// 5 ZERO-DAY · 2 CVE · 3 EXPLOIT IN THE LAST 24H
The UNC6671 group uses vishing on personal smartphones to bypass MFA and steal SaaS sessions. Google has tracked over $10 million in extortion payments.

On August 19, 2026, Google Threat Intelligence Group and Mandiant documented an evolution in the tactics of the data extortion group UNC6671: initial contact now occurs preferentially via employees' personal phones, where corporate protections are reduced or absent. The goal is to convince the victim to connect to spoofed login portals using an adversary-in-the-middle architecture, intercepting credentials and MFA tokens in real time. This shift of the attack perimeter from managed devices to personal phones renders traditional security stacks ineffective.

Key Takeaways
  • UNC6671 contacts employees on their personal phones impersonating IT staff for "urgent security migrations"
  • Attackers use AitM portals to capture credentials and active sessions, then Python and PowerShell scripts to exfiltrate data from cloud and SaaS environments
  • Google has tracked over $10.6 million in Bitcoin payments to wallets associated with the group between January and May 2026
  • The group registers adversarial MFA devices and removes legitimate ones to ensure persistence on compromised accounts

The Personal Phone as the Enterprise Security Blind Spot

UNC6671's choice to target personal phones is not random. According to the cited source, "the threat actor often contacts employees via their personal mobile devices." These devices lack corporate EDR, DNS filters, email gateways, or logging systems that record inbound voice calls. The human operator, posing as an IT technician, exploits the psychological pressure of a "mandatory security migration" to push the victim toward a controlled login portal.

The adversary-in-the-middle architecture interposes itself between the user and the legitimate service. When the victim enters credentials and the MFA code, both are intercepted in real time. CrowdStrike has documented that this infrastructure "capture their authentication data and active session tokens in real time." Once an authenticated session at the identity provider is obtained, attackers gain implicit lateral movement across the entire connected SaaS ecosystem.

"Regardless of whether this activity reflects a fractured threat group, outsourced extortion negotiators, or a broader affiliate network, the initial infection vector leveraged and goals of these campaigns are consistent" — Google Threat Intelligence Group

The Asymmetry Between IdP and Connected SaaS Services

The technical core of the attack lies in the architectural discontinuity between the identity provider and SaaS applications. CrowdStrike observed that "by abusing the trust relationship between the IdP and connected services, the adversaries bypass the need to compromise individual SaaS apps and move laterally across the victim's entire SaaS ecosystem with a single authenticated session." This means a single intercepted session on Microsoft 365 or Okta opens access to dozens of connected services without additional authentication.

Persistence is guaranteed through a precise sequence: registration of an attacker-controlled MFA device, followed by removal of existing ones. This way the victim loses control of the account while the attacker maintains access even after potential password changes. The domains used to host the fraudulent portals — passkeyhelpdesk.com, setupsso.com, idokta.com — employ target-specific subdomains, complicating generic detection.

Extortion Economics and Group Trajectory

UNC6671 does not deploy ransomware: its specialization is data-only extortion. This model reduces incident visibility, eliminating typical indicators of a cryptographic deployment and accelerating the timeline between compromise and payment demand. Google has tracked over $10.6 million in Bitcoin payments to wallets associated with the group in the January–May 2026 period.

The extortion figures are significant: initial demands exceeding $3 million, with an average settlement of approximately $750,000 in 53 percent or more of documented cases. The group has operated under multiple brands — BlackFile (retired May 11, 2026), Redact, Pink, Helix, Falcon — suggesting a flexible structure that Google described as a possible "fractured threat group, outsourced extortion negotiators, or a broader affiliate network." The exact relationship with ShinyHunters, a collective with similar tradecraft, remains not fully clarified: Google assesses operational independence despite overlaps.

Sector Targeting and Tactical Volatility

The targeting chronology shows rapid adaptation: manufacturing, real estate, and healthcare between April and May 2026; technology, transportation, and hospitality in June; financial and legal in July. This sector rotation, documented based on the cited source, indicates an ability to recalibrate campaigns based on perceived profitability and saturation of previous targets. The collective is tracked by CrowdStrike as "Cordial Spider," with emphasis on "rapid data theft and extortion."

Confirmed victims are distributed across North America, Australia, and the United Kingdom, with dozens of organizations targeted. Google explicitly stated that "these compromises are not the result of a security vulnerability in vendor products or infrastructure": the entire attack chain rests on social engineering, rendering traditional exposure metrics based on CVEs and patch levels inapplicable.

Why This Matters

The brief does not specify corrective measures indicated by primary sources. The cited source does not document explicit operational recommendations for potentially exposed organizations. No indication emerges on specific hardening, policy configurations, or verification controls implemented by targets that successfully rejected the calls. The dossier does not quantify the vishing campaign success rate nor the total number of calls placed versus those converted to compromise. The geographic origin of the phone operators and the internal organizational structure of UNC6671 — unitary group, affiliate network, or fragmented crews — remain undetermined.

What the dossier documents is the confirmation of a pattern: when the attack starts on a device outside the corporate perimeter, enterprise security investments do not intercept the threat. The discontinuity between identity provider and connected services amplifies the damage of a single compromised session. The specialization in data-only extortion, without encryption, further reduces the detection window.

The closure of the BlackFile brand on May 11, 2026 did not halt activity: the retirement was communicated through the site itself, followed by reactivation under other names. This branding elasticity, combined with the use of automated scripts for exfiltration, indicates an operation designed for resilience more than for persistence on a single identity. For organizations in financial and professional services — the current targeting sector — the consequence is that the threat model must explicitly include personal devices as an attack surface.

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. thomasharris6.wordpress.com
  2. vncybers.vn
  3. thehackernews.com
  4. wordpress.com