Microsoft 365 data theft via fake IT calls
A group called UNC6671 calls employees, pretends to be IT support, and tricks them into a fake login page. That steals both their password and their active sign-in session, letting the attacker read their Microsoft 365 or Okta-connected mail and files without ever cracking a password.
- Report priority
- High
- Victim
- Microsoft 365
What is known
An attacker phones an employee's personal cell, poses as the IT helpdesk pushing an urgent passkey or multi-factor authentication update, and walks them to a fake enrollment page that sits between the employee and the real Microsoft 365 or Okta login, capturing both the password and the live session token as the employee signs in.
What to do
Instead, ask whether anyone at your organization has recently received an unsolicited call about a mandatory passkey, MFA, or SSO update and been sent a link to enroll or sign in again. Treat any such call as suspicious until verified through a known internal IT channel, since this campaign runs through freshly registered domains rather than a specific software bug.
Require employees to verify any helpdesk contact through a known internal number or ticketing system before clicking a link or entering credentials, and have security teams enforce phishing-resistant sign-in methods (like hardware security keys), shorten how long a sign-in session stays valid, and restrict Microsoft 365 and Okta access to managed devices and trusted networks.
Reported details
An employee at a financial services or private equity firm gets a call from someone claiming to be internal IT, warning that a security migration must happen right away. The caller sends a link to a look-alike sign-in page built around words like passkey or SSO. The employee enters their password and completes multi-factor authentication on that fake page, and the attacker's tool relays that session in real time, capturing a working authentication token.
UNC6671 runs adversary-in-the-middle (AiTM) phishing via vishing calls, relaying real-time Microsoft 365 or Okta logins through look-alike passkey/MFA/SSO enrollment domains to capture credentials and a live session token, bypassing the need to crack a password. Google Threat Intelligence Group ties the activity to extortion brands formerly marketed as BlackFile and now operating as Redact, Pink, Helix, and Falcon, sharing phishing templates and domain infrastructure. Post-compromise, operators use scripted direct-stream data collection to exfiltrate mail and files at scale, route traffic through residential proxies to blend in, and reset non-SSO app passwords via compromised mailboxes while deleting security alerts. Domain registration accelerated to roughly one new root domain every 1.6 days between June and July, with seven activated in one 72-hour window.
References
- cloud.google.com · unc6671-targets-financial-services-and-enterprise-cloud-environments Cyber Security News
- ppl-ai-file-upload.s3.amazonaws.com · UNC6671-Automates-Microsoft-365-Data-Theft-After-Hijacking-Employee-Sessions.pdf Cyber Security News
- any.run · threat-intelligence-feeds Cyber Security News
- bleepingcomputer.com · hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group BleepingComputer
- infosecurity-magazine.com · redact-extortion-group-blackfile Infosecurity Magazine
- infosecurity-magazine.com · logokit-phishing-real-time Infosecurity Magazine
- infosecurity-magazine.com · hollowgraph-microsoft-calendars Infosecurity Magazine
- securityweek.com · vishing-extortion-group-unc6671-rebrands-after-making-millions SecurityWeek