“We have seen continued targeting against the financial sector with additional targeting of other organizations including in the med tech space,” Austin Larsen, principal threat analyst at GTIG, told CyberScoop.
BlackFile, UNC6671, and its link to The Com
Researchers identify the extortion group operating against financial firms and other sectors as BlackFile. Google Threat Intelligence Group (GTIG) tracks the cluster as UNC6671 and associates it more broadly with an actor referenced as The Com. GTIG and other commercial responders describe BlackFile as active since the start of the year and shifting its focus from sector to sector while maintaining a steady pace of activity.
Four brands and shared infrastructure: Redact, Pink, Helix and Falcon
BlackFile has split extortion operations across four named brands — Redact, Pink, Helix and Falcon — while using shared infrastructure, according to Google. Several organizations received new extortion demands from Redact in the most recent week. GTIG researchers told CyberScoop that the brands are run by the same threat cluster; Austin Larsen estimated fewer than a dozen core operators manage the different brands even if different people sometimes operate each brand.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTechniques: voice-phishing, social engineering, and escalation
The group’s initial access method centers on impersonating IT support in voice-phishing and social engineering calls. Attackers recruit hundreds of callers — often lower-level people paid a small fee or offered an opportunity to earn goodwill with the group — to make the calls and obtain access. Once access is gained, the group applies data-theft extortion; their demands typically begin near $3 million and, in several recent cases, were negotiated down to less than $1 million, Google reported.
Beyond monetary demands, escalation tactics include threatening messages and swatting incidents — the latter a tactic used by several subsets of The Com, Google said. Flashpoint researchers additionally observed malicious infrastructure that they tied to targeting of named financial firms, though they emphasized it was unclear whether those firms had been compromised.
Targets and scale: large organizations across multiple sectors
BlackFile’s victims include private equity firms, law firms, and financial rating agencies, and the group has impacted organizations in healthcare, technology, transportation, logistics, wholesale, retail and hospitality. GTIG’s Larsen characterized the activity as “big-game hunting,” noting the group “does go after some of the largest organizations in the sectors that they go for. They’re not going after small companies.”
Researchers measured a steady cadence: on average about 1.5 new victims per day. Flashpoint named firms whose infrastructure was observed being targeted — Blackstone, Bain Capital, Moody’s, CME and Apollo — while noting the difference between observed targeting and confirmed compromise.
Mandiant and incident response: more than two dozen successful compromises
Mandiant incident responders report frequent encounters with BlackFile, having been engaged by more than two dozen organizations that the company says were successfully compromised by the group since January. Google said new victims in the financial sector contacted Mandiant for assistance earlier this month. Those engagements underline both the group’s reach and the role of commercial incident responders in addressing active extortion cases.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: Expect continued voice-phishing and social-engineering attempts that exploit human trust. The reported use of large numbers of recruited callers and a small core operator set suggests defensive work should focus on detection of post-access behavior and rapid incident response.
- Policymakers and regulators: The pattern of high-dollar extortion demands (starting around $3 million and often negotiated under $1 million) plus swatting escalations highlights cross-cutting harm that may interest financial regulators and law enforcement; researchers link the activity to a broader cluster identified as The Com.
- Affected enterprises and procurement leaders: BlackFile targets large organizations across finance, healthcare and other sectors, reinforcing that high-profile firms are in scope. The group’s use of shared infrastructure across named brands means organizations should treat activity attributed to Redact, Pink, Helix or Falcon as potentially related.
BlackFile’s campaign presents a clear pattern: loud, human-focused intrusion attempts run by a compact operator core, amplified by a far larger pool of callers and supported by shared infrastructure across multiple extortion brands. The facts reported by GTIG, Flashpoint and Mandiant leave several concrete questions for victims and defenders — foremost among them whether observed targeting of named financial firms led to compromise, and how many of the group’s recent demands resulted in payments despite several reported negotiations below $1 million. Answers to those questions will shape whether the current cadence of roughly 1.5 new victims a day continues or can be disrupted.




