Hedge Fund Vishing Attacks Traced to UNC6671, the Group Behind the BlackFile Brand

Google's threat researchers say one core crew is running help-desk phone scams that have hit Point72, Citadel, Two Sigma and Millennium, then stealing data straight from their cloud accounts.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A telephone headset positioned next to a computer screen displaying cloud account access logs, representing the vishing attacks that preceded data theft from ma
Share

Key points

  • Google's Threat Intelligence Group has linked recent attacks on Point72, Millennium, Two Sigma and Citadel, plus several private-equity firms, to an extortion crew it tracks as UNC6671, previously known publicly as BlackFile.
  • The attackers phone employees pretending to be the company help desk, then direct them to fake login pages that steal passwords and active session tokens in real time.
  • Between January and May 2026, Google tracked more than $10.6 million in Bitcoin paid to wallets tied to the group.
  • Initial ransom demands reach $3 million, but operators typically settle around $750,000 after negotiation.
  • Mandiant, Google's incident response arm, says it's currently helping several dozen breached organisations.

A single extortion crew is behind the recent run of attacks on some of the biggest names in finance, according to Google's Threat Intelligence Group (GTIG).

GTIG says it tracks the activity as UNC6671, the same operators who ran the "BlackFile" extortion brand when it first appeared in February 2025. Since then the group has rotated into at least four new public-facing names: Redact, Pink, Helix, and Falcon. We've tracked three of those pivots since our first BlackFile story on 9 July, including the Microsoft 365 session-theft campaign reported a day later.

The named targets are heavy hitters. Point72 Asset Management told investors it had been attacked but found no evidence client data was taken. Two Sigma said it blocked the attempt entirely.

"While previously operating under the public brand 'BlackFile,' UNC6671 has diversified its extortion operations across multiple public brands," Austin Larsen, a principal threat analyst at GTIG, told BleepingComputer. "GTIG assesses that a single core intrusion group is driving the helpdesk vishing and cloud data theft across these various public extortion brands."

Noteworthy too: Mandiant's report says the group's focus shifted in July 2026 toward private-equity firms, hedge funds, major law firms and financial-rating agencies, having previously worked across manufacturing, healthcare, real-estate and hospitality sectors.

How are the hackers getting in?

They're calling employees on personal phones and impersonating the company help desk. This is voice phishing, or vishing: a phone-based scam where the caller pretends to be someone the victim would normally trust.

The pretext barely varies. Employees are told they need to re-enrol a passkey (a phone or hardware-based login credential) or refresh their multi-factor authentication, the secondary verification layer sitting on top of a password.

From there, the victim is sent to a site that looks like their employer's login page but isn't. It runs an adversary-in-the-middle phishing kit, software that sits between the victim and the real login page, silently copying the password and the active session cookie as they're entered.

That session cookie is the real target. It's the small file a browser holds after login that tells a website this person is already authenticated. A fresh stolen cookie lets the attacker bypass both the password and the second-step code entirely.

What happens after they get in?

Once inside a Microsoft 365 or Okta single sign-on account (one credential that unlocks dozens of connected work apps), the attackers access the dashboard and pull data from every linked cloud service. Automated tools handle the copying. Security alerts and password-reset emails are deleted from the victim's inbox to buy time before anyone notices.

Then comes the demand.

Detail Figure
Bitcoin paid to group wallets, Jan to May 2026 $10.6 million
Typical opening ransom demand Up to $3 million
Typical settled amount Around $750,000
Organisations Mandiant is currently helping Several dozen
First BlackFile activity observed February 2025

GTIG notes the tactics resemble those of Scattered Spider, tracked as UNC3944, which also calls help desks. The infrastructure, domain registration patterns and extortion network are distinct enough, though, that Google treats UNC6671 as a separate operation.

Should you worry?

If you work in finance or at any large employer, yes. An unexpected call from your "IT help desk" asking you to reset a passkey or approve a login should be treated as suspect until you've verified it on a number you already know. That one habit defeats nearly every attack in this campaign.

The funds affected so far maintain that client data wasn't taken. With Mandiant working through dozens of active cases, that picture could still change.

© 2026 Threat Vectr