Redact Rebrand Uses IT Helpdesk Vishing

Infosecurity Magazine · High sophistication
Last updated August 7, 2026

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to access cloud accounts like Microsoft 365 and Okta and then exfiltrate data for extortion.

Key findings

  • BlackFile (UNC6671) reportedly rebranded to “Redact,” while related branding also included Pink, Helix, and Falcon.
  • The group’s main initial-access method is vishing that impersonates IT helpdesk staff and pressures users into urgent security changes.
  • Victims are sent to spoofed login portals using Adversary-in-the-Middle (AiTM) infrastructure to capture credentials and MFA tokens.
  • GTIG linked multiple brands due to reused infrastructure and phishing templates, including root domains passkeyhelpdesk[.]com and passkeydeploy[.]com.
  • Newly observed tactics include spoofing a legitimate helpdesk phone number and using compromised email accounts to reset passwords and delete security alerts.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Legal, IT helpdesk/service desk, Identity and access management (IAM) teams.
  • Affected industries: Manufacturing, Real estate, Healthcare, Insurance, Technology, Transportation, Hospitality, Financial services, Legal services, Private equity, Credit rating agencies.
  • Attack channels: vishing, website.
  • Impersonated: IT helpdesk staff (internal help desk), Legitimate helpdesk (spoofed phone number).

Awareness takeaways

  • Treat unexpected ‘IT helpdesk’ security migration calls as suspicious, verify using an official internal directory or ticketing system before doing anything.
  • Never sign in from a link/domain provided during a phone call; navigate to known corporate URLs instead.
  • Be extra cautious when calls or authentication prompts involve personal devices, attackers deliberately target them.
  • If you suspect account compromise, report immediately, attackers may delete security notifications to hide their activity.

Red flags to watch for

  • Unsolicited urgent call pressuring immediate security changes
  • Employee is directed to a lookalike/spoofed login portal
  • Call targets a personal device rather than corporate channels
  • Caller ID shows a familiar helpdesk number but the request is unusual/urgent
  • Pushes the user to act immediately rather than follow normal IT change process
  • Requests actions on personal devices
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a call from “IT Helpdesk” on your personal phone: urgent passkey migration, must do it now. This is the Redact crew, formerly BlackFile. They pose as helpdesk, then walk you to sites like passkeyhelpdesk.com to ‘enable FIDO2 passkeys’ while their Adversary-in-the-Middle system steals your password and MFA code. Here’s the twist: they may spoof our real helpdesk number and target your personal phone, then rush you so you don’t notice the weird URL or that this didn’t come through our normal ticketing tools. If anyone calls about urgent passkey or MFA changes, hang up and contact IT yourself using our directory or ticketing system, never use the number or link they just gave you.

Similar attacks

Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026
UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026
Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
UNC6671 Rebrands, Runs IT Helpdesk Vishing

UNC6671 Rebrands, Runs IT Helpdesk Vishing

Google Threat Intelligence reports that extortion group UNC6671 (formerly branded “BlackFile”) is calling employees while posing as IT helpdesk staff and pushing “urgent security migrations.” Victims are lured to spoofed login pages to capture passwords and MFA tokens, enabling Microsoft 365/Okta…

August 7, 2026