{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:18:43.440Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-unc6671-vishing-crew-rebrands-and-banks-10-6m-after-help-desk-impersonat","title":"UNC6671 vishing crew rebrands and banks $10.6M after help-desk impersonation calls","date":"2026-05","date_precision":"month","year":2026,"victim_org":"Organisations in manufacturing, real estate, healthcare, insurance, technology, transportation, hospitality, financial and legal services","sector":"Other","country":"Global","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Credential Theft","Data Breach","Extortion"],"loss_usd":10600000,"loss_kind":"criminal_proceeds","loss_note":"USD equivalent of Bitcoin paid into wallets Google Threat Intelligence linked to the group between January and May 2026, across 18 addresses. Not a single victim's loss.","records_affected":null,"threat_actor":"UNC6671 (formerly BlackFile; operating as Redact, Pink, Helix and Falcon)","summary":"Google Threat Intelligence reported that UNC6671, the vishing extortion crew previously known as BlackFile, retired that brand in May 2026 and continued under four names: Redact, Pink, Helix and Falcon. Between January and May 2026 the group received more than $10.6 million in Bitcoin across 18 wallet addresses. Opening demands ran from $1 million to $3 million, typically negotiated down 50 to 75 percent, with more than half of tracked cases settling near $750,000. Targeting moved from manufacturing, real estate, healthcare and insurance in spring to technology, transport and hospitality by mid-year and to financial and legal firms by July.","how_it_worked":"Operators call employees on their personal mobile phones, reaching them outside any corporate monitoring, and present themselves as IT help desk staff running a mandatory, urgent security migration. The victim is directed to a spoofed Microsoft 365 or Okta login portal that captures credentials and multi-factor tokens through an adversary-in-the-middle proxy. Refinements include spoofing the organisation's real help desk number so the caller ID corroborates the story, and using already-compromised mailboxes to trigger password resets while deleting the confirmation emails so the user never sees them.","lessons":"Phishing-resistant MFA, restricting authentication to trusted networks or managed devices, and alerting on new MFA factor enrolment in the identity provider are the three controls Google names against this exact playbook.","confidence":"Confirmed","sources":[{"title":"Vishing Extortion Group UNC6671 Rebrands After Making Millions","url":"https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/","publisher":"SecurityWeek"},{"title":"UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data","url":"https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-unc6671-vishing-crew-rebrands-and-banks-10-6m-after-help-desk-impersonat"}]}