Active High impact Fraud Checked 6h ago

Vishing crew UNC6671 hits Wall Street firms for data theft

A phone-based social engineering group tracked by Google as UNC6671 has targeted major US financial firms by posing as IT support and stealing employee login details. Arctic Wolf reported similar ongoing activity involving Pink, Helix, Cinder and Redact, while noting that the brands may not be one proven group. Microsoft reported on September 10 that attackers were still calling employees on personal phones to steal Microsoft 365 access and company data. Apollo Global Management remains the first named target in this campaign to confirm that hackers stole personal data, including Social Security numbers.

Started
Jun 1, 2026
Latest activity
Sep 11, 2026
Attributed to
UNC6671 (formerly BlackFile, operating as Redact/Pink/Falcon/Helix)Likely
Where
United States
Sectors
Finance
Scale
Over 200 financial firms and businesses targeted

Current status

No credible reporting or official statement dated after September 11, 2026 was found; the latest evidence still describes ongoing activity.

Active: Confirmed and still going. Attacker activity or disruption is continuing.

Who is behind it

Microsoft separately named Storm-3121 and Storm-3032 in related initial-access activity. This does not prove that all named extortion brands are one group.

Impact

Attackers use fake IT help desk calls and phishing sites to steal employee credentials and multi-factor login sessions, then take data from SharePoint, OneDrive, Exchange and Box accounts. Microsoft said some intrusions lasted for weeks. Arctic Wolf observed no malware or network spread in the cases it studied. Uber Freight said its incident was contained and its operations were not disrupted. Apollo confirmed that personal data was stolen, but has not said how many people were affected. Google estimated the wider campaign had collected about 10.6 million dollars, while some victims reportedly paid.

What to do

Employees should never provide login credentials or approve a multi-factor login request after an unsolicited phone call. Verify IT support requests through a known company channel and use phishing-resistant methods such as FIDO2 security keys or passkeys where available. Companies should require managed devices for cloud access and watch for unusual sign-ins and bulk file downloads. Individuals notified by Apollo should watch for identity theft, consider the free credit monitoring Apollo is offering, and consider a credit freeze or fraud alert.

Timeline

  1. Sep 11, 2026

    BleepingComputer reported that Microsoft linked passkey-themed phishing and Microsoft 365 data theft to ShinyHunters, Helix and other extortion groups.

    Activebleepingcomputer.com
  2. Sep 10, 2026

    Help Net Security reported that attackers were still calling or texting employees on personal phones, stealing Microsoft 365 access and pulling data from SharePoint, OneDrive and Exchange. It said Microsoft attributed related initial access to Storm-3121, Storm-3032 and other actors.

    Activehelpnetsecurity.com
  3. Sep 8, 2026

    Help Net Security reported that Arctic Wolf's PREY-0058 activity was targeting executives with fake IT support calls, stealing Microsoft 365 sessions and taking data for extortion. The report said the activity shared significant tradecraft similarities with UNC6671.

    Activehelpnetsecurity.com
  4. Sep 3, 2026

    Arctic Wolf reported that PREY-0058 was still targeting US organizations through fake IT help desk calls, stolen cloud login sessions and residential proxy sign-ins. It found data theft from Microsoft 365 and Box accounts, followed by extortion demands. Arctic Wolf said the activity overlaps with UNC6671 but that the different extortion brands may represent affiliates or related groups rather than one proven actor.

    Activegithub.com
  5. Aug 26, 2026

    Law360 reported that Apollo Global Management shareholders are raising claims that their personal data was exposed in the breach, adding a second legal front alongside the individual data-privacy investigation already announced by Edelson Lechtzin LLP.

    Activelaw360.com
  6. Aug 24, 2026

    The Register and SecurityWeek republished details of the Apollo breach, confirming hackers spent about four days inside Apollo's cloud platforms during the July 6 to July 10 window, with no new facts about additional named victims or law enforcement action.

    Activetheregister.com
  7. Aug 23, 2026

    A US plaintiffs' firm, Edelson Lechtzin LLP, announced it is investigating potential data privacy legal claims against Apollo Global Management on behalf of individuals notified about the breach.

    Activepr.cullmantimes.com
  8. Aug 22, 2026

    Apollo Global Management shares fell about 5.7 percent following disclosure of the client data breach, reflecting investor reaction to the incident.

    Activefinance.yahoo.com
  9. Aug 21, 2026

    Apollo's notice filed with the California attorney general's data breach registry said intruders had unauthorized access to some of its cloud-based systems between July 6 and July 10, and that it was not until August 12 that Apollo determined the stolen data included full names, dates of birth, contact details, home addresses and Social Security numbers. Apollo said it has no evidence so far that the stolen data has been posted online or used for fraud, and it is offering affected individuals free credit monitoring and identity protection.

    Activeinsurancebusinessmag.com
  10. Aug 21, 2026

    Apollo Global Management confirmed hackers gained unauthorized access to its cloud systems in July and stole personal data, including names, dates of birth, home addresses and Social Security numbers, notifying affected individuals by letter. It is the first named target in this campaign to confirm actual data theft rather than just being probed.

    Activeinsurancejournal.com
  11. Aug 20, 2026

    A Biometric Update report said Point72 told investors no customer data was stolen and Two Sigma found no indication its systems were affected, while Citadel declined to comment, as Reuters linked additional firms including Blackstone, Bridgewater, Apollo, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody's to attacker infrastructure without confirming any of them were breached.

    Activebiometricupdate.com
  12. Aug 17, 2026

    Trans.info reported Uber Freight had confirmed the cyberattack and said the incident was contained and remediated with no impact on operations, while Helix's claimed file count remained unverified.

    Activetrans.info
  13. Aug 13, 2026

    Google estimated the wider vishing extortion campaign linked to UNC6671 has netted the group about 10.6 million dollars.

    Activemsn.com
  14. Aug 13, 2026

    Uber Freight confirmed a data security incident to FreightWaves, saying it had contained the intrusion and engaged federal law enforcement, but it has not confirmed whether the attackers' claimed stolen files are authentic or said whether it paid a ransom.

    Activefreightwaves.com
  15. Aug 12, 2026

    Uber Freight confirmed unauthorized access to part of its systems and said the incident was contained and fixed. Helix claimed it stole nearly 1 million files, but Uber Freight did not confirm that claim and said its operations were not disrupted.

    Activetheregister.com
  16. Aug 11, 2026

    Cybersecurity Dive reported that UNC6671 remained linked to recent extortion attacks on private equity firms, ratings agencies and law firms.

    Activecybersecuritydive.com
  17. Aug 7, 2026

    Reports confirmed the group rebranded its leak sites from BlackFile to Redact, Pink, Helix and Falcon after an alleged affiliate hijack.

    Activesecurityweek.com
  18. Aug 6, 2026

    Google's Threat Intelligence Group formally linked the campaign to UNC6671 and the retired BlackFile extortion brand.

    Activebleepingcomputer.com
  19. Jul 26, 2026

    Reuters and Google data showed the phone-based extortion campaign had targeted dozens of major US financial firms over the prior month.

    Activeesecurityplanet.com
  20. Jul 15, 2026

    SecurityAffairs reported credential-stealing vishing sites targeting over 200 financial firms under names including Redact, Pink, Falcon and Helix.

    Activesecurityaffairs.com

Sources

Related reports