickly turn into data theft and extortion; escalate suspicious calls immediately so security can contain access fast.
Red flags to watch for
- Unsolicited IT help desk call to a personal/mobile device
- Pressure to complete an unexpected login flow immediately
- Being routed to a login experience that is not a known corporate URL/process
Read the video transcript
You get a call on your personal cell: “Hi, this is the IT help desk, I’m calling to help you with your account access.” Groups like UNC6671 use these voice-phishing calls to walk you through a fake login website, steal your password and even your MFA code, then script a massive data grab and hit the firm with million‑dollar extortion demands. Their script is simple: call your mobile, claim there’s an urgent access issue, rush you into a login flow that isn’t our normal URL, and have you type your credentials and approve MFA while you’re still on the call. If anyone claiming to be IT calls you out of the blue, hang up and contact the help desk through our official channel yourself, that one move shuts this whole scam down.