Google Threat Intelligence Exposes BlackFile Vishing Extortion Campaign
The Google Threat Intelligence Group (GTIG) has released a detailed analysis of UNC6671, a threat actor operating under the "BlackFile" brand, which conducts sophisticated extortion campaigns against organizations globally. Emerging in early 2026, this group targets dozens of entities in North America, Australia, and the UK, focusing on Microsoft 365 and Okta infrastructure. The attackers utilize high-volume voice phishing (vishing) combined with adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA). By masquerading as IT support personnel and directing victims to credential-harvesting sites, they gain deep access to cloud environments. Once inside, they employ Python and PowerShell scripts to exfiltrate sensitive corporate data for extortion. Although UNC6671 has occasionally co-opted the ShinyHunters brand, GTIG confirms their operations are independent, citing unique communication channels and domain registration patterns. The report emphasizes that these breaches result from social engineering rather than vendor vulnerabilities, urging organizations to adopt phishing-resistant MFA solutions to protect their identity platforms and SaaS applications from such identity-centric threats.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection