Executive Summary
In early 2026, the financially motivated threat group UNC6671, operating under the 'BlackFile' brand, initiated a series of sophisticated voice phishing (vishing) attacks targeting employees' personal mobile devices. Posing as internal IT support, the attackers directed victims to fraudulent login portals designed to harvest credentials and multi-factor authentication (MFA) tokens. Utilizing adversary-in-the-middle (AiTM) techniques, UNC6671 gained unauthorized access to cloud environments, including Microsoft 365 and Okta, and exfiltrated sensitive data using automated scripts. The stolen information was then leveraged for extortion, with demands often reaching seven figures. (cloud.google.com)
This campaign underscores a significant shift in cyberattack methodologies, emphasizing the exploitation of human factors over technical vulnerabilities. The success of UNC6671's operations highlights the critical need for organizations to implement phishing-resistant MFA solutions and enhance employee awareness to mitigate social engineering threats. (cloud.google.com)
Why This Matters Now
The UNC6671 campaign exemplifies the evolving landscape of cyber threats, where attackers increasingly exploit human vulnerabilities through sophisticated social engineering tactics. As organizations continue to adopt cloud-based services, the importance of securing identity and access management systems becomes paramount to prevent unauthorized data access and potential extortion. (cloud.google.com)
Attack Path Analysis
UNC6671 initiated the attack by impersonating IT support in vishing calls to employees' personal phones, directing them to fake SSO portals to harvest credentials and MFA codes. With these credentials, the attackers registered their own devices for MFA, gaining persistent access to the victims' cloud environments. They then moved laterally within the cloud infrastructure, accessing various SaaS applications such as Microsoft 365, SharePoint, and OneDrive. Utilizing Python and PowerShell scripts, the attackers exfiltrated large volumes of sensitive corporate data. The stolen data was used to extort the victim organizations, with threats of public exposure if ransom demands were not met.
Kill Chain Progression
Initial Compromise
Description
UNC6671 conducted vishing attacks, impersonating IT support to direct employees to fraudulent SSO portals, capturing their credentials and MFA codes.
MITRE ATT&CK® Techniques
Spearphishing Voice
Valid Accounts
Credentials from Password Stores
Data from Cloud Storage
Automated Exfiltration
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security Awareness Training
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Awareness Training
Control ID: 500.14(b)
DORA – ICT Risk Management Framework
Control ID: Article 13
CISA ZTMM 2.0 – User Training and Awareness
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Primary target of UNC6671 vishing attacks seeking SaaS data access, requiring enhanced egress security and zero trust segmentation to prevent data exfiltration.
Investment Management/Hedge Fund/Private Equity
Specifically targeted by UNC6671 social engineering campaigns, vulnerable to encrypted traffic interception and lateral movement requiring multicloud visibility and anomaly detection.
Management Consulting
Professional services firms face elevated vishing risks targeting personal devices, necessitating threat detection capabilities and secure hybrid connectivity for client data protection.
Information Technology/IT
IT help desk impersonation attacks exploit sector credibility, requiring kubernetes security and cloud firewall capabilities to protect against command and control activities.
Sources
- UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Datahttps://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.htmlVerified
- Welcome to BlackFile: Inside a Vishing Extortion Operationhttps://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/Verified
- BlackFile hackers target retail, hospitality with vishing and data extortionhttps://www.scworld.com/brief/blackfile-hackers-target-retail-hospitality-with-vishing-and-data-extortionVerified
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platformshttps://thehackernews.com/2026/01/mandiant-finds-shinyhunters-using.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent credential theft via social engineering, it would likely limit the attacker's ability to exploit these credentials within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls and segmenting sensitive resources.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the attacker's ability to move laterally by enforcing strict segmentation and monitoring internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the attacker's ability to maintain command and control by providing centralized monitoring and management across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by enforcing strict outbound traffic policies.
While Aviatrix Zero Trust CNSF may not prevent the initial data exfiltration, it would likely limit the scope of data accessible to attackers, thereby reducing the potential impact of extortion attempts.
Impact at a Glance
Affected Business Functions
- Financial Transactions
- Client Data Management
- Document Management
- Customer Relationship Management
Estimated downtime: 7 days
Estimated loss: $500,000
Confidential client financial records, sensitive internal communications, and personally identifiable information (PII) of clients and employees.
Recommended Actions
Key Takeaways & Next Steps
- • Implement phishing-resistant MFA methods, such as FIDO2 tokens, to prevent unauthorized access through credential theft.
- • Enhance employee training programs to recognize and report vishing attempts and other social engineering tactics.
- • Deploy Zero Trust Segmentation to limit lateral movement within cloud environments, restricting access based on identity and context.
- • Utilize Multicloud Visibility & Control solutions to monitor and manage access across all cloud platforms, detecting anomalous activities.
- • Establish robust Egress Security & Policy Enforcement mechanisms to control and monitor data exfiltration attempts, preventing unauthorized data transfers.



