A sophisticated wave of cyberattacks targeting global financial giants like Citadel and Point72 has been traced to the UNC6671 extortion group. Using advanced vishing techniques, the attackers are bypassing multi-factor authentication to access critical cloud data.

Key Takeaways

  • UNC6671 is targeting elite hedge funds, private equity firms, and law firms.
  • The group utilizes 'vishing' (voice phishing) to manipulate employees into granting system access.
  • Attackers bypass security by stealing session cookies and SSO credentials.
  • The group operates under multiple brands including Redact, Pink, Helix, and Falcon.

A massive wave of targeted cyberattacks hitting hedge funds, private-equity firms, and major financial organizations has been officially linked to UNC6671. This extortion group is reportedly an offshoot or associated entity of the notorious BlackFile campaign.

According to reports from Reuters and Bloomberg, high-profile firms including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel have been targeted. The attackers employ a highly effective social engineering tactic known as vishing (voice phishing), where they impersonate corporate helpdesks to trick employees into compromising their security settings.

Why This Matters

BozokMedia analysis shows that the shift from targeting retail sectors to high-stakes financial institutions marks a significant escalation in cybercriminal sophistication. By targeting the 'keys to the kingdom'—Single Sign-On (SSO) credentials—these attackers can gain unfettered access to entire corporate cloud ecosystems, making the impact of a single breach catastrophic.

A single core intrusion group is driving the helpdesk vishing and cloud data theft across various public extortion brands.

The technical execution involves directing victims to fraudulent domains that host adversary-in-the-middle phishing kits. Once the attackers capture Microsoft 365 or Okta credentials, they can access all linked cloud platforms. To evade detection, they use automated tools to delete security notifications and password-reset emails from compromised inboxes.

Historical Background

The BlackFile group first emerged in February 2025, primarily targeting the retail and hospitality sectors. However, a strategic pivot occurred in July 2026, when the group shifted its focus toward high-value targets such as private-equity firms, major law firms, and financial-rating agencies.

Did You Know?: Between January and May 2026, threat analysts tracked over $10.6 million USD in Bitcoin payments flowing to wallets associated with this group.

Frequently Asked Questions

1. How does the vishing attack actually work?
Attackers call employees on personal phones, spoofing the company helpdesk, and claim the employee needs to update their multi-factor authentication or passkeys.

2. Is this group the same as Scattered Spider?
While the tactics are similar, Mandiant notes that UNC6671 uses a distinct infrastructure and domain registration pattern, separating them from Scattered Spider.