Impostor Calls Target US Finance With Spoof Sites

Check Point Research · Medium sophistication
Last updated August 11, 2026

Researchers reported a real campaign against large U.S. financial firms where callers pretend to be coworkers or IT to trick employees into entering passwords and multi-factor codes on spoofed websites. After access is gained, the attackers pressure victims with data-leak threats and demand large ransoms.

How the Attack Worked

This campaign combines a phone call with a fake website to steal login credentials and one-time codes. An attacker calls an employee pretending to be a coworker or internal IT staff member, claiming there is an urgent account or security issue that needs to be resolved. The caller directs the employee to a login page framed as a verification step. That page is spoofed to look legitimate, and once the employee enters their password and multi-factor authentication code, the attacker captures both and gains access to the account.

Why It Succeeded

The pretext relies on urgency and familiarity. Impersonating a coworker or IT staff lowers suspicion because these are people employees are used to trusting and cooperating with quickly, especially when told there is a security problem. Directing the target to a website rather than asking for information verbally also makes the request feel more procedural and less like a typical scam attempt, even though the destination is not an official company URL.

What Happens After Compromise

Once the attackers, tracked as UNC6671, obtain valid credentials and MFA codes, they use that access against large US financial firms and enterprise cloud environments. Victims are then threatened with data leaks, and the group has issued ransom demands ranging from $750,000 to $3 million. This turns a single successful phone call into a high-stakes extortion event rather than a simple account compromise.

What to Watch For

  • An unsolicited call from someone claiming to be a coworker or IT staff, pushing urgent action on an account issue
  • Being directed to a login page that is not a known or official company URL
  • Any request to share or type an MFA code as part of "verification"
  • Follow-up messages threatening data leaks or demanding payment after a login incident

Building Resistance

  • Treat unexpected "IT" or "coworker" calls as suspicious, and verify the caller through a known internal number or official directory before taking any action
  • Never enter credentials or MFA codes into a site reached from an unsolicited call; only use trusted bookmarks or your company's official portal
  • Report extortion or data-leak threats immediately to Security or Legal rather than engaging directly
  • Finance, treasury, IT helpdesk, cloud administrators, and executives should receive targeted awareness on this specific pretext, since they are the primary targets

This pattern reflects known adversary techniques for gathering victim information (T1598) and using accounts to further an extortion goal (T1656), and it underscores why credential and MFA code requests delivered through a phone call deserve the same scrutiny as a suspicious email.

Key findings

  • Callers impersonate coworkers or IT staff to capture passwords and MFA codes.
  • Victims are sent or directed to spoofed websites to collect credentials and authentication codes.
  • After compromise, attackers threaten to leak data and issue ransom demands between $750,000 and $3 million.
  • Campaign targets large U.S. financial firms and enterprise cloud environments; threat actor tracked as UNC6671.

Who’s being targeted

  • Commonly targeted roles: Finance and treasury teams, Executives and executive assistants, IT helpdesk and identity teams, Cloud administrators, All employees (anti-impersonation and MFA safety).
  • Affected industries: Financial services, Banking, Enterprise cloud environments.
  • Attack channels: vishing, website.
  • Impersonated: Coworker or Internal IT staff.

Red flags to watch for

  • Unsolicited call pressuring immediate action for an account issue
  • Being directed to a login page that is not a known/official company URL
  • Request to share or type an MFA code as part of ‘verification’
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does this attack trick employees?

Callers pose as coworkers or IT staff claiming an urgent account or security issue, then direct the employee to a spoofed login page to enter their password and MFA code.

What happens after credentials are stolen?

The attackers, tracked as UNC6671, use the access to threaten victims with data leaks and issue ransom demands ranging from $750,000 to $3 million.

Who is being targeted?

Large US financial firms are the primary target, with finance, treasury, IT helpdesk, cloud administrators, and executives most at risk.

What is the biggest red flag to watch for?

An unsolicited call pressuring immediate action and a request to enter a password or MFA code on a login page that is not a known company URL.

Read the video transcript

Imagine this: your phone rings, “Hi, this is IT, there’s a security issue with your account.” They say UNC6671-style: “Go to our verification page and confirm your login.” You land on a site that looks like our cloud portal, but the URL is slightly off, and they coach you to type your password and MFA code while they wait. Here’s the trap: the moment you do that, they own your account. In real cases against big US finance firms, the callers then threaten to leak data and demand between seven hundred fifty thousand and three million dollars. Your move: if an unexpected ‘IT’ or coworker call sends you to a login page, hang up and reach IT using the number in our official directory, never use the number or link they just gave you.

Similar attacks

Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
UNC6671 Rebrands, Runs IT Helpdesk Vishing

UNC6671 Rebrands, Runs IT Helpdesk Vishing

Google Threat Intelligence reports that extortion group UNC6671 (formerly branded “BlackFile”) is calling employees while posing as IT helpdesk staff and pushing “urgent security migrations.” Victims are lured to spoofed login pages to capture passwords and MFA tokens, enabling Microsoft 365/Okta…

August 7, 2026
UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026
UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026