Skip to content
NetarxImpact Database
Help Desk ImpersonationUnknownConfirmedCampaign

UNC6671 vishing crew rebrands and banks $10.6M after help-desk impersonation calls

Organisations in manufacturing, real estate, healthcare, insurance, technology, transportation, hospitality, financial and legal services · Other · Global · May 2026

Criminal proceeds
$10,600,000
What the attackers earned. Not the same as what the victims lost, and often much smaller.
USD equivalent of Bitcoin paid into wallets Google Threat Intelligence linked to the group between January and May 2026, across 18 addresses. Not a single victim's loss.

What happened

Google Threat Intelligence reported that UNC6671, the vishing extortion crew previously known as BlackFile, retired that brand in May 2026 and continued under four names: Redact, Pink, Helix and Falcon. Between January and May 2026 the group received more than $10.6 million in Bitcoin across 18 wallet addresses. Opening demands ran from $1 million to $3 million, typically negotiated down 50 to 75 percent, with more than half of tracked cases settling near $750,000. Targeting moved from manufacturing, real estate, healthcare and insurance in spring to technology, transport and hospitality by mid-year and to financial and legal firms by July.

How the deception worked

Operators call employees on their personal mobile phones, reaching them outside any corporate monitoring, and present themselves as IT help desk staff running a mandatory, urgent security migration. The victim is directed to a spoofed Microsoft 365 or Okta login portal that captures credentials and multi-factor tokens through an adversary-in-the-middle proxy. Refinements include spoofing the organisation's real help desk number so the caller ID corroborates the story, and using already-compromised mailboxes to trigger password resets while deleting the confirmation emails so the user never sees them.

The control that would have caught it· our reading, not a claim from the sources

Phishing-resistant MFA, restricting authentication to trusted networks or managed devices, and alerting on new MFA factor enrolment in the identity provider are the three controls Google names against this exact playbook.

Sources (2)

  1. Vishing Extortion Group UNC6671 Rebrands After Making Millions
    SecurityWeek·securityweek.comOpen ↗
  2. UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
    The Hacker News·thehackernews.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.