Leadership1 publisher3 min readPublished
The extortion call now comes from your help desk, and the fix is a procedure you own
Google says the BlackFile crew has targeted dozens of organisations by phoning staff and posing as internal IT. No vendor bug is involved, which puts the remedy on IT leadership.
The Board Room · Leadership desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Google Threat Intelligence Group (GTIG) tracks an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, targeting organizations via voice phishing (vishing) and single sign-on (SSO) compromise.
- UNC6671 uses adversary-in-the-middle techniques to bypass perimeter defences and MFA, primarily targets Microsoft 365 and Okta infrastructure, and uses Python and PowerShell scripts to programmatically exfiltrate sensitive corporate data for subsequent extortion.
- GTIG states these compromises are not the result of a security vulnerability in vendor products or infrastructure, but instead highlight the effectiveness of social engineering.
- Since emerging in early 2026, UNC6671 has maintained a high operational cadence, and GTIG assesses the group has targeted dozens of organizations across North America, Australia and the UK.
- The vishing calls used for initial access are typically made by "callers" hired by the threat actor.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
An extortion group that Google Threat Intelligence Group tracks as UNC6671, operating under the "BlackFile" brand, is getting into corporate cloud estates by telephoning employees and impersonating internal IT or help desk staff, then relaying their credentials and multi-factor codes to the real single sign-on portal in real time [1][2][7]. GTIG states plainly that these compromises are not the result of a security vulnerability in vendor products or infrastructure [3], which means there is nothing to patch and no product to buy your way out of: what failed is an identity-verification procedure that IT leadership owns.
The scale is not trivial. GTIG says the group emerged in early 2026, has kept a high operational cadence, and has targeted dozens of organisations across North America, Australia and the UK [4]. The callers are hired hands rather than the operators themselves [5], and they frequently ring employees on their personal mobile phones, which both bypasses corporate security tooling and moves the conversation away from standard support channels [6].
The pretext is the part worth reading twice. According to GTIG, callers cite a mandatory migration to passkeys or a required MFA update, which justifies sending the employee to a credential harvesting page and supplies cover for any security alerts the compromise generates [8]. The group has moved from bespoke per-victim domains to a subdomain model, typically registered with Tucows, using themes such as "passkey" and "enrollment" [9]; the three templates GTIG published are organisation-prefixed subdomains of enrollms, passkeyms and setupsso [10], all three of which describe an identity-enrolment errand rather than a login [11]. In other words, your own identity roadmap is the script.
Mechanically, the call runs as an adversary-in-the-middle session: the victim lands on a lookalike SSO subdomain, the attacker submits the captured username and password to the legitimate provider, and the resulting push, SMS or TOTP challenge is approved by a victim who believes they are completing a setup step [7]. The attacker then goes straight to the account's security settings and registers a new attacker-controlled MFA device for persistence [12], fast enough, GTIG says, to establish a foothold before the user or the security operations centre spots the anomaly [13]. From there the group moves laterally across SaaS applications, concentrating on Microsoft 365 and Okta and reaching SharePoint and OneDrive [14], and uses Python and PowerShell to exfiltrate data programmatically for extortion [2].
One governance detail matters for anyone who has to brief a board mid-incident: UNC6671 has co-opted the ShinyHunters name in at least one case to lend its threats artificial credibility, while GTIG assesses the two operations are independent on the basis of separate TOX channels, distinct domain registration patterns, and a dedicated BlackFile leak site [15]. The name in the extortion note is marketing, not attribution.
Three things to watch. Whether your help desk can prove its identity to an employee, rather than only the reverse, since the attack depends on a caller sounding official on a personal phone [6][8]. Whether new MFA device registrations generate an alert an analyst actually sees within minutes, given how quickly the attacker adds one [12][13]. And whether announcements of passkey projects reach staff before the vishing callers reference them; GTIG's own recommendation is to move to phishing-resistant MFA for SaaS and identity platforms [16].