Google Threat Intelligence Group is tracking UNC6671 as it continues data-theft extortion operations under multiple public brands, including Redact, Pink, Helix, and Falcon, despite earlier claims that the BlackFile brand had retired. The important part for defenders is not the name on the leak site. It is the repeatable intrusion pattern: helpdesk-style vishing, adversary-in-the-middle credential capture, cloud session persistence, and rapid SaaS data theft.
What Google reported
GTIG assesses that UNC6671 did not disappear when one extortion brand faded. Instead, the operators appear to have diversified across multiple data-leak identities while keeping a consistent technical baseline. Campaigns use tailored phone calls to employees, often on personal mobile devices, with callers posing as IT helpdesk staff managing urgent passkey, MFA, or SSO enrollment changes.
The target is then directed to a lookalike authentication portal built around convincing passkey, MFA, or SSO language. That infrastructure is designed to intercept credentials and multi-factor authentication tokens through adversary-in-the-middle phishing. Once access is established, the operators move into enterprise cloud services such as Microsoft 365 and Okta and use automation to steal data at SaaS scale.
GTIG also observed infrastructure overlaps tying multiple extortion brands together. Generic root domains themed around passkeys and helpdesk enrollment were reused across different victims and leak-site brands, suggesting either a common operator, shared phishing infrastructure, or closely related affiliate activity.
Why this matters to SMBs and government contractors
This is the kind of threat that bypasses a lot of “normal” security spending. A company can have MFA enabled, cloud email protected, and endpoint tools installed, but still lose data if the helpdesk workflow and cloud session controls are weak.
For small and mid-sized businesses, the risk is straightforward: attackers are targeting the human trust path around IT support. For government contractors, the stakes are higher because Microsoft 365, Okta, file shares, ticketing systems, CRM platforms, and legal or finance repositories can all hold CUI, contract records, personnel data, export-sensitive documents, or customer information.
UNC6671’s reported shift toward financial services, private equity, legal, and professional services also matters because those sectors often sit near high-value transactions, sensitive client data, and third-party access into larger organizations. A smaller firm can become the easier door into a much more valuable ecosystem.
Defensive takeaways
- Make helpdesk identity changes verifiable. Passkey enrollment, MFA reset, device enrollment, and SSO recovery should require a known internal process, not an inbound phone call. Train staff to hang up and call back through a trusted number.
- Move toward phishing-resistant MFA. FIDO2 security keys, platform passkeys, Windows Hello for Business, and Okta FastPass-style authenticators reduce the value of lookalike domains and AiTM phishing because authentication is cryptographically bound to the legitimate origin.
- Shorten and monitor cloud sessions. Long-lived SaaS sessions give attackers room to operate after a successful phishing event. Use conditional access, continuous access evaluation where available, and step-up authentication for sensitive repositories.
- Treat SaaS “file access” like potential exfiltration. Do not only alert on obvious download events. Scripted access patterns from unusual user agents, abnormal file-open volume, or suspicious geographic/network sources should be investigated quickly.
- Limit access to managed devices and trusted networks. Conditional access tied to MDM posture, EDR presence, SASE/VPN ranges, and device compliance makes it harder for stolen sessions to be reused from attacker infrastructure.
- Audit non-SSO applications. GTIG noted abuse of compromised mailboxes to reset passwords for apps outside centralized SSO. Any business-critical SaaS platform outside the identity provider becomes a soft target.
- Watch for helpdesk-themed domain patterns. Domains using passkey, MFA, SSO, enrollment, or helpdesk language paired with company-specific subdomains are strong hunting leads during active campaigns.
Bulwark Black assessment
UNC6671 is a good example of where modern extortion is headed: identity-first, cloud-native, and brand-flexible. The public ransomware-style name is less important than the playbook. If the same operators can keep using vishing, AiTM portals, and SaaS exfiltration under new labels, defenders need controls that break the workflow rather than controls that only chase the latest group name.
The priority for most organizations should be boring but effective: lock down helpdesk reset paths, enforce phishing-resistant MFA for high-risk users, require managed devices for cloud access, and build detections around abnormal SaaS data access. If those controls are missing, a single convincing phone call can become a full cloud data-theft incident.
