Vishing crew UNC6671 hits Wall Street firms for data theft
A phone-based social engineering group tracked by Google as UNC6671 has targeted major US financial firms by posing as IT support and stealing employee login details. Arctic Wolf reported similar ongoing activity involving Pink, Helix, Cinder and Redact, while noting that the brands may not be one proven group. Microsoft reported on September 10 that attackers were still calling employees on personal phones to steal Microsoft 365 access and company data. Apollo Global Management remains the first named target in this campaign to confirm that hackers stole personal data, including Social Security numbers.
- Started
- Jun 1, 2026
- Latest activity
- Sep 11, 2026
- Attributed to
- UNC6671 (formerly BlackFile, operating as Redact/Pink/Falcon/Helix)Likely
- Where
- United States
- Sectors
- Finance
- Scale
- Over 200 financial firms and businesses targeted
Current status
No credible reporting or official statement dated after September 11, 2026 was found; the latest evidence still describes ongoing activity.
Active: Confirmed and still going. Attacker activity or disruption is continuing.
Who is behind it
Microsoft separately named Storm-3121 and Storm-3032 in related initial-access activity. This does not prove that all named extortion brands are one group.
Impact
Attackers use fake IT help desk calls and phishing sites to steal employee credentials and multi-factor login sessions, then take data from SharePoint, OneDrive, Exchange and Box accounts. Microsoft said some intrusions lasted for weeks. Arctic Wolf observed no malware or network spread in the cases it studied. Uber Freight said its incident was contained and its operations were not disrupted. Apollo confirmed that personal data was stolen, but has not said how many people were affected. Google estimated the wider campaign had collected about 10.6 million dollars, while some victims reportedly paid.
What to do
Employees should never provide login credentials or approve a multi-factor login request after an unsolicited phone call. Verify IT support requests through a known company channel and use phishing-resistant methods such as FIDO2 security keys or passkeys where available. Companies should require managed devices for cloud access and watch for unusual sign-ins and bulk file downloads. Individuals notified by Apollo should watch for identity theft, consider the free credit monitoring Apollo is offering, and consider a credit freeze or fraud alert.
Timeline
-
Sep 11, 2026
BleepingComputer reported that Microsoft linked passkey-themed phishing and Microsoft 365 data theft to ShinyHunters, Helix and other extortion groups.
Activebleepingcomputer.com -
Sep 10, 2026
Help Net Security reported that attackers were still calling or texting employees on personal phones, stealing Microsoft 365 access and pulling data from SharePoint, OneDrive and Exchange. It said Microsoft attributed related initial access to Storm-3121, Storm-3032 and other actors.
Activehelpnetsecurity.com -
Sep 8, 2026
Help Net Security reported that Arctic Wolf's PREY-0058 activity was targeting executives with fake IT support calls, stealing Microsoft 365 sessions and taking data for extortion. The report said the activity shared significant tradecraft similarities with UNC6671.
Activehelpnetsecurity.com -
Sep 3, 2026
Arctic Wolf reported that PREY-0058 was still targeting US organizations through fake IT help desk calls, stolen cloud login sessions and residential proxy sign-ins. It found data theft from Microsoft 365 and Box accounts, followed by extortion demands. Arctic Wolf said the activity overlaps with UNC6671 but that the different extortion brands may represent affiliates or related groups rather than one proven actor.
Activegithub.com -
Aug 26, 2026
Law360 reported that Apollo Global Management shareholders are raising claims that their personal data was exposed in the breach, adding a second legal front alongside the individual data-privacy investigation already announced by Edelson Lechtzin LLP.
Activelaw360.com -
Aug 24, 2026
The Register and SecurityWeek republished details of the Apollo breach, confirming hackers spent about four days inside Apollo's cloud platforms during the July 6 to July 10 window, with no new facts about additional named victims or law enforcement action.
Activetheregister.com -
Aug 23, 2026
A US plaintiffs' firm, Edelson Lechtzin LLP, announced it is investigating potential data privacy legal claims against Apollo Global Management on behalf of individuals notified about the breach.
Activepr.cullmantimes.com -
Aug 22, 2026
Apollo Global Management shares fell about 5.7 percent following disclosure of the client data breach, reflecting investor reaction to the incident.
Activefinance.yahoo.com -
Aug 21, 2026
Apollo's notice filed with the California attorney general's data breach registry said intruders had unauthorized access to some of its cloud-based systems between July 6 and July 10, and that it was not until August 12 that Apollo determined the stolen data included full names, dates of birth, contact details, home addresses and Social Security numbers. Apollo said it has no evidence so far that the stolen data has been posted online or used for fraud, and it is offering affected individuals free credit monitoring and identity protection.
Activeinsurancebusinessmag.com -
Aug 21, 2026
Apollo Global Management confirmed hackers gained unauthorized access to its cloud systems in July and stole personal data, including names, dates of birth, home addresses and Social Security numbers, notifying affected individuals by letter. It is the first named target in this campaign to confirm actual data theft rather than just being probed.
Activeinsurancejournal.com -
Aug 20, 2026
A Biometric Update report said Point72 told investors no customer data was stolen and Two Sigma found no indication its systems were affected, while Citadel declined to comment, as Reuters linked additional firms including Blackstone, Bridgewater, Apollo, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody's to attacker infrastructure without confirming any of them were breached.
