UNC3753 Hit U.S. Professional Services Firms With Vishing and Walk-In Intrusions
Dozens of legal, financial, and consulting firms were hit between January and May 2026 in a data-theft extortion run that blended phone-based social engineering with physical site visits.

A financially motivated crew tracked as UNC3753 spent the first five months of 2026 working its way through U.S. professional services firms — legal, financial, and consulting outfits — using phone calls and, in some cases, physical visits to offices.
Google Mandiant and the Google Threat Intelligence Group attributed the activity, which ran January through May 2026 and hit dozens of organizations.
The playbook is unglamorous. Operators called help desks and end users, talked their way past identity checks, and walked off with credentials or session tokens. Where phones didn't work, the group reportedly showed up in person. No zero-days. No exotic malware. Just process failures, exploited patiently.
Once inside, the goal was data — not encryption.
UNC3753 staged and exfiltrated files from corporate environments, then moved to extortion: pay, or the data gets published. That places the group in the same operational lane as Scattered Spider and the broader cluster of English-speaking social-engineering crews that have dominated incident response queues for the past two years.
The targeting is notable. Professional services firms hold concentrated client data — privileged legal correspondence, M&A diligence, tax filings, beneficial-ownership records — that carries leverage well beyond the breached firm itself. A single law firm compromise can cascade into client notifications across dozens of corporates.
Neither Mandiant nor GTIG has named victims publicly. The campaign window suggests notification letters will begin landing with state attorneys general over the coming weeks, with the New York Department of Financial Services and California AG likely to see the heaviest volume given the sector concentration. The FTC retains jurisdiction over Safeguards Rule failings at non-bank financial firms, and breach-notification obligations under state law are triggered regardless of whether ransomware was deployed.
Defenders should treat help desk and reception desks as Tier 1 attack surface.
What affected users should do:
- If you're a client of a law firm, accounting practice, or boutique financial advisor that issues a notice, ask specifically which document repositories were accessed and whether matter files tied to your account were among the exfiltrated set. "An unauthorized third party accessed our systems" is not a sufficient answer.
- Rotate any portal credentials shared with the affected firm, and assume documents you uploaded — tax records, IDs, deal terms — are in attacker hands.
- Place a fraud alert or credit freeze if Social Security numbers or financial account numbers were in scope.
- Watch for follow-on vishing. Crews that breach professional services firms routinely reuse stolen correspondence to impersonate partners and request wire changes from clients.
Firms in the sector should pull help desk call recordings from the January–May window, audit any out-of-band identity verification overrides, and confirm whether physical visitor logs match badge access events.



