UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google Cloud Threat Intelligence · High sophistication
Last updated August 7, 2026

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion from cloud services like Microsoft 365 and Okta.

How the attack worked

UNC6671 runs a real-world vishing campaign where callers impersonate internal IT helpdesk staff and pressure employees with claims of an urgent, mandatory security migration. The pretext typically centers on enabling FIDO2 passkeys or updating multi-factor authentication enrollment. Employees are directed to a lookalike credential-harvesting subdomain designed to resemble a legitimate company login portal, such as domains using patterns like createssopasskey or addssopasskey. Once a victim signs in, adversary-in-the-middle infrastructure captures both the password and the MFA token in real time, giving the attacker a live, authenticated session.

Why it succeeded

Several factors make this pretext effective. Calls often arrive on an employee's personal mobile device rather than a work line, which can bypass expectations about how corporate IT normally communicates. In some cases the caller has spoofed the legitimate helpdesk phone number, adding a false sense of legitimacy to the interaction. The urgency framing, a mandatory security update that must happen now, discourages employees from pausing to verify the request through other channels. Because the scenario touches identity and access management directly, it also targets employees who are primed to treat MFA and passkey prompts as routine security hygiene rather than a potential threat.

What to watch for

  • Unsolicited calls claiming a mandatory, urgent security migration is required
  • A request to visit a web address that is not an official corporate domain, particularly one referencing passkeys, MFA, or SSO
  • Calls received on a personal mobile number rather than a work line
  • Pressure to act immediately without time to verify the request
  • Missing password reset confirmations or security alert emails, which attackers have deleted to avoid detection

How to build resistance

Organizations should train employees, including finance, executive, legal, and IT staff, to treat unexpected helpdesk calls as unverified until confirmed through a known internal number or directory, rather than any number or link provided during the call itself. Employees should be reminded to only use official company bookmarks or portals for MFA and passkey enrollment, never a link given over the phone. Because attackers have been observed deleting password-reset confirmations and security notifications to reduce detection, staff should also be encouraged to report any gaps in expected security alerts. Reinforcing these habits across all employee groups, not just IT and IAM administrators, helps reduce the chance that an urgent-sounding call leads to a compromised account.

Key findings

  • UNC6671 continues to run real-world vishing-led compromises, despite a claimed “retirement” of an extortion brand.
  • Callers impersonate IT helpdesk staff and pressure employees with urgent “mandatory” security migration instructions.
  • Victims are directed to spoofed login portals using adversary-in-the-middle (AiTM) tooling to capture credentials and MFA tokens.
  • The actor often calls employees on personal mobile phones and in some cases spoofs the legitimate helpdesk phone number.
  • Compromised email accounts are used to reset passwords and attackers delete security notifications to reduce detection.
  • Infrastructure shows reuse of “passkey/mfa/sso” themed domains across multiple extortion brands (Redact, Pink, Helix, Falcon, BlackFile).

Who’s being targeted

  • Commonly targeted roles: All employees, Finance teams, Executives, Legal teams, IT helpdesk/service desk, Identity & access management (IAM) administrators.
  • Affected industries: Financial services, Private equity, Professional services, Legal services, Manufacturing, Real estate, Healthcare, Insurance, Technology, Transportation, Hospitality.
  • Attack channels: vishing, website.
  • Impersonated: Internal IT Helpdesk.

Red flags to watch for

  • Unsolicited urgent call about a “mandatory” security migration
  • Request to use a web address that isn’t an official corporate domain (lookalike “passkey/mfa/sso” site)
  • Call comes to a personal mobile number and/or the caller pressures you to act immediately
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the UNC6671 vishing scam?

UNC6671 is a threat actor that calls employees pretending to be IT helpdesk staff, claiming an urgent mandatory security migration requires enabling passkeys or updating MFA enrollment, then directs victims to a spoofed login portal that steals credentials and MFA tokens.

How does UNC6671 make the calls seem legitimate?

The actor often calls employees on their personal mobile phones, and in some cases spoofs the legitimate helpdesk phone number to add credibility to the request.

What happens after credentials are stolen in this scam?

Adversary-in-the-middle infrastructure captures passwords and MFA tokens, allowing attackers to compromise email and cloud accounts, reset passwords, delete security alerts, and pursue data theft and extortion.

What are warning signs employees should watch for?

Red flags include unsolicited urgent calls about a mandatory security migration, requests to visit a non-official login web address, and pressure to act immediately, especially when the call arrives on a personal phone.

Read the video transcript

You get a call on your personal phone: “Hi, this is IT helpdesk, urgent mandatory security migration…” They say you must enable a new passkey now, then send you to a fake login like company.createssopasskey.com that looks just like Microsoft 365 or Okta. This is UNC6671 vishing: they grab your password and MFA code, log in as you, reset things, and quietly delete the security emails so you never see alerts. If IT ever calls you unexpectedly about passkeys or MFA, hang up and call the helpdesk back using the number in our internal directory.

Similar attacks

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
UNC6671 Rebrands, Runs IT Helpdesk Vishing

UNC6671 Rebrands, Runs IT Helpdesk Vishing

Google Threat Intelligence reports that extortion group UNC6671 (formerly branded “BlackFile”) is calling employees while posing as IT helpdesk staff and pushing “urgent security migrations.” Victims are lured to spoofed login pages to capture passwords and MFA tokens, enabling Microsoft 365/Okta…

August 7, 2026
NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026