Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s, among

A sophisticated hacking campaign has targeted over 200 firms, including major financial institutions, by impersonating IT support staff to steal multi-factor authentication (MFA) credentials. The campaign, tracked by Google Threat Intelligence Group (GTIG) as UNC6671, has operated under several names, including Redact, Pink, Falcon, and Helix, and has been linked to the BlackFile extortion brand.
The attackers employ voice phishing (vishing) techniques, calling employees on their personal mobile phones while posing as the company's IT help desk. In some instances, they spoof the legitimate support number to enhance credibility. They create a false sense of urgency, directing victims to lookalike credential-harvesting websites, such as `[company].createssopasskey[.]com` or `[company].addssopasskey[.]com`, under the pretext of mandatory security migrations, such as enabling FIDO2 passkeys or updating MFA enrollment.
If an employee enters their credentials on these fake sites, the hackers harvest their password and then immediately solicit the second-factor passcode over the phone, hijacking the account before the call concludes. To evade detection, the attackers delete security alerts and password reset notifications from compromised accounts.
After gaining access, UNC6671 utilizes automated tools to exfiltrate data from cloud services like Microsoft 365 and Okta. The group's methods and infrastructure have remained largely consistent despite operating under various extortion brands, suggesting a close operational link between them.
GTIG's analysis indicates that UNC6671, despite announcing the alleged retirement of the BlackFile brand in May 2026, has diversified its operations across multiple extortion fronts. Bitcoin wallets linked to BlackFile received 141.65 BTC, valued at approximately $10.69 million, between January and May 2026. Ransom payments continued even after the publicized shutdown of the BlackFile leak site on May 11, 2026, with significant cashout events observed in late April and early May, confirming uninterrupted financial operations during the rebranding phase.
The attackers typically demand ransoms between $1 million and $3 million, often negotiating discounts of 50-75%. In over half of the tracked cases, victims paid an average ransom of around $750,000.
Targets are selected based on their perceived likelihood of paying to prevent the release of sensitive stolen data, making financial organizations, private equity firms, and law firms particularly attractive. Companies for which malicious subdomains were identified include Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody's. Other targeted entities include Uber, Zillow, Levi Strauss, and law firms such as Paul Hastings and Greenberg Traurig. Point72 Asset Management confirmed it was targeted, and sources indicated attempts against Two Sigma Investments and Citadel.
Greenberg Traurig stated that its security protocols prevented a data breach. Most other named firms either declined to comment or did not respond to inquiries.
Redact, one of the group names, explicitly stated on its darknet site that its hackers are "not politically or morally motivated." Falcon acknowledged an affiliation with Redact but denied any connection to Helix or Pink. The precise relationships between these various groups remain unclear to investigators, although they appear to share common infrastructure. The campaign has repeatedly shifted its focus across sectors, moving to wherever data is deemed valuable enough to generate a ransom payment.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]