Skip to content

Leadership1 publisher3 min readPublished

UNC6671 did not retire: four brands, one helpdesk script, and calls to personal phones

Google Threat Intelligence Group says the crew behind BlackFile spread into Redact, Pink, Helix and Falcon while keeping the same vishing route into Microsoft 365 and Okta.

The Board Room · Leadership desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026.
  • Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon.
  • UNC6671 relies on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations.
  • The threat actor often contacts employees via their personal mobile devices.
  • The calls lure victims to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

Google Threat Intelligence Group says it is still tracking UNC6671 running data theft extortion despite the announced retirement of the BlackFile extortion brand in May 2026, and that telemetry and infrastructure analysis show the crew diversified rather than disbanded, across Redact, Pink, Helix and Falcon [1][2]. The operational point has nothing to do with malware: the entry vector is a phone call to one of your employees, often on their personal mobile, from someone posing as IT helpdesk running a mandatory, urgent security migration [3][4].

What happens next is the part worth reading twice. The call steers the employee to a spoofed login portal where adversary-in-the-middle infrastructure intercepts both credentials and MFA tokens [5]. Once session persistence is established, the actors run automated scripts to exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta [6]. MFA is not absent in these intrusions; it is present, harvested in transit, and stepped over. The control that actually decides the outcome is whether a human being can be talked into authenticating on demand, and whether your helpdesk identity process is impersonable by a stranger with a phone number.

The infrastructure reads like a service business. UNC6671 hosts credential harvesting panels on generic root domains masquerading as passkey-related, then appends victim-specific subdomains for each targeted campaign [7]. GTIG cites the Falcon brand using the root domain passkeyhelpdesk[.]com [8]. Because those root domains are reused across multiple target organisations rather than kept isolated per victim, they create a traceable chain linking the brands [9], and overlaps in phishing templates, victimology and shared infrastructure conduits support the assessment that one group of actors sits behind BlackFile, Redact, Pink, Helix and Falcon [10]. GTIG hedges honestly: splintered affiliates or shared phishing-as-a-service infrastructure are also plausible readings [11].

The rebrand story is instructive about who the audience really is. On June 27, 2026, Redact operators published a post on their new leak site claiming the BlackFile brand had been compromised and hijacked by an exiled affiliate running a lookalike leak site and unsanctioned extortion under unlinked Tox identities [12][13]. That rogue affiliate, Redact claimed, deliberately orchestrated the May 2026 shutdown to sow confusion among threat intelligence analysts and cyber insurance negotiators and damage the brand's reputation [14]. Redact said it introduced a single verified Tox ID and PGP key to authenticate future correspondence, and denied that pressure from rival groups drove the change [15][16]. Roughly a month separated the claimed shutdown from the relaunch post [2]. Groups that manage brand equity for the benefit of insurance negotiators are not groups whose retirement announcements belong in a risk register.

Targeting has moved with the money: GTIG notes recent activity focused on financial services, private equity and professional services [17].

Three things to watch. Whether your helpdesk can establish identity without trusting an inbound contact, given that the impersonation is of your own helpdesk [3]. Whether contact on personal devices is treated as non-authoritative by default, since that is where the calls often land [4]. And whether the SaaS estate has detection for scripted bulk export after a valid session appears, because that is the step where data leaves [6]. GTIG's update includes hardening guidance alongside the infrastructure linkages [18]; the write-up is by Tyler McLellan and Austin Larsen [19]. Five brands have now carried this same playbook [1].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories