Hedge Fund Vishing Attacks Traced to UNC6671, the Group Behind the BlackFile Brand

Google's threat researchers say one core crew is running help-desk phone scams that have hit Point72, Citadel, Two Sigma and Millennium, then stealing data straight from their cloud accounts.

ThreatVectr Newsdesk· 4 min read
Full-frame photoreal editorial image of a dimly lit server room with rows of humming racks, one open cabinet showing a glowing blue cable bundle, subtle red war
Share

Key points

  • Google's Threat Intelligence Group has linked recent attacks on Point72, Millennium, Two Sigma, Citadel and several private-equity firms to an extortion crew it tracks as UNC6671, previously known publicly as BlackFile.
  • The attackers phone employees pretending to be the company help desk, then send them to fake login pages that steal passwords and active session tokens in real time.
  • Between January and May 2026, Google tracked more than $10.6 million in Bitcoin paid to wallets tied to the group.
  • Initial ransom demands reach $3 million, but operators typically settle around $750,000 after negotiation.
  • Mandiant, Google's incident response arm, says it is currently helping several dozen breached organisations.

A single extortion crew is behind the recent run of attacks on some of the biggest names in finance, according to researchers at Google.

Google's Threat Intelligence Group (GTIG) told BleepingComputer it tracks the activity as UNC6671, the same operators who ran the public "BlackFile" extortion brand earlier in the year. The group has since rotated through several new names: Redact, Pink, Helix and Falcon.

The victims are serious. Reuters and Bloomberg reported that Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel and several private-equity firms were targeted. Point72 told investors it had been attacked but found no sign client data was stolen. Two Sigma said it blocked the intrusion attempt.

"While previously operating under the public brand 'BlackFile,' UNC6671 has diversified its extortion operations across multiple public brands," Austin Larsen, a principal threat analyst at GTIG, said. "GTIG assesses that a single core intrusion group is driving the helpdesk vishing and cloud data theft across these various public extortion brands."

How are the hackers getting in?

They are calling employees on their personal phones and pretending to be the company help desk. This is called voice phishing, or vishing: a phone-based scam where a criminal impersonates someone the victim would normally trust.

The pretext is almost always the same. The caller tells the employee they need to re-enrol a passkey (a phone or hardware-based login) or update their multi-factor authentication, the second step, usually a code or app tap, that sits on top of a password.

The employee is then sent to a website that looks like their employer's login page. It is not. It is an "adversary-in-the-middle" phishing kit, which sits between the victim and the real login page and quietly copies the password and the active session cookie as the victim types.

That session cookie is the prize. It is the small file a browser holds after you log in that tells a website "this person is already signed in." Steal a fresh one and the attacker skips the password and the second-step code entirely.

What happens after they get in?

Once inside a Microsoft 365 or Okta single sign-on account (one login that opens the door to dozens of connected work apps), the attackers log into the dashboard and pull data from every cloud service linked to it. Automated tools do the copying. The attackers also delete security alerts and password-reset emails from the victim's inbox to buy time.

Then comes the extortion demand.

Detail Figure
Bitcoin paid to group wallets, Jan to May 2026 $10.6 million
Typical opening ransom demand Up to $3 million
Typical settled amount Around $750,000
Organisations Mandiant is currently helping Several dozen
First BlackFile activity observed February 2025

GTIG notes the tactics look a lot like Scattered Spider, tracked as UNC3944, another crew known for calling help desks. But the infrastructure, domain patterns and extortion brands are different enough that Google treats UNC6671 as its own operation.

What should ordinary people watch for?

If you get an unexpected call from your "IT help desk" asking you to reset a passkey or approve a login on your phone, hang up and call your real IT team on a number you already know. That single habit defeats almost every attack in this campaign.

So far the funds involved say client data was not taken. That may change as Mandiant works through the dozens of active cases.

© 2026 Threat Vectr