UNC6671 Rebrands, Runs IT Helpdesk Vishing

Security Week Feed · High sophistication
Last updated August 7, 2026

Google Threat Intelligence reports that extortion group UNC6671 (formerly branded “BlackFile”) is calling employees while posing as IT helpdesk staff and pushing “urgent security migrations.” Victims are lured to spoofed login pages to capture passwords and MFA tokens, enabling Microsoft 365/Okta account takeover and follow-on extortion. The group has rebranded into multiple names (Redact, Pink, Helix, Falcon) and has collected more than $10M in Bitcoin in early 2026.

Key findings

  • UNC6671 uses tailored IT helpdesk phone calls to push “mandatory, urgent security migrations” and lure victims to spoofed login portals.
  • The actor targets Microsoft 365 and Okta and uses adversary-in-the-middle techniques to capture credentials and MFA tokens.
  • The group retired the “BlackFile” name and continues under multiple extortion brands: Redact, Pink, Helix, and Falcon.
  • Generic root domains (e.g., passkeyhelpdesk[.]com) and victim-name subdomains are used to host credential-harvesting panels.
  • Tactics have evolved to include spoofing legitimate helpdesk phone numbers and using compromised email accounts to reset passwords for non-SSO apps while deleting alerts.
  • GTIG tracked over $10M in Bitcoin payments (Jan–May) across 18 wallet addresses; initial demands often $1M–$3M, with negotiated reductions.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance and treasury teams, Private equity deal teams, Professional services client teams, IT helpdesk/service desk, Cloud administrators (Microsoft 365/Okta admins).
  • Affected industries: Financial services, Private equity, Professional services.
  • Attack channels: vishing, website, email.
  • Impersonated: Internal IT helpdesk employee, Helpdesk calling from a spoofed legitimate number.

Awareness takeaways

  • Train staff to treat unsolicited ‘urgent security migration’ calls as suspicious and verify via a known internal channel before taking action.
  • Teach users to never enter passwords or MFA codes into portals reached from a phone call; only sign in via known bookmarks/company app links.
  • Add user education on checking domains carefully (especially ‘passkey/helpdesk/portal’ lookalikes) and reporting them quickly.
  • Warn employees that caller ID can be faked; helpdesk numbers should not be treated as proof of legitimacy.

Red flags to watch for

  • Unsolicited urgent migration request via phone, often to a personal mobile
  • Login link goes to an unfamiliar domain (e.g., "passkeyhelpdesk[.]com") rather than the company’s normal SSO page
  • Pressure to provide or approve MFA quickly while on the phone
  • Caller ID matches helpdesk but the request is unexpected (caller-ID spoofing)
  • Missing or disappearing security notifications/confirmation emails
  • Requests to take action immediately while staying on the phone
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a call from “IT Helpdesk” on your mobile: urgent security migration, right now, or you’ll lose access. This is a UNC6671 vishing play: they pose as helpdesk, talk you through a 'mandatory migration,' and send you to a fake Microsoft 365 or Okta page like passkeyhelpdesk.com to steal your password and MFA code. They even spoof our helpdesk number and stay on the line, pressuring you to type your password and approve MFA while they intercept it in the middle and take over accounts for extortion. Your move: if anyone calls about an 'urgent migration' or surprise password reset, hang up and contact IT using our official helpdesk portal or chat, never use the number or link they give you.

Similar attacks

Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026