Vishing group UNC6671 skips the network and calls employees on their personal phones
Cybersecurity

Vishing group UNC6671 skips the network and calls employees on their personal phones

Google Threat Intelligence Group says UNC6671 has moved past corporate phishing filters entirely, tracking more than 10.6 million dollars in Bitcoin extorted from targets who answered a fake IT help desk call.

PublishedAugust 15, 2026
Read time5 min read
Share

The attack that email filters were never built to stop

Google Threat Intelligence Group and Mandiant have been tracking UNC6671, a financially motivated extortion operation that dispenses with phishing email entirely and instead calls employees directly on their personal mobile phones. The caller poses as internal IT help desk staff and claims the employee needs to complete an urgent, mandatory security migration, a pretext built specifically to create the kind of time pressure that short-circuits careful verification and discourages the employee from hanging up to confirm the request through another channel.

Because the contact happens over a personal phone number rather than a corporate email address or Slack channel, none of the enterprise's email security gateways, link scanners, or attachment sandboxes ever see the interaction. The entire attack surface this campaign exploits sits outside the perimeter that most security teams spend the majority of their budget defending, which is exactly why it has continued to work against organizations with otherwise mature email security programs.

From a phone call to a stolen session in minutes

Once an employee is on the call, UNC6671 directs them to a spoofed login page designed to match their organization's actual identity provider down to the branding and layout. Adversary-in-the-middle infrastructure sits between the victim and the real login service, capturing the username and password as they are typed and relaying the multi-factor authentication prompt in real time, so the victim's own MFA approval hands the attacker a valid, authenticated session token rather than blocking the intrusion the way MFA is designed to.

From there the group runs automated Python and PowerShell scripts that immediately begin pulling data out of Microsoft 365 and Okta-connected SaaS applications. Google's researchers describe this as a fast, largely automated pipeline: the manual, human part of the attack is the phone call itself, and everything downstream of a successful credential capture happens at machine speed, which sharply limits the window incident response teams have to intervene once the initial vishing call succeeds and the session token is in the attacker's hands.

One group, five brand names, since January

UNC6671 has operated under a rotating set of extortion brands since it first appeared in January 2026, including BlackFile, which it retired on May 11, followed by Redact, Pink, Helix, and Falcon. Rebranding after a wave of media coverage or law enforcement attention is a common tactic among extortion crews, since it resets the reputational association victims and researchers have built around a given name while the underlying infrastructure, tooling, and operators continue unchanged behind the scenes.

Tracking a group across five names in seven months requires the kind of infrastructure-level attribution that Google's threat intelligence team specializes in, correlating wallet addresses, phishing kit code reuse, and operational timing rather than relying on the self-reported brand name attached to a given extortion note. For defenders, the practical lesson is to build detection around the technique, help desk impersonation plus AitM credential capture, rather than around any single group name that may not survive the next rebrand.

The money says this is working better than most ransomware

Researchers tracked more than 10.6 million dollars in Bitcoin payments flowing to wallets associated with the group's operations between January 7 and May 12, 2026, a four-month window. That figure, generated without deploying any ransomware or encrypting a single system, underscores how effective pure data theft and extortion has become as a business model relative to the operational complexity and law enforcement attention that ransomware deployment now attracts, especially now that many victim organizations have functioning backups that make encryption alone a weaker lever than it once was.

The targets span North America, Australia, and the United Kingdom, with a recent pivot toward financial services and mergers-and-acquisitions firms, organizations where a breach disclosure during a live deal or regulatory filing window creates outsized pressure to pay quickly and quietly rather than fight the extortion in public. That targeting choice is deliberate: a leak timed to disrupt a pending transaction is worth far more to the extortionist than the same data released at a moment with no deal on the table.

What actually stops a call your directory can't filter

The fix for this attack pattern is procedural, not technical, and that is precisely why it is hard to enforce consistently. IT help desks need a verification protocol for any inbound or outbound identity-related request that does not rely on the caller's own claimed identity, such as requiring the employee to initiate contact through a known internal channel rather than acting on an unsolicited call, regardless of how urgent the caller makes it sound.

Phishing-resistant authentication, specifically FIDO2 hardware keys or passkeys that cannot be relayed through an adversary-in-the-middle proxy the way a one-time code can, closes the specific technical gap UNC6671 exploits even when the social engineering succeeds. Any enterprise that has not yet moved its highest-privilege accounts, identity administrators, finance, and executives, onto phishing-resistant MFA should treat this campaign's 10.6 million dollar haul as the business case for prioritizing that migration this quarter.

Vishing belongs on the same roadmap line as email security

Most enterprise security budgets still treat voice-based social engineering as a training slide rather than a control with its own tooling and metrics, even as vishing crews like UNC6671 demonstrate that it now generates extortion revenue on par with mid-tier ransomware operations. That gap between perceived risk and actual dollar impact is worth surfacing directly to the board, since the number attached to this single campaign, over 10.6 million dollars in four months, is not a hypothetical.

A realistic response plan pairs the technical fix, phishing-resistant MFA on high-value accounts, with an organizational one: a published, well-known process for verifying IT contact that every employee has actually seen, not just a policy buried in an onboarding deck. UNC6671's entire model depends on employees not knowing what a legitimate help desk contact looks like, and closing that knowledge gap costs far less than the ransom this group has already collected from organizations that never closed it.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#unc6671#vishing#help-desk-scam#social-engineering#google-threat-intelligence#cryptocurrency-extortion