Actor Profile

UNC6671 is a financially motivated extortion group tracked by Google Threat Intelligence Group (GTIG) that operates under multiple public brands including BlackFile, Redact, Pink, Helix, and Falcon. The group first emerged as BlackFile in February 2025 targeting retail and hospitality sectors before pivoting to high-value financial targets in July 2026. GTIG assesses that a single core intrusion group drives the helpdesk vishing and cloud data theft operations across these various extortion brands. Between January and May 2026, GTIG tracked over $10.6 million USD in Bitcoin payments to group wallets, with initial demands reaching upwards of $3 million but typically settling around $750,000 USD after negotiations. The group rebranded from BlackFile to Redact in May 2026 while continuing operations under multiple affiliate brands.

TTPs (Tactics, Techniques, Procedures)

UNC6671 employs sophisticated social engineering through voice phishing (vishing) campaigns targeting employees on personal mobile phones while spoofing corporate helpdesks. Attackers impersonate IT support claiming victims need to enroll in passkeys or update multi-factor authentication settings. Victims are directed to adversary-in-the-middle (AiTM) phishing kits hosted on domains impersonating target companies that steal credentials and session cookies in real time. The group focuses on compromising Microsoft 365 and Okta single-sign-on (SSO) accounts to gain access to multiple linked cloud platforms through the SSO dashboard. Post-compromise, attackers deploy automated tools for mass data exfiltration from cloud services and delete security notifications and password-reset emails from compromised inboxes to maintain persistence and evade detection. The infrastructure and TTPs differ from Scattered Spider (UNC3944) despite similarities in helpdesk social engineering methods.

Targets & Patterns

UNC6671 initially targeted retail and hospitality organizations when emerging as BlackFile in February 2025, then expanded to manufacturing, healthcare, real estate, technology, and transportation sectors through early 2026. In July 2026, the group strategically pivoted to high-value financial sector targets including hedge funds, private-equity firms, major law firms, and financial-rating agencies. Confirmed victims include Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. The targeting shift reflects a focus on organizations with significant financial resources and sensitive data, likely to maximize extortion payouts. The financial sector presents attractive targets due to regulatory pressures around data breaches, reputational concerns, and the ability to pay substantial ransoms. Mandiant is currently assisting several dozen organizations compromised by UNC6671, indicating widespread victimization beyond publicly disclosed incidents.

Historical Context

BlackFile first emerged in February 2025 with attacks on retail and hospitality sectors. The group announced a rebrand to Redact in May 2026 while maintaining operations under multiple affiliate brands. The July 2026 targeting shift toward financial services represents a significant operational evolution, moving from diverse mid-tier targets to concentrated high-value financial sector victims. Between January and May 2026, the group demonstrated sustained operational tempo with over $10.6 million in tracked Bitcoin payments. The infrastructure and extortion network differ from Scattered Spider (UNC3944), despite both groups employing helpdesk vishing tactics, indicating UNC6671 represents a distinct threat cluster. The Falcon extortion brand disputed Mandiant's clustering in August 2026, claiming exclusive affiliation with Redact rather than shared infrastructure with Helix, Pink, or other named groups, suggesting potential internal fragmentation or operational security concerns within the broader UNC6671 ecosystem.

Defensive Recommendations

  • Implement robust employee security awareness training focused on vishing tactics, emphasizing verification of IT helpdesk requests through official channels before providing credentials or MFA codes, especially for calls to personal mobile devices
  • Deploy conditional access policies requiring device compliance and trusted network locations for SSO access to cloud platforms, limiting the effectiveness of stolen session cookies from external networks
  • Enable comprehensive cloud audit logging and implement detection rules for anomalous SSO dashboard access patterns, automated data exfiltration tools, and deletion of security notifications or password-reset emails from user inboxes
  • Enforce phishing-resistant authentication methods such as FIDO2 hardware security keys or passkeys that cannot be intercepted by adversary-in-the-middle phishing kits, particularly for privileged accounts with SSO access
  • Monitor for domain registration patterns mimicking corporate infrastructure and implement DNS filtering to block access to newly registered domains impersonating the organization's helpdesk or authentication portals