Redact Rebrand Uses IT Helpdesk Vishing

Infosecurity Magazine · High sophistication
Last updated August 7, 2026

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to access cloud accounts like Microsoft 365 and Okta and then exfiltrate data for extortion.

Key findings

  • BlackFile (UNC6671) reportedly rebranded to “Redact,” while related branding also included Pink, Helix, and Falcon.
  • The group’s main initial-access method is vishing that impersonates IT helpdesk staff and pressures users into urgent security changes.
  • Victims are sent to spoofed login portals using Adversary-in-the-Middle (AiTM) infrastructure to capture credentials and MFA tokens.
  • GTIG linked multiple brands due to reused infrastructure and phishing templates, including root domains passkeyhelpdesk[.]com and passkeydeploy[.]com.
  • Newly observed tactics include spoofing a legitimate helpdesk phone number and using compromised email accounts to reset passwords and delete security alerts.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Legal, IT helpdesk/service desk, Identity and access management (IAM) teams.
  • Affected industries: Manufacturing, Real estate, Healthcare, Insurance, Technology, Transportation, Hospitality, Financial services, Legal services, Private equity, Credit rating agencies.
  • Attack channels: vishing, website.
  • Impersonated: IT helpdesk staff (internal help desk), Legitimate helpdesk (spoofed phone number).

Awareness takeaways

  • Treat unexpected ‘IT helpdesk’ security migration calls as suspicious, verify using an official internal directory or ticketing system before doing anything.
  • Never sign in from a link/domain provided during a phone call; navigate to known corporate URLs instead.
  • Be extra cautious when calls or authentication prompts involve personal devices, attackers deliberately target them.
  • If you suspect account compromise, report immediately, attackers may delete security notifications to hide their activity.

Red flags to watch for

  • Unsolicited urgent call pressuring immediate security changes
  • Employee is directed to a lookalike/spoofed login portal
  • Call targets a personal device rather than corporate channels
  • Caller ID shows a familiar helpdesk number but the request is unusual/urgent
  • Pushes the user to act immediately rather than follow normal IT change process
  • Requests actions on personal devices
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a call from “IT Helpdesk” on your personal phone: urgent passkey migration, must do it now. This is the Redact crew, formerly BlackFile. They pose as helpdesk, then walk you to sites like passkeyhelpdesk.com to ‘enable FIDO2 passkeys’ while their Adversary-in-the-Middle system steals your password and MFA code. Here’s the twist: they may spoof our real helpdesk number and target your personal phone, then rush you so you don’t notice the weird URL or that this didn’t come through our normal ticketing tools. If anyone calls about urgent passkey or MFA changes, hang up and contact IT yourself using our directory or ticketing system, never use the number or link they just gave you.

Similar attacks

Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
Helix Extortion Hit Uber Freight via Helpdesk Vishing

Helix Extortion Hit Uber Freight via Helpdesk Vishing

Uber Freight is investigating unauthorized access after the Helix extortion group claimed it stole nearly one million files from company cloud and email repositories. Google-linked research says the broader cluster (UNC6671) commonly gets in by calling employees and posing as IT helpdesk staff…

August 12, 2026
BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026
UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026