Researchers reported a real campaign against large U.S. financial firms where callers pretend to be coworkers or IT to trick employees into entering passwords and multi-factor codes on spoofed websites. After access is gained, the attackers pressure victims with data-leak threats and demand large ransoms.
How the Attack Worked
This campaign combines a phone call with a fake website to steal login credentials and one-time codes. An attacker calls an employee pretending to be a coworker or internal IT staff member, claiming there is an urgent account or security issue that needs to be resolved. The caller directs the employee to a login page framed as a verification step. That page is spoofed to look legitimate, and once the employee enters their password and multi-factor authentication code, the attacker captures both and gains access to the account.
Why It Succeeded
The pretext relies on urgency and familiarity. Impersonating a coworker or IT staff lowers suspicion because these are people employees are used to trusting and cooperating with quickly, especially when told there is a security problem. Directing the target to a website rather than asking for information verbally also makes the request feel more procedural and less like a typical scam attempt, even though the destination is not an official company URL.
What Happens After Compromise
Once the attackers, tracked as UNC6671, obtain valid credentials and MFA codes, they use that access against large US financial firms and enterprise cloud environments. Victims are then threatened with data leaks, and the group has issued ransom demands ranging from $750,000 to $3 million. This turns a single successful phone call into a high-stakes extortion event rather than a simple account compromise.
What to Watch For
- An unsolicited call from someone claiming to be a coworker or IT staff, pushing urgent action on an account issue
- Being directed to a login page that is not a known or official company URL
- Any request to share or type an MFA code as part of "verification"
- Follow-up messages threatening data leaks or demanding payment after a login incident
Building Resistance
- Treat unexpected "IT" or "coworker" calls as suspicious, and verify the caller through a known internal number or official directory before taking any action
- Never enter credentials or MFA codes into a site reached from an unsolicited call; only use trusted bookmarks or your company's official portal
- Report extortion or data-leak threats immediately to Security or Legal rather than engaging directly
- Finance, treasury, IT helpdesk, cloud administrators, and executives should receive targeted awareness on this specific pretext, since they are the primary targets
This pattern reflects known adversary techniques for gathering victim information (T1598) and using accounts to further an extortion goal (T1656), and it underscores why credential and MFA code requests delivered through a phone call deserve the same scrutiny as a suspicious email.
Key findings
- Callers impersonate coworkers or IT staff to capture passwords and MFA codes.
- Victims are sent or directed to spoofed websites to collect credentials and authentication codes.
- After compromise, attackers threaten to leak data and issue ransom demands between $750,000 and $3 million.
- Campaign targets large U.S. financial firms and enterprise cloud environments; threat actor tracked as UNC6671.
Who’s being targeted
- Commonly targeted roles: Finance and treasury teams, Executives and executive assistants, IT helpdesk and identity teams, Cloud administrators, All employees (anti-impersonation and MFA safety).
- Affected industries: Financial services, Banking, Enterprise cloud environments.
- Attack channels: vishing, website.
- Impersonated: Coworker or Internal IT staff.
Red flags to watch for
- Unsolicited call pressuring immediate action for an account issue
- Being directed to a login page that is not a known/official company URL
- Request to share or type an MFA code as part of ‘verification’
Frequently asked questions
How does this attack trick employees?
Callers pose as coworkers or IT staff claiming an urgent account or security issue, then direct the employee to a spoofed login page to enter their password and MFA code.
What happens after credentials are stolen?
The attackers, tracked as UNC6671, use the access to threaten victims with data leaks and issue ransom demands ranging from $750,000 to $3 million.
Who is being targeted?
Large US financial firms are the primary target, with finance, treasury, IT helpdesk, cloud administrators, and executives most at risk.
What is the biggest red flag to watch for?
An unsolicited call pressuring immediate action and a request to enter a password or MFA code on a login page that is not a known company URL.
Read the video transcript
Imagine this: your phone rings, “Hi, this is IT, there’s a security issue with your account.” They say UNC6671-style: “Go to our verification page and confirm your login.” You land on a site that looks like our cloud portal, but the URL is slightly off, and they coach you to type your password and MFA code while they wait. Here’s the trap: the moment you do that, they own your account. In real cases against big US finance firms, the callers then threaten to leak data and demand between seven hundred fifty thousand and three million dollars. Your move: if an unexpected ‘IT’ or coworker call sends you to a login page, hang up and reach IT using the number in our official directory, never use the number or link they just gave you.