Google Threat Intelligence Group tracks a financially motivated vishing and extortion collective called UNC6671 that impersonates IT helpdesk staff, calls employees on personal phones, steals credentials and MFA codes... The group operated originally as BlackFile, retired that brand in May 2026, and has since divers...
Research answer

Create a landscape editorial hero image for this Studio Global article: What hacking groups tracked by Google under the names Falcon, Helix, Pink, and Redact — possibly part of a larger collective called UNC6671. Article summary: Let me also check Google's own report for the most authoritative. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
A single cybercrime collective, tracked by Google's Threat Intelligence Group (GTIG) as UNC6671, has collected more than $10 million in Bitcoin since January 2026 by calling employees at major U.S. financial firms, impersonating IT helpdesk staff, and tricking them into handing over credentials — including live multi-factor authentication (MFA) codes . The operation, which originally ran under the BlackFile extortion brand before rebranding in mid-2026, now operates at least four public-facing extortion brands: Redact, Pink, Helix, and Falcon
.
Google's reporting and corroborating cybersecurity news outlets explicitly name the following large U.S. financial and investment firms as targets of UNC6671: Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, and TPG .
Reuters and Bloomberg additionally reported that Point72 Asset Management, Millennium Management, Two Sigma, and Citadel were also targeted .
The attack chain relies on a deceptively simple combination of social engineering and adversary-in-the-middle (AiTM) phishing infrastructure, not sophisticated malware.
1. Vishing calls to personal cellphones. Attackers call employees on their personal mobile devices, spoofing caller IDs to appear as the company helpdesk. They claim an urgent passkey migration or MFA update is required . Targeting personal phones helps bypass corporate telephony monitoring and security tooling.
2. Real-time credential and MFA theft. Victims are directed to spoofed single sign-on portals that look identical to legitimate company pages. The AiTM proxy intercepts the username and password, then captures the live MFA token — whether push, SMS, or TOTP — in real time. The attacker immediately registers a new attacker-controlled MFA device to maintain persistent access .
3. Automated data exfiltration. Once inside, the group deploys automated Python and PowerShell scripts that harvest data from connected cloud services — Microsoft 365, SharePoint, OneDrive, Okta, Zendesk, and Salesforce. The scripts search for keywords like "confidential" and "SSN" to prioritize high-value data .
4. Extortion and data leak sites. Stolen data — including intellectual property, source code, and sensitive client information — is published on dedicated data leak sites (DLS) under each brand unless the victim pays the ransom .
Before shifting focus to financial services, private equity, and professional services in mid-2026, UNC6671 (operating as BlackFile) targeted a wide range of sectors including manufacturing, real estate, healthcare, insurance, technology, transportation, and hospitality .
Google attributes all four extortion brands to the broader UNC6671 collective based on shared domain registration patterns, overlapping phishing templates, shared AiTM phishing kits, and overlapping victim organizations .
However, Google notes that alternative scenarios — such as splintered affiliates or multiple groups sharing the same Phishing-as-a-Service infrastructure — "may also be plausible" . The brands are not necessarily separate criminal crews; they are likely the same operator(s) running multiple leak-site brands simultaneously after rebranding from BlackFile.
Security experts and Google's GTIG recommend the following mitigations against this specific threat :
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Google Threat Intelligence Group tracks a financially motivated vishing and extortion collective called UNC6671 that impersonates IT helpdesk staff, calls employees on personal phones, steals credentials and MFA codes...
Google Threat Intelligence Group tracks a financially motivated vishing and extortion collective called UNC6671 that impersonates IT helpdesk staff, calls employees on personal phones, steals credentials and MFA codes... The group operated originally as BlackFile, retired that brand in May 2026, and has since diversified into four public facing extortion brands: Redact, Pink, Helix, and Falcon.
Confirmed targets include Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, TPG, Point72, Millennium Management, Two Sigma, and Citadel.