Skip to content
NetarxImpact Database
Vishing (Voice Phishing)UnknownConfirmedCampaign

BlackFile extortion gang runs vishing campaign against retail and hospitality

Multiple retail and hospitality organisations (unnamed) · Retail · United States · February 2026

What happened

BleepingComputer reported on April 24, 2026 that a financially motivated group tracked as BlackFile had been running data theft and extortion attacks against retail and hospitality organisations since February 2026. Mandiant confirmed it was actively responding to several vishing incidents involving the group. Palo Alto Networks' Unit 42 linked BlackFile with moderate confidence to 'The Com' network of English-speaking cybercriminals.

How the deception worked

Operators called employees from spoofed VoIP numbers while posing as IT support and steered them onto fake login pages to capture credentials. Holding valid credentials, they registered their own devices as trusted authenticators, which neutralised multi-factor authentication and let them escalate into executive accounts. They then swept Salesforce instances and SharePoint servers for files containing terms such as 'confidential' and 'SSN', published samples on a dark web leak site, and demanded seven-figure ransoms. The group also attempted swatting against employees to increase pressure during negotiations.

AI involvement · Unknown

Reporting described spoofed VoIP calls and branded phishing pages, but did not confirm synthetic voice on the calls.

The control that would have caught it· our reading, not a claim from the sources

Blocking self-service device registration for new authenticators, and requiring a verified approval step for it, is the control that stops credential theft from becoming persistent MFA-bypassing access.

Sources (1)

  1. New BlackFile extortion gang targets retail and hospitality orgs
    BleepingComputer·bleepingcomputer.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.