{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:38:15.795Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"BlackFile extortion gang runs vishing campaign against retail and hospitality","date":"2026-02","date_precision":"month","victim_org":"Multiple retail and hospitality organisations (unnamed)","sector":"Retail","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Physical Pretexting"],"ai_involvement":"Unknown","ai_notes":"Reporting described spoofed VoIP calls and branded phishing pages, but did not confirm synthetic voice on the calls.","outcomes":["Data Breach","Extortion","Credential Theft"],"loss_usd":null,"loss_note":"Seven-figure ransom demands were reported; no confirmed payment totals were published in this report.","records_affected":null,"threat_actor":"BlackFile (also tracked as UNC6671, CL-CRI-1116, Cordial Spider)","summary":"BleepingComputer reported on April 24, 2026 that a financially motivated group tracked as BlackFile had been running data theft and extortion attacks against retail and hospitality organisations since February 2026. Mandiant confirmed it was actively responding to several vishing incidents involving the group. Palo Alto Networks' Unit 42 linked BlackFile with moderate confidence to 'The Com' network of English-speaking cybercriminals.","how_it_worked":"Operators called employees from spoofed VoIP numbers while posing as IT support and steered them onto fake login pages to capture credentials. Holding valid credentials, they registered their own devices as trusted authenticators, which neutralised multi-factor authentication and let them escalate into executive accounts. They then swept Salesforce instances and SharePoint servers for files containing terms such as 'confidential' and 'SSN', published samples on a dark web leak site, and demanded seven-figure ransoms. The group also attempted swatting against employees to increase pressure during negotiations.","lessons":"Blocking self-service device registration for new authenticators, and requiring a verified approval step for it, is the control that stops credential theft from becoming persistent MFA-bypassing access.","confidence":"Confirmed","sources":[{"title":"New BlackFile extortion gang targets retail and hospitality orgs","url":"https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/","publisher":"BleepingComputer"}],"entry_type":"campaign","slug":"2026-blackfile-extortion-gang-runs-vishing-campaign-against-retail-and-hospit","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-blackfile-extortion-gang-runs-vishing-campaign-against-retail-and-hospit"}]}