UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google Cloud Threat Intelligence · High sophistication
Last updated August 7, 2026

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion from cloud services like Microsoft 365 and Okta.

How the attack worked

UNC6671 runs a real-world vishing campaign where callers impersonate internal IT helpdesk staff and pressure employees with claims of an urgent, mandatory security migration. The pretext typically centers on enabling FIDO2 passkeys or updating multi-factor authentication enrollment. Employees are directed to a lookalike credential-harvesting subdomain designed to resemble a legitimate company login portal, such as domains using patterns like createssopasskey or addssopasskey. Once a victim signs in, adversary-in-the-middle infrastructure captures both the password and the MFA token in real time, giving the attacker a live, authenticated session.

Why it succeeded

Several factors make this pretext effective. Calls often arrive on an employee's personal mobile device rather than a work line, which can bypass expectations about how corporate IT normally communicates. In some cases the caller has spoofed the legitimate helpdesk phone number, adding a false sense of legitimacy to the interaction. The urgency framing, a mandatory security update that must happen now, discourages employees from pausing to verify the request through other channels. Because the scenario touches identity and access management directly, it also targets employees who are primed to treat MFA and passkey prompts as routine security hygiene rather than a potential threat.

What to watch for

  • Unsolicited calls claiming a mandatory, urgent security migration is required
  • A request to visit a web address that is not an official corporate domain, particularly one referencing passkeys, MFA, or SSO
  • Calls received on a personal mobile number rather than a work line
  • Pressure to act immediately without time to verify the request
  • Missing password reset confirmations or security alert emails, which attackers have deleted to avoid detection

How to build resistance

Organizations should train employees, including finance, executive, legal, and IT staff, to treat unexpected helpdesk calls as unverified until confirmed through a known internal number or directory, rather than any number or link provided during the call itself. Employees should be reminded to only use official company bookmarks or portals for MFA and passkey enrollment, never a link given over the phone. Because attackers have been observed deleting password-reset confirmations and security notifications to reduce detection, staff should also be encouraged to report any gaps in expected security alerts. Reinforcing these habits across all employee groups, not just IT and IAM administrators, helps reduce the chance that an urgent-sounding call leads to a compromised account.

Key findings

  • UNC6671 continues to run real-world vishing-led compromises, despite a claimed “retirement” of an extortion brand.
  • Callers impersonate IT helpdesk staff and pressure employees with urgent “mandatory” security migration instructions.
  • Victims are directed to spoofed login portals using adversary-in-the-middle (AiTM) tooling to capture credentials and MFA tokens.
  • The actor often calls employees on personal mobile phones and in some cases spoofs the legitimate helpdesk phone number.
  • Compromised email accounts are used to reset passwords and attackers delete security notifications to reduce detection.
  • Infrastructure shows reuse of “passkey/mfa/sso” themed domains across multiple extortion brands (Redact, Pink, Helix, Falcon, BlackFile).

Who’s being targeted

  • Commonly targeted roles: All employees, Finance teams, Executives, Legal teams, IT helpdesk/service desk, Identity & access management (IAM) administrators.
  • Affected industries: Financial services, Private equity, Professional services, Legal services, Manufacturing, Real estate, Healthcare, Insurance, Technology, Transportation, Hospitality.
  • Attack channels: vishing, website.
  • Impersonated: Internal IT Helpdesk.

Red flags to watch for

  • Unsolicited urgent call about a “mandatory” security migration
  • Request to use a web address that isn’t an official corporate domain (lookalike “passkey/mfa/sso” site)
  • Call comes to a personal mobile number and/or the caller pressures you to act immediately
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the UNC6671 vishing scam?

UNC6671 is a threat actor that calls employees pretending to be IT helpdesk staff, claiming an urgent mandatory security migration requires enabling passkeys or updating MFA enrollment, then directs victims to a spoofed login portal that steals credentials and MFA tokens.

How does UNC6671 make the calls seem legitimate?

The actor often calls employees on their personal mobile phones, and in some cases spoofs the legitimate helpdesk phone number to add credibility to the request.

What happens after credentials are stolen in this scam?

Adversary-in-the-middle infrastructure captures passwords and MFA tokens, allowing attackers to compromise email and cloud accounts, reset passwords, delete security alerts, and pursue data theft and extortion.

What are warning signs employees should watch for?

Red flags include unsolicited urgent calls about a mandatory security migration, requests to visit a non-official login web address, and pressure to act immediately, especially when the call arrives on a personal phone.

Read the video transcript

You get a call on your personal phone: “Hi, this is IT helpdesk, urgent mandatory security migration…” They say you must enable a new passkey now, then send you to a fake login like company.createssopasskey.com that looks just like Microsoft 365 or Okta. This is UNC6671 vishing: they grab your password and MFA code, log in as you, reset things, and quietly delete the security emails so you never see alerts. If IT ever calls you unexpectedly about passkeys or MFA, hang up and call the helpdesk back using the number in our internal directory.

Similar attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay codes in real time, SIM swapping, and stealing session cookies so MFA isn’t needed again. It also cites known incidents (e.g., Uber 2022 MFA…

July 29, 2026
“Work Panel” Streamlines Vishing Into One Console

“Work Panel” Streamlines Vishing Into One Console

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites and guide victims through password and MFA capture. The tool clones brand look-and-feel for services like Okta and Microsoft 365, then lets a…

July 29, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026
Hotel Wi‑Fi DNS Scam Steals Microsoft 365 Logins

Hotel Wi‑Fi DNS Scam Steals Microsoft 365 Logins

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in pages. Victims are then tricked into completing a device-code login that grants attackers a legitimate session token, often bypassing MFA. This…

July 28, 2026
Voicemail Lure Drives Microsoft Device-Code Phish

Voicemail Lure Drives Microsoft Device-Code Phish

A voicemail-themed phishing campaign (“Kali365 Ringer”) targeted financial and insurance organizations using a missed-call notification and a Google Sites page to appear legitimate. Victims were redirected through multiple trusted services and instructed to approve a Microsoft device-code login…

July 27, 2026