Leadership1 distinct publisher3 min readUpdated
Google Threat Intelligence Group says the crew behind BlackFile spread into Redact, Pink, Helix and Falcon while keeping the same vishing route into Microsoft 365 and Okta.
The Board Room · Leadership desk
Compiled by The Board RoomSomething wrong?How this is made
Google Threat Intelligence Group says it is still tracking UNC6671 running data theft extortion despite the announced retirement of the BlackFile extortion brand in May 2026, and that telemetry and infrastructure analysis show the crew diversified rather than disbanded, across Redact, Pink, Helix and Falcon [1][2]. The operational point has nothing to do with malware: the entry vector is a phone call to one of your employees, often on their personal mobile, from someone posing as IT helpdesk running a mandatory, urgent security migration [3][4].
What happens next is the part worth reading twice. The call steers the employee to a spoofed login portal where adversary-in-the-middle infrastructure intercepts both credentials and MFA tokens [5]. Once session persistence is established, the actors run automated scripts to exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta [6]. MFA is not absent in these intrusions; it is present, harvested in transit, and stepped over. The control that actually decides the outcome is whether a human being can be talked into authenticating on demand, and whether your helpdesk identity process is impersonable by a stranger with a phone number.
The infrastructure reads like a service business. UNC6671 hosts credential harvesting panels on generic root domains masquerading as passkey-related, then appends victim-specific subdomains for each targeted campaign [7]. GTIG cites the Falcon brand using the root domain passkeyhelpdesk[.]com [8]. Because those root domains are reused across multiple target organisations rather than kept isolated per victim, they create a traceable chain linking the brands [9], and overlaps in phishing templates, victimology and shared infrastructure conduits support the assessment that one group of actors sits behind BlackFile, Redact, Pink, Helix and Falcon [10]. GTIG hedges honestly: splintered affiliates or shared phishing-as-a-service infrastructure are also plausible readings [11].
The rebrand story is instructive about who the audience really is. On June 27, 2026, Redact operators published a post on their new leak site claiming the BlackFile brand had been compromised and hijacked by an exiled affiliate running a lookalike leak site and unsanctioned extortion under unlinked Tox identities [12][13]. That rogue affiliate, Redact claimed, deliberately orchestrated the May 2026 shutdown to sow confusion among threat intelligence analysts and cyber insurance negotiators and damage the brand's reputation [14]. Redact said it introduced a single verified Tox ID and PGP key to authenticate future correspondence, and denied that pressure from rival groups drove the change [15][16]. Roughly a month separated the claimed shutdown from the relaunch post [2]. Groups that manage brand equity for the benefit of insurance negotiators are not groups whose retirement announcements belong in a risk register.
Targeting has moved with the money: GTIG notes recent activity focused on financial services, private equity and professional services [17].
Three things to watch. Whether your helpdesk can establish identity without trusting an inbound contact, given that the impersonation is of your own helpdesk [3]. Whether contact on personal devices is treated as non-authoritative by default, since that is where the calls often land [4]. And whether the SaaS estate has detection for scripted bulk export after a valid session appears, because that is the step where data leaves [6]. GTIG's update includes hardening guidance alongside the infrastructure linkages [18]; the write-up is by Tyler McLellan and Austin Larsen [19]. Five brands have now carried this same playbook [1].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon.
Redact claimed the original BlackFile brand had been compromised and hijacked by an exiled affiliate who operated an unauthorized lookalike data leak site and conducted unsanctioned extortion campaigns under their name using unlinked Tox identities.
Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026.
UNC6671 relies on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations.
The threat actor often contacts employees via their personal mobile devices.
The calls lure victims to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed first-party telemetry, single vendor
The cluster rests on one publisher, but that source is primary research: GTIG/Mandiant telemetry and infrastructure analysis with named root domains, per-brand bridging chains, data leak site figures and a reproduced criminal statement. Specificity is high; independent replication is absent, and the captured text is truncated mid-indicator list, so key detail and the hardening guidance cannot be fully checked.
Confirmed multi-brand victim activity, scale undisclosed
Real-world activity is concretely observed — victims listed across separate leak sites, a live Redact DLS launch, and shared infrastructure hitting organizations later extorted under two different brands — but the source gives no victim counts, ransom figures, or named affected organizations, so the footprint cannot be sized.
Close to source, attribution leans on one vendor
The cluster's headline framing — that UNC6671 did not retire and runs one helpdesk script across several brands — tracks the source closely, and the ledger preserves GTIG's own caveat about alternative explanations. The mild positive gap reflects that a five-brand single-actor conclusion, plus a narrative sourced from the criminals' own leak-site post, is presented as settled when it rests on unreplicated vendor telemetry and no disclosed scale.
Vendor research with product-adjacent hardening advice
The sole source is Google Cloud's own blog carrying GTIG/Mandiant bylines; the post frames itself as an update that supplies hardening guidance for cloud and identity environments Google sells intelligence and security services around. That is a normal and disclosed research-marketing posture, not concealment, but it is the only voice in the cluster and no disinterested party corroborates the attribution.
Credible primary research, unreplicated
Technical claims are specific and internally consistent, and the reporting entity is an established threat-intel group, which supports moderate confidence. Confidence is held back by single-publisher sourcing, a self-hedged attribution, no quantified victim data, reliance in part on adversary statements, and a truncated source body.
leadership
The extortion call now comes from your help desk, and the fix is a procedure you own1 distinct publisher
security
Mandiant found 100 high-severity bugs in two days. Plan for the other side doing the same.1 distinct publisher
invest
Rust's arrayref hijack lasted 86 minutes, and Wiz ties it to North Korea1 distinct publisher
security
Vishing gets a product tier: Okta finds kits that steer the victim's browser mid-call1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.