Published · 4d agoSecurity2 min read
1.5 new victims a day: BlackFile's entire entry path is a call to the help desk
The figure is a targeting rate reported by researchers, and it is produced by hundreds of hired callers running one repeatable IT-support pretext against employee mobile phones.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- BlackFile targets an average of 1.5 new victims daily, according to researchers cited by CyberScoop.
- BlackFile is tracked by Google Threat Intelligence Group as UNC6671 and associated more broadly with The Com; it has been active since the start of the year, shifting focus from one sector to the next.
- The extortion group impersonates IT support in voice-phishing and social engineering attacks and recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon.
- Mandiant incident responders have been engaged by more than two dozen organizations successfully compromised by the group since January.
- The attackers use hundreds of callers, often lower-level people recruited for a small fee or an opportunity to earn goodwill with the group, to make the voice phishing calls that obtain initial access; Austin Larsen of GTIG estimates fewer than a dozen core operators run the different brands under the BlackFile umbrella.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The number is a targeting rate, not a breach count: BlackFile, which Google Threat Intelligence Group tracks as UNC6671 and associates with The Com, goes after an average of 1.5 new victims a day, according to researchers cited by CyberScoop [1][2]. That is roughly ten a week, or about 45 over a month, and GTIG is explicit that these compromises are not the result of a vulnerability in any vendor product [14][7].
What sustains that cadence is labour, not tooling. GTIG's Austin Larsen told CyberScoop the group uses hundreds of callers, often lower-level recruits working for a small fee or for goodwill, while fewer than a dozen core operators run the brands above them [5]. The callers dial employees' personal cell phones to get outside corporate security tooling and away from the real support channel, posing as internal IT and citing a mandatory passkey migration or an MFA update [8]. The pretext doubles as cover for the alerts the intrusion will generate [8].
The rest is mechanical. The victim is sent to a lookalike SSO subdomain, credentials are relayed to the genuine provider in real time, the MFA challenge is passed back through the caller, and the attacker registers its own MFA device before the SOC notices [9]. Okta Threat Intelligence reports that phishing kits sold as a service now let a caller drive the victim's browser in sync with the script, which defeats any MFA that is not phishing-resistant [12].
The economics reward volume over precision. Demands often open around $3 million and are typically negotiated to under $1 million, a discount of more than two thirds [6][15]. Mandiant has been called in by more than two dozen successfully compromised organisations since January [4], and Larsen describes the target set as big-game hunting rather than small companies [16]. The extortion is now split across Redact, Pink, Helix and Falcon on shared infrastructure [3].
Two things would move the rate: phishing-resistant MFA at the identity layer [7][12], and a help-desk process that cannot be reached, or impersonated, on a personal phone [8].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
BlackFile targets an average of 1.5 new victims daily, according to researchers cited by CyberScoop.
- [2]
BlackFile is tracked by Google Threat Intelligence Group as UNC6671 and associated more broadly with The Com; it has been active since the start of the year, shifting focus from one sector to the next.
ReportedView cited source - [3]
The extortion group impersonates IT support in voice-phishing and social engineering attacks and recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon.
ReportedView cited source - [4]
Mandiant incident responders have been engaged by more than two dozen organizations successfully compromised by the group since January.
ReportedView cited source - [5]
The attackers use hundreds of callers, often lower-level people recruited for a small fee or an opportunity to earn goodwill with the group, to make the voice phishing calls that obtain initial access; Austin Larsen of GTIG estimates fewer than a dozen core operators run the different brands under the BlackFile umbrella.
- [6]
The group's extortion demands often start around $3 million and payments have typically been negotiated down to less than $1 million, according to Google.
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cyberscoop.com4d agoDetails emerge on BlackFile's recent attacks on financial companies | CyberScoop
- cloud.google.com4d agoWelcome to BlackFile: Inside a Vishing Extortion Operation | Google Cloud Blog