Activebiometricupdate.com -
Aug 17, 2026
Trans.info reported Uber Freight had confirmed the cyberattack and said the incident was contained and remediated with no impact on operations, while Helix's claimed file count remained unverified.
Activetrans.info -
Aug 13, 2026
Google estimated the wider vishing extortion campaign linked to UNC6671 has netted the group about 10.6 million dollars.
Activemsn.com -
Aug 13, 2026
Uber Freight confirmed a data security incident to FreightWaves, saying it had contained the intrusion and engaged federal law enforcement, but it has not confirmed whether the attackers' claimed stolen files are authentic or said whether it paid a ransom.
Activefreightwaves.com -
Aug 12, 2026
Uber Freight confirmed unauthorized access to part of its systems and said the incident was contained and fixed. Helix claimed it stole nearly 1 million files, but Uber Freight did not confirm that claim and said its operations were not disrupted.
Activetheregister.com -
Aug 11, 2026
Cybersecurity Dive reported that UNC6671 remained linked to recent extortion attacks on private equity firms, ratings agencies and law firms.
Activecybersecuritydive.com -
Aug 7, 2026
Reports confirmed the group rebranded its leak sites from BlackFile to Redact, Pink, Helix and Falcon after an alleged affiliate hijack.
Activesecurityweek.com -
Aug 6, 2026
Google's Threat Intelligence Group formally linked the campaign to UNC6671 and the retired BlackFile extortion brand.
Activebleepingcomputer.com -
Jul 26, 2026
Reuters and Google data showed the phone-based extortion campaign had targeted dozens of major US financial firms over the prior month.
Activeesecurityplanet.com -
Jul 15, 2026
SecurityAffairs reported credential-stealing vishing sites targeting over 200 financial firms under names including Redact, Pink, Falcon and Helix.
Activesecurityaffairs.com
Sources
- Attackers Impersonate IT Support to Breach Leading Financial Companies SecurityAffairs Jul 15, 2026
- Wall Street firms hit by phone-based hacking scams eSecurityPlanet Jul 26, 2026
- Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group BleepingComputer Aug 6, 2026
- Blackstone, KKR and CME targeted in vishing wave tied to BlackFile crew SiliconANGLE Aug 7, 2026
- UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data The Hacker News Aug 7, 2026
- Vishing Extortion Group UNC6671 Rebrands After Making Millions SecurityWeek Aug 7, 2026
- UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services Google Cloud Aug 7, 2026
- Former BlackFile affiliates linked to extortion campaign targeting private equity Cybersecurity Dive Aug 11, 2026 unverified
- Uber Freight keeps on trucking after extortion crew breaks in The Register Aug 12, 2026
- Uber Freight confirms cyber incident after hackers claim nearly 1 million files FreightWaves Aug 13, 2026
- Google ties the Uber Freight hackers to a $10.6 million vishing operation MSN/Cryptopolitan Aug 13, 2026
- Wall Street vishing attacks expose voice as a weak link in identity security Biometric Update Aug 20, 2026
- Uber Freight confirms cyberattack as hackers claim nearly 1 million files stolen trans.info Aug 17, 2026
- Apollo Global Reveals Data Breach After Hackers Target Financial Firms Insurance Journal Aug 21, 2026
- Alternative asset manager confirms hackers stole personal data in social engineering attack Insurance Business Aug 21, 2026
- Apollo Says Hackers Stole Social Security Numbers In A Cloud Breach The Wealth Advisor Aug 21, 2026
- Apollo Data Breach Shows Wall Street's Cloud Security Problem TechBooky Aug 21, 2026
- Apollo Global reveals data breach after hackers target financial firms Reuters via MSN Aug 21, 2026
- Apollo says hackers accessed personal data in latest Wall Street breach Financial Times Aug 21, 2026
- Apollo Global Management (APO) Is Down 5.7% After Disclosing Client Data Breach Yahoo Finance Aug 22, 2026
- $1T investment giant Apollo breached after social engineering attack The Register Aug 24, 2026
- Personal Information Exposed in Apollo Global Data Breach SecurityWeek Aug 24, 2026
- Wall Street giant Apollo confirms personal data breach Cybernews Aug 23, 2026
- Apollo Data Breach Shows the Risk Behind a Simple Phone Call Security Boulevard Aug 23, 2026 unverified
Related reports
- Microsoft 365 data theft via fake IT calls Aug 7, 2026
- Redact voice scams breach company cloud accounts Aug 7, 2026
- UNC6671 phishing targets M&A firms for data theft Aug 7, 2026
- BlackFile-linked attackers attack hedge funds Aug 6, 2026
- UNC6671 steals cloud accounts via fake IT calls Aug 6, 2026
- Wall Street hedge funds hit by voice scams Aug 1, 2026
- Wall Street firms hit by phone-based hacking scams Jul 30, 2026
- Attackers Impersonate IT Support to Breach Leading Financial Companies Jul 28, 2026
- UNC6671 steals SaaS data via fake IT calls Jul 26, 2026
- Microsoft Entra accounts hijacked via fake callers Jul 15, 2026
- Okta warns of fake Microsoft 365 calls Jul 10, 2026
- Okta warns of fake IT passkey scam Jul 10, 2026