Vishing extortion group UNC6671 rebrands after $10M ransoms

UNC6671 rebranded as Redact, Pink, Helix and Falcon after collecting over $10 million in Bitcoin from vishing attacks that targeted Microsoft 365 and Okta users.

UNC6671, a vishing extortion group, has rebranded as Redact, Pink, Helix and Falcon after collecting more than $10 million in Bitcoin. The group emerged in early 2026 and focused campaigns on Microsoft 365 and Okta single sign-on systems in North America, the United Kingdom and Australia.

Operators placed voice calls posing as IT helpdesk staff to contact employees, often on personal mobile phones, and claimed urgent security migrations to trick victims into signing into fake login portals. The actors used adversary-in-the-middle techniques to capture credentials and multi-factor authentication tokens, allowing access to cloud accounts.

The group registered generic root domains that hosted credential-harvesting pages and created subdomains that included victim names to make login pages appear legitimate. Observed domains include passkeyhelpdesk[.]com, portalpasskey[.]com, mysecurepasskey[.]com, addssopasskey[.]com, passkeydeploy[.]com and passkeyuser[.]com.

Google Threat Intelligence Group (GTIG) reported that UNC6671 retired the BlackFile extortion name in May and launched a Redact data leak site in June. GTIG found overlaps in infrastructure and techniques across the BlackFile, Redact, Pink, Helix and Falcon brands and noted that those overlaps suggest a common group may be linked to the different brands while allowing that splinter affiliates or shared phishing services could also explain the connections.

Between January and May the actors received more than $10 million in Bitcoin across 18 wallet addresses tied to extortion incidents. Initial ransom demands typically ranged from $1 million to more than $3 million, but operators often reduced demands by 50% to 75% during negotiations. In over 53% of tracked cases, final payments averaged about $750,000. Some victims made payments after the BlackFile name was retired.

GTIG reported recent campaigns showed refinements in technique. The actors spoofed legitimate helpdesk phone numbers, used compromised email accounts to reset passwords on non-SSO enterprise applications, and deleted confirmation messages and alerts to reduce chances of detection. GTIG noted that adversary-in-the-middle attacks intercept one-time codes or session tokens used in authentication.

GTIG’s ongoing monitoring shows the group has diversified its public brands while maintaining consistent initial access and post-compromise steps that affect organizations using cloud SSO and standard MFA protections.

Articles by this author