UNC6671 Vishing Attacks Hijack Personal Phones to Steal SaaS Data
A financially motivated threat cluster tracked as UNC6671 has intensified its voice phishing (vishing) operations against enterprise employees in financial services, private equity, and professional services sectors. According to Google Threat Intelligence Group (GTIG) and Mandiant, the actors impersonate internal IT help desk staff to pressure victims into completing so-called urgent security migrations. A notable evolution in tradecraft: UNC6671 frequently contacts targets on their personal mobile phones rather than corporate lines, exploiting the weaker security posture of personal devices to bypass enterprise monitoring.
The calls direct victims to spoofed login portals backed by adversary-in-the-middle (AitM) infrastructure that captures credentials and multi-factor authentication (MFA) tokens in real time. With authenticated sessions established, operators deploy automated Python and PowerShell scripts to enumerate and exfiltrate sensitive data from Microsoft 365 and Okta environments. Defenders should audit active session tokens immediately, enforce phishing-resistant MFA such as FIDO2 hardware keys, and start with our password checker to verify that no employee credentials have been compromised in prior campaigns.
UNC6671 has cycled through multiple data leak site (DLS) brands since emerging in early January 2026. The group initially operated as BlackFile (CL-CRI-1116) before retiring that name on May 11, 2026, subsequently launching Redact, Pink (CL-CRI-1147), Helix, and Falcon (CL-CRI-1182) sites. On May 31, 2026, the Pink DLS went live; by June 27, 2026, Redact operators publicly accused a former associate of hijacking the originalFile brand for unsanctioned extortion. CrowdStrike tracks the umbrella collective as Cordial Spider, while GTIG assesses UNC6671's tradecraft as independent of—though stylistically similar to—ShinyHunters (Bling Libra).
The campaign underscores that human trust, not product vulnerabilities, remains the primary attack surface. Organizations should treat any unsolicited call requesting MFA approval or credential entry with extreme suspicion, particularly when the caller references personal contact details. Run a privacy checkup to review your personal exposure, confirm that DNS and routing are not being silently intercepted via a DNS leak test, and ensure SaaS accounts are not leaking session data through covert AitM proxies.