UNC6671 phishing targets M&A firms for data theft

Published August 7, 2026

A financially motivated group called UNC6671 calls employees on their personal phones, pretends to be IT help desk staff, and tricks them into handing over Microsoft 365 or Okta logins. It now targets M&A firms, law firms, and private equity shops to steal deal and litigation data, then extorts the victim over it.

Report priority
Medium
Targets
BlackFile+6 more

How it works

An attacker calls an employee's personal cell posing as internal IT support, then walks them through a fake login page on a lookalike domain that captures their username, password, and one-time passcode in real time, giving the attacker a live company login session.

What to do

Ask whether your organization's help desk will reset access or MFA for someone who only calls in and sounds convincing, without a callback or manager verification step.

Require call-backs to a known number or in-person verification before any help desk resets credentials or MFA, restrict sensitive cloud logins to company-managed devices, and turn on audit logging so deleted security alerts and password-reset emails in Microsoft 365 or Okta get flagged instead of silently disappearing.

Technical details

Affected software: BlackFile, Redact, Pink, Helix, Falcon, Microsoft 365, Okta

An employee at a private equity firm gets a phone call from someone claiming to be internal IT support, asking them to verify their login on a new security page. The page sits on a domain named after the victim company to look legitimate, and it relays the entered password and passcode straight through to the real Microsoft 365 or Okta login so the attacker rides in on a valid session. Once inside, the attacker uses scripts to pull deal files, litigation documents, and investor records from cloud storage and email, then deletes the security alerts and password-reset notices that would tip off the target.

UNC6671, previously branded BlackFile, splintered into four extortion brands (Redact, Pink, Helix, Falcon) after a May 2026 retirement announcement, but Google's Threat Intelligence Group ties them together through shared phishing templates and domain infrastructure. The group vishes employees, directs them to adversary-in-the-middle credential-harvesting pages hosted on victim-branded subdomains (registered roughly every 1.6 days), and captures live SSO sessions for Microsoft 365 and Okta. It then automates exfiltration with python-requests and PowerShell and deletes password-reset and security-alert emails from compromised inboxes to delay detection.