A sophisticated hacking campaign has targeted over 200 firms, including major financial institutions, by impersonating IT support staff to steal multi-factor authentication (MFA) credentials. The campaign, tracked by Google Threat Intelligence Group (GTIG) as UNC6671, has operated under several names, including Redact, Pink, Falcon, and Helix, and has been linked to the BlackFile extortion brand.
The attackers employ voice phishing (vishing) techniques, calling employees on their personal mobile phones while posing as the company's IT help desk. In some instances, they spoof the legitimate support number to enhance credibility. They create a false sense of urgency, directing victims to lookalike credential-harvesting websites, such as `[company].createssopasskey[.]com` or `[company].addssopasskey[.]com`, under the pretext of mandatory security migrations, such as enabling FIDO2 passkeys or updating MFA enrollment.
If an employee enters their credentials on these fake sites, the hackers harvest their password and then immediately solicit the second-factor passcode over the phone, hijacking the account before the call concludes. To evade detection, the attackers delete security alerts and password reset notifications from compromised accounts.
After gaining access, UNC6671 utilizes automated tools to exfiltrate data from cloud services like Microsoft 365 and Okta. The group's methods and infrastructure have remained largely consistent despite operating under various extortion brands, suggesting a close operational link between them.
GTIG's analysis indicates that UNC6671, despite announcing the alleged retirement of the BlackFile brand in May 2026, has diversified its operations across multiple extortion fronts. Bitcoin wallets linked to BlackFile received 141.65 BTC, valued at approximately $10.69 million, between January and May 2026. Ransom payments continued even after the publicized shutdown of the BlackFile leak site on May 11, 2026, with significant cashout events observed in late April and early May, confirming uninterrupted financial operations during the rebranding phase.
The attackers typically demand ransoms between $1 million and $3 million, often negotiating discounts of 50-75%. In over half of the tracked cases, victims paid an average ransom of around $750,000.
Targets are selected based on their perceived likelihood of paying to prevent the release of sensitive stolen data, making financial organizations, private equity firms, and law firms particularly attractive. Companies for which malicious subdomains were identified include Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody's. Other targeted entities include Uber, Zillow, Levi Strauss, and law firms such as Paul Hastings and Greenberg Traurig. Point72 Asset Management confirmed it was targeted, and sources indicated attempts against Two Sigma Investments and Citadel.
Greenberg Traurig stated that its security protocols prevented a data breach. Most other named firms either declined to comment or did not respond to inquiries.
Redact, one of the group names, explicitly stated on its darknet site that its hackers are "not politically or morally motivated." Falcon acknowledged an affiliation with Redact but denied any connection to Helix or Pink. The precise relationships between these various groups remain unclear to investigators, although they appear to share common infrastructure. The campaign has repeatedly shifted its focus across sectors, moving to wherever data is deemed valuable enough to generate a ransom payment.






