Cybersecurity Research

Same Scammers, New Names: Vishing Extortion Gang Rebrands to Evade Detection

Key Takeaway Train staff to verify any unexpected IT support calls through official channels before entering credentials or MFA codes, especially when contacted on personal devices.

Security researchers at Google Threat Intelligence Group say a threat actor known as UNC6671 has not disappeared despite publicly announcing the retirement of its 'BlackFile' extortion brand in May 2026. Instead, the group has spread its operations across several new extortion fronts, including brands called Redact, Pink, Helix, and Falcon, all sharing the same underlying infrastructure and techniques.

The group's method relies heavily on voice phishing, where attackers call employees on their personal mobile phones pretending to be IT helpdesk staff carrying out an urgent, mandatory security migration. Victims are directed to fake login pages that intercept usernames, passwords, and multi-factor authentication codes in real time. Once the attackers gain access, they use automated tools to steal data from cloud platforms such as Microsoft 365 and Okta.

Researchers note that although each extortion brand publishes stolen data on its own separate leak site, the phishing templates, target selection, and shared infrastructure make clear these are the same actors operating under different names. Recent targeting has focused on financial services, private equity, and professional services firms.

vishing extortion cloud security phishing financial services
Regulated in financial services? APRA CPS 220, 230 and 234, in plain language ->

Summarised by CISO AI from Google Threat Intelligence. We link back to every original so you can read it yourself.