What happened
Google Threat Intelligence reported that UNC6671, the vishing extortion crew previously known as BlackFile, retired that brand in May 2026 and continued under four names: Redact, Pink, Helix and Falcon. Between January and May 2026 the group received more than $10.6 million in Bitcoin across 18 wallet addresses. Opening demands ran from $1 million to $3 million, typically negotiated down 50 to 75 percent, with more than half of tracked cases settling near $750,000. Targeting moved from manufacturing, real estate, healthcare and insurance in spring to technology, transport and hospitality by mid-year and to financial and legal firms by July.
How the deception worked
Operators call employees on their personal mobile phones, reaching them outside any corporate monitoring, and present themselves as IT help desk staff running a mandatory, urgent security migration. The victim is directed to a spoofed Microsoft 365 or Okta login portal that captures credentials and multi-factor tokens through an adversary-in-the-middle proxy. Refinements include spoofing the organisation's real help desk number so the caller ID corroborates the story, and using already-compromised mailboxes to trigger password resets while deleting the confirmation emails so the user never sees them.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant MFA, restricting authentication to trusted networks or managed devices, and alerting on new MFA factor enrolment in the identity provider are the three controls Google names against this exact playbook.
Sources (2)
- Vishing Extortion Group UNC6671 Rebrands After Making MillionsSecurityWeek·securityweek.comOpen ↗
- UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS DataThe Hacker News·thehackernews.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.