"While previously operating under the public brand ‘BlackFile,’ UNC6671 has diversified its extortion operations across multiple public brands, including Redact, Pink, Helix, and Falcon," Austin Larsen, a principal threat analyst at Google’s Threat Intelligence Group (GTIG), told BleepingComputer.
How UNC6671 gains access: vishing into cloud accounts
According to GTIG and reporting cited by BleepingComputer, the group tracked as UNC6671 uses voice-phishing (vishing) to reach employees on their personal mobile phones while impersonating corporate help-desks. Attackers tell targets they must enroll passkeys or update multi-factor authentication settings, then send them to domains that impersonate the employee's company. Those sites host adversary-in-the-middle phishing kits that capture credentials and session cookies in real time.
Once attackers steal Microsoft 365 or Okta single-sign-on (SSO) accounts, they log into the SSO dashboard to gain access to all cloud platforms linked to that account. The operators then use automated tools to extract data from cloud services and delete security notifications and password-reset emails from compromised inboxes, according to the technical description provided to BleepingComputer.
Who has been targeted and how reporting has unfolded
Reuters and Bloomberg reported that hedge funds and private-equity firms, including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel, were among organizations targeted in recent vishing-driven attempts. Point72 reportedly told investors it had been attacked but had not found evidence that client data was stolen. Two Sigma said it had blocked an attempted intrusion and found no indication that its systems or data were affected. Millennium declined to comment in response to questions from BleepingComputer. Citadel declined to comment and referred BleepingComputer to Bloomberg’s reporting. Separately, BleepingComputer noted that Point72 and Two Sigma did not respond to requests for comment.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageExtortion network, brands, and payments tracked by GTIG
GTIG traces the activity to UNC6671 and says the core intrusion group operates under multiple public extortion brands. GTIG’s Austin Larsen told BleepingComputer that the group previously operated under the BlackFile brand and has since diversified into brands named Redact, Pink, Helix, and Falcon. GTIG assesses that a single core intrusion group is driving the helpdesk vishing and cloud data theft across these public extortion brands.
GTIG also quantified financial flows tied to the campaign: "Between January and May 2026, GTIG tracked over $10.6 million USD in Bitcoin payments to group wallets," Larsen said. He added that initial demands reach upwards of $3 million, while operators routinely settle for around $750,000 USD after negotiations.
Mandiant’s findings and how UNC6671 compares to Scattered Spider
Mandiant’s reporting, cited by BleepingComputer, links the public BlackFile activity to a group that first emerged in February 2025 with attacks against retail and hospitality organizations. Mandiant reports a targeting shift in July 2026 toward private-equity firms, hedge funds, major law firms, and financial-rating agencies after previously focusing on manufacturing, healthcare, real-estate, technology, transportation, and hospitality sectors.
Mandiant also told BleepingComputer that the infrastructure and extortion network used by UNC6671 differ from those historically associated with Scattered Spider (UNC3944), even though both have used help-desk social-engineering and authentication interception tactics. Mandiant said it is currently assisting several dozen organizations compromised by UNC6671.
What this means for security teams, affected enterprises, and UNC6671 itself
- Security teams: The attack chain emphasizes compromise via SSO and session cookies rather than only stolen passwords. Detection and response efforts that focus on SSO dashboards, cookie replay protections, and monitoring for unusual cloud-service access will be directly implicated by the techniques described.
- Affected enterprises (hedge funds, private-equity firms, law firms): Firms targeted in the reported wave have varying public responses: Point72 told investors it found no evidence of client-data theft; Two Sigma reported blocking an attempted intrusion with no indication systems were affected; several firms declined or deferred comment to BleepingComputer. Those responses illustrate uneven public disclosure even as firms engage incident response and, in some cases, external assistance from Mandiant.
- UNC6671 (the extortion operators): GTIG’s tracking of multi-brand activity and the Bitcoin flow figures suggest the group has shifted to a diversified extortion model and has achieved measurable financial returns between January and May 2026, according to the figures provided to BleepingComputer.
The record laid out by GTIG and Mandiant shows a single intrusion core using social-engineered phone calls, adversary-in-the-middle phishing, and SSO compromise to reach across cloud estates — and settling extortion demands that, on average, land far below initial demands. Mandiant’s involvement with several dozen victims and GTIG’s tracking of multimillion-dollar Bitcoin payments make clear that this campaign is operational and financially consequential. The remaining questions — including how widely the multi-brand model will spread and whether defenses will adjust quickly enough to limit cloud access via compromised SSO — will determine whether UNC6671’s pattern becomes the new normal for extortion-driven data theft.
Source: BleepingComputer — Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group




