Cybersecurity teams are warning about a wave of attacks linked to the threat cluster UNC6671, which has been focusing on financial services, private equity, and professional organizations. The common thread across recent incidents is a UNC6671 vishing campaign that uses voice phishing to reach employees—often by dialing their personal mobile numbers—and then steering them toward fraudulent access pages.
Rather than relying on software vulnerabilities, attackers are leaning on deception, urgency, and identity fraud. If your organization depends on SaaS apps and centralized identity providers, this is a reminder that attackers are increasingly targeting the human steps in login workflows.
How the UNC6671 vishing campaign works
According to reporting from major threat-intelligence teams, the attackers impersonate IT help desk staff. They contact employees with a message about an urgent “mandatory” security migration, creating pressure to act quickly.
The calls are then designed to move victims to a spoofed login portal. That portal is built to capture authentication details and multi-factor authentication (MFA) artifacts in real time.
Credentials and MFA tokens captured through AitM
Once a victim enters credentials and approves MFA, the criminal infrastructure acts as an adversary-in-the-middle (AitM) system. This approach enables the attacker to intercept not only logins but also MFA tokens, which are often the last barrier between an attacker and an authenticated session.
With those items in hand, attackers can keep access stable and continue operations without repeatedly triggering fresh authentication challenges.
From stolen authentication to SaaS data theft
After the initial compromise, the goal shifts from “getting in” to “taking out.” The reporting indicates that the attackers use automated scripting—specifically Python and PowerShell—to support data extraction from enterprise cloud environments and SaaS applications.
Targets named in the analysis include Microsoft 365 and Okta. Instead of treating each SaaS app as a separate battlefield, the attackers aim to establish a foothold at the identity layer and then move through the connected ecosystem.
Persistence via MFA device registration
In many cases, the attackers maintain ongoing access by registering adversary-controlled MFA devices to compromised accounts. Importantly, this often happens after removing existing MFA devices, reducing the chance that the organization will notice sudden authentication changes through expected recovery flows.
By abusing the trust relationships between an identity provider and connected services, the attacker can effectively reuse a single authenticated session across multiple SaaS applications.
Multiple extortion brands and why that matters
In addition to credential theft, UNC6671 is associated with data extortion activity. The cluster has been observed using multiple public-facing extortion brands. This branding sprawl can make investigation and attribution harder, while also supporting monetization through separate negotiation channels.
Examples cited include brands such as Redact, Pink (also identified under a different naming reference), Helix, and Falcon. A previously used brand, BlackFile, was reported as retired on May 11, 2026, with later messages indicating shutdown actions tied to that brand name.
A timeline of notable events included: UNC6671 appearing in early January 2026, a BlackFile-related data leak site launching on February 6, and going offline late April—followed by brand shutdown messaging in mid-May.
Why vishing is especially effective for SaaS ecosystems
Security teams often invest heavily in detecting phishing emails, but voice phishing changes the equation. When attackers call employees and impersonate help desk staff, the interaction feels legitimate—especially when the victim is told to complete a security migration or resolve an “account issue.”
Some analyses also point to tailored phishing kits and access controls that try to frustrate researchers and sandbox analysis. In other words, the campaign is not just socially engineered; it is engineered to keep credentials flowing.
Targeting personal phones to increase credibility
A key detail in the reporting is that calls frequently reach victims through their personal mobile devices, not only corporate lines. That reduces friction for the attacker and can increase victim trust—especially if the call display number is spoofed to resemble help desk contact information.
When victims see what looks like a legitimate help desk identity, they are more likely to follow instructions to visit a link that leads to an AitM capture page.
Other tactics supporting the campaign
Beyond the core vishing and fake portal flow, the reports describe additional behaviors that improve attacker success and help avoid detection.
- Credential-harvesting panels hosted on generic-looking domains that reference passkeys, MFA, or SSO.
- Victim-specific subdomains appended to support targeted voice phishing while associating each page with the specific victim context.
- Spoofed help desk calls that direct the employee to fraudulent AitM pages.
- Compromised email accounts used to trigger password resets for non-SSO applications, then remove password-reset confirmations and security alerts to reduce visibility.
This combination—social engineering plus operational cleanup—makes the campaign harder to detect with traditional controls.
Shifting victim footprint and monetization patterns
The reporting also notes changes in where the attackers focused over time. Incidents were described as moving from broad enterprise targets across multiple sectors to later campaigns aimed at technology, transportation, hospitality, and then high-value financial and legal organizations.
From a business perspective, the strategy includes monetary pressure. Initial ransom demands were described as reaching figures above $3 million, with reductions during negotiations ranging between 50% and 75% of the initial demand. In more than half of the tracked cases, a lower average settlement amount was reported.
Additionally, the tracking period highlighted large payments associated with the group, measured in Bitcoin, with the reporting citing over $10.6 million in tracked payments within a defined window.
How organizations can reduce risk
The most actionable takeaway is that the attack path centers on phishing and authenticated session capture, not on breaking vendor software. Organizations are urged to adopt controls that remain effective even when users are deceived.
- Enforce phishing-resistant MFA, so that attackers cannot reuse captured authentication factors.
- Integrate SaaS applications with SSO to reduce fragmented authentication paths that can be exploited in parallel.
- Implement session controls to limit how long and how broadly stolen sessions can be used.
- Restrict authentication to trusted networks where practical, and require stricter access conditions for sensitive actions.
- Use corporate-managed devices for access to identity and SaaS resources.
- Monitor IdP logs for suspicious MFA registration events, especially when new MFA devices appear unexpectedly.
- Deploy security tooling and alerting for signs that credential data is being entered into unauthorized or suspicious domains.
Together, these steps can reduce the chance that a single vishing call leads to lasting identity compromise.
Final thoughts
The UNC6671 vishing campaign illustrates a modern pattern: attackers combine human-targeted voice phishing with infrastructure designed to intercept authentication in real time. Once they gain a foothold at the identity layer, they can pivot into the broader SaaS environment and support automated data theft and extortion operations.
Organizations that strengthen identity defenses—especially phishing-resistant MFA, better session governance, and vigilant IdP monitoring—are more likely to stop these attempts before attackers can turn stolen credentials into sustained access.
Source: https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html
