Leadership1 distinct publisher3 min readUpdated
Google says the BlackFile crew has targeted dozens of organisations by phoning staff and posing as internal IT. No vendor bug is involved, which puts the remedy on IT leadership.
The Board Room · Leadership desk
Compiled by The Board RoomSomething wrong?How this is made
An extortion group that Google Threat Intelligence Group tracks as UNC6671, operating under the "BlackFile" brand, is getting into corporate cloud estates by telephoning employees and impersonating internal IT or help desk staff, then relaying their credentials and multi-factor codes to the real single sign-on portal in real time [1][2][7]. GTIG states plainly that these compromises are not the result of a security vulnerability in vendor products or infrastructure [3], which means there is nothing to patch and no product to buy your way out of: what failed is an identity-verification procedure that IT leadership owns.
The scale is not trivial. GTIG says the group emerged in early 2026, has kept a high operational cadence, and has targeted dozens of organisations across North America, Australia and the UK [4]. The callers are hired hands rather than the operators themselves [5], and they frequently ring employees on their personal mobile phones, which both bypasses corporate security tooling and moves the conversation away from standard support channels [6].
The pretext is the part worth reading twice. According to GTIG, callers cite a mandatory migration to passkeys or a required MFA update, which justifies sending the employee to a credential harvesting page and supplies cover for any security alerts the compromise generates [8]. The group has moved from bespoke per-victim domains to a subdomain model, typically registered with Tucows, using themes such as "passkey" and "enrollment" [9]; the three templates GTIG published are organisation-prefixed subdomains of enrollms, passkeyms and setupsso [10], all three of which describe an identity-enrolment errand rather than a login [11]. In other words, your own identity roadmap is the script.
Mechanically, the call runs as an adversary-in-the-middle session: the victim lands on a lookalike SSO subdomain, the attacker submits the captured username and password to the legitimate provider, and the resulting push, SMS or TOTP challenge is approved by a victim who believes they are completing a setup step [7]. The attacker then goes straight to the account's security settings and registers a new attacker-controlled MFA device for persistence [12], fast enough, GTIG says, to establish a foothold before the user or the security operations centre spots the anomaly [13]. From there the group moves laterally across SaaS applications, concentrating on Microsoft 365 and Okta and reaching SharePoint and OneDrive [14], and uses Python and PowerShell to exfiltrate data programmatically for extortion [2].
One governance detail matters for anyone who has to brief a board mid-incident: UNC6671 has co-opted the ShinyHunters name in at least one case to lend its threats artificial credibility, while GTIG assesses the two operations are independent on the basis of separate TOX channels, distinct domain registration patterns, and a dedicated BlackFile leak site [15]. The name in the extortion note is marketing, not attribution.
Three things to watch. Whether your help desk can prove its identity to an employee, rather than only the reverse, since the attack depends on a caller sounding official on a personal phone [6][8]. Whether new MFA device registrations generate an alert an analyst actually sees within minutes, given how quickly the attacker adds one [12][13]. And whether announcements of passkey projects reach staff before the vishing callers reference them; GTIG's own recommendation is to move to phishing-resistant MFA for SaaS and identity platforms [16].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Since emerging in early 2026, UNC6671 has maintained a high operational cadence, and GTIG assesses the group has targeted dozens of organizations across North America, Australia and the UK.
Google Threat Intelligence Group (GTIG) tracks an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, targeting organizations via voice phishing (vishing) and single sign-on (SSO) compromise.
UNC6671 uses adversary-in-the-middle techniques to bypass perimeter defences and MFA, primarily targets Microsoft 365 and Okta infrastructure, and uses Python and PowerShell scripts to programmatically exfiltrate sensitive corporate data for subsequent extortion.
GTIG states these compromises are not the result of a security vulnerability in vendor products or infrastructure, but instead highlight the effectiveness of social engineering.
The vishing calls used for initial access are typically made by "callers" hired by the threat actor.
The callers often call targeted employees' personal cellular phones to bypass security tooling and move the victim away from standard support channels, masquerading as internal IT or help desk personnel.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed first-party incident findings, single vendor
The account is granular and operationally checkable: a step-by-step AiTM lifecycle, named credential harvesting domain templates and registrar, specific exfiltration tooling, and a concrete logging artefact (FileAccessed versus FileDownloaded). It reads as derived from GTIG's own engagements. It is nonetheless one publisher with no independent corroboration, no victim identification and no quantified success or dwell-time data, which caps the score.
Technique observed in dozens of environments, one telemetry set
Real-world use is documented rather than hypothetical: repeatable subdomain infrastructure, scripted exfiltration seen in multiple engagements, and a live data leak site. But the reach rests entirely on GTIG's own assessment of "dozens" of targeted organizations, with no victim disclosures, no per-region counts and no outside telemetry, so this sits well below broadly corroborated campaign visibility.
Mostly proportionate, scale framing outruns disclosed proof
The technical body is restrained and specific, and GTIG deflates the obvious sensational angle by stating no vendor vulnerability is involved. The mild overstatement is in the framing: "expansive" campaign and "dozens of organizations" are single-source assessments with no victim, outcome or success-rate data, and the closing prescription of phishing-resistant MFA is presented as the remedy without any account of rollout cost or of the help desk verification procedures that would have to accompany it.
Vendor-authored intel with aligned product interest
The single source is Google's own threat intelligence group publishing on Google Cloud's blog. The report's central recommendation - move to phishing-resistant MFA and better identity and SaaS monitoring - maps directly onto commercial offerings from the publisher, and the explicit statement that no vendor product vulnerability is involved is also comfortable for the identity platforms named. Disclosure of specific indicators and detection guidance is a genuine public good that partly offsets this, so the reading is material but not disqualifying.
Credible primary account, unverifiable outside it
Confidence is moderate: the mechanics are internally consistent, specific and consistent with widely documented AiTM vishing tradecraft, and they come from the party that ran the investigations. The limiting factors are structural - one publisher, one telemetry set, a commercially aligned author, and no independent check on the scale claim or on the outcomes for targeted organisations.
leadership
UNC6671 did not retire: four brands, one helpdesk script, and calls to personal phones1 distinct publisher
product
RingCentral lost 1.6 million records to a phone call, not a missing patch1 distinct publisher
build
Three permission problems wearing one service principal: why published agents return 4031 distinct publisher
security
ClickFix operators install the signed Deno runtime to run their remote JavaScript1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026