Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

0
High
Threat Actor
Published: 08/06/2026 (08/06/2026, 20:07:24 UTC)
Source: Bleeping Computer

Description

A wave of cyberattacks targeting hedge funds, private-equity firms, and financial organizations has been linked to UNC6671, an extortion group associated with the BlackFile campaign. The attacks primarily use voice phishing (vishing) to trick employees into granting access to corporate systems, often by impersonating help desks and stealing credentials via adversary-in-the-middle phishing kits. After gaining access to Microsoft 365 or Okta single-sign-on accounts, attackers exfiltrate data from cloud services and delete security notifications to evade detection. The group has diversified its extortion operations under multiple public brands and has shifted targeting toward financial and legal sectors since mid-2026. Several major firms have reported attempted intrusions or attacks, with no confirmed data theft publicly disclosed. The group has extorted millions in Bitcoin payments since early 2026.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 20:26:31 UTC

Technical Analysis

UNC6671 is an extortion group linked to the BlackFile campaign that targets hedge funds, private-equity firms, and financial organizations using voice phishing (vishing) attacks. Attackers impersonate corporate help desks to trick employees into enrolling in fake security updates, stealing credentials and session cookies via adversary-in-the-middle phishing kits hosted on spoofed domains. Compromised Microsoft 365 or Okta single-sign-on accounts provide access to multiple cloud platforms, from which data is stolen and security alerts deleted. The group operates multiple extortion brands and has shifted focus to financial and legal sectors since July 2026. The group has extorted over $10 million in Bitcoin, with initial ransom demands around $3 million often settling near $750,000. Mandiant and Google Threat Intelligence Group track UNC6671 separately from similar groups like Scattered Spider. Several dozen organizations are currently being assisted due to compromises by UNC6671.

Potential Impact

The attacks enable unauthorized access to corporate cloud environments by stealing credentials and session cookies through vishing and phishing techniques. This access allows attackers to exfiltrate sensitive data from multiple cloud platforms and delete security notifications, increasing the risk of undetected data breaches and extortion. Financial organizations targeted include major hedge funds and private-equity firms, potentially exposing sensitive financial and client information. While some targeted firms have reported no evidence of data theft, the extortion group has successfully extracted millions in ransom payments from victims.

Defensive Guidance

No official patch or fix applies as this is a social engineering and credential theft campaign. Organizations should be aware of the vishing tactics used by UNC6671, including help desk impersonation and enrollment in fake security updates. Strengthening employee awareness and training against vishing attacks is critical. Monitoring for suspicious domain registrations and phishing kits impersonating corporate domains may help detect attacks. Use of strong multi-factor authentication methods resistant to interception and session cookie theft is recommended. Since this is a cloud environment compromise, securing single-sign-on configurations and monitoring for anomalous access is advised. Vendor advisories or official guidance from affected service providers should be consulted for additional mitigations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.79,"severitySource":"default","classifier":"rss-v2"}

Threat ID: 6a74edebbf8831d539431eb3

Added to database: 08/06/2026, 20:26:19 UTC

Last enriched: 08/06/2026, 20:26:31 UTC

Last updated: 08/07/2026, 03:57:45 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses